defirisk.co
rubric v1.7.0

Default bytes32(0) acceptable as valid root

OpenEden's assessment for RD-F-154 — scored not_applicable on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

[★ CRITICAL — not_applicable] No Merkle-root bridge. OpenEden USDO uses Chainlink CCIP CCT (Chainlink-managed, not a Merkle-root system). XRPL TBILL is native XRPL issuance. F154 (Nomad bytes32(0) root bug class) is structurally inapplicable.

Sources #

  • URL
    OpenEden + Chainlink CCIP CCT announcementChainlink CCIP CCT — managed burn-and-mint standard, not a Merkle-root bridge systemretrieved 2026-05-16
  • Internal
    OpenEden protocol profile §7Profile §7: has_bridge_surface=false; CCIP CCT not a Merkle-root bridge; XRPL native issuance not a bridgeretrieved 2026-05-16

Methodology #

Determine whether the bridge inbox accepts a default-value (bytes32(0)) Merkle root as a valid proof root (Nomad bug class).

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol openeden factor RD-F-154 score not_applicable collected_at 2026-05-16 10:11:45