defirisk.co
rubric v1.7.0

Disclosure SLA public

Hyperlane's assessment for RD-F-176 — scored red on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

No acknowledgment SLA published on Immunefi program page, no SECURITY.md with SLA, no Hyperlane doc page with response timeline. The April 2026 critical disclosure (issue #8589, opened 2026-04-14) received no documented team response for 33+ days, consistent with no SLA commitment in force. For a $132M bridge with an active critical disclosure, absence of published SLA is a red finding.

Sources #

Methodology #

Determine whether the protocol publishes an acknowledgment-time SLA for disclosed vulnerabilities (e.g., 72h ack).

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol hyperlane factor RD-F-176 score red collected_at 2026-05-16 23:03:56