defirisk.co
rubric v1.7.0

Auditor re-engaged after last exploit

Orca's assessment for RD-F-083 — scored not_applicable on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

No prior protocol exploits. Methodology specifies gray (N/A) when there are no prior exploits — no post-exploit re-audit can be assessed. Note: Orca has conducted six proactive audits (Kudelski 2022, Neodyme 2022, OtterSec 2024, Sec3 x3 in 2025) but these are routine audits, not post-exploit re-audits.

Sources #

  • Internal
    Data cache — no prior incidents; F083 not applicablerisk-dashboard/.research/protocols/orca/00-data-cache.json sources.rekt.incidents=[] — no prior protocol exploits; F083 structurally inapplicableretrieved 2026-05-16
  • GitHub
    Orca Whirlpools .audits directory (6 audit PDFs)https://github.com/orca-so/whirlpools/tree/main/.auditsretrieved 2026-05-16

Methodology #

Determine whether a reputable auditor performed a re-audit or incident review after the most recent exploit.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol orca factor RD-F-083 score not_applicable collected_at 2026-05-16 02:39:16