FORESHOCK
Back to Research

What Our Monitoring Actually Caught: a 90-Day Signal Audit

We built Foreshock to tell subscribers when something material changes about a protocol they're watching. So we asked the only question that actually tests that promise: over the last 90 days, what would a paying subscriber actually have heard from us?

The method was simple. We went back through 90 days of our own pipeline data. Then we independently researched, protocol by protocol, what really happened in the world in that window. Then we compared the two lists. This is that comparison, including the parts that don't flatter us.

The number that matters

  • Material events found by independent research: 27, across our 11 covered protocols, every one publicly sourced.
  • Events our pipeline alerted a subscriber to: 0.
  • Detection rate: 0 percent. Not a low percentage. Zero.

Context that explains the number without excusing it:

  • Our automated daily data refresh started existing only 6 days before the window closed. Before that, ingestion was manual and occasional.
  • Even now, 6 of its last 7 pull requests sit unmerged, so most of what it found in its first week never reached the live pipeline.

What the 27 events were

They split into two honest buckets.

24 events were detectable-unbuilt: our methodology has no automated detector for them at all yet. We research these things by hand today, and the window showed how much happens between manual passes:

  • 9 dependency or counterparty changes: new custodians, new bridges, new backing-asset venues.
  • 8 governance or admin-key changes: multisig signer rotations, parameter overhauls, votes that materially change a protocol's risk.
  • The rest: TVL swings, a bug bounty overhaul, a legal action.

3 events were misses inside categories we already score. These are worse, and each deserves its facts stated plainly:

  • Radiant Capital wound down operations in June. Borrowing disabled across every market, emissions halted, TVL collapsed from a $386 000 000 peak to roughly $2 210 000. Our ingested data reflects the collapse. The published score never moved, to the decimal.
  • SSV Network's TVL fell 55.9 percent peak to trough over six weeks, including a 35.1 percent single-day drop. Its score didn't move either.
  • A Morpho Blue market lost real money in July to a frozen price oracle, and the incident isn't in our ledger (more on this one below).

Why the scores didn't move

We read our own scoring code rather than guessed. Our TVL category deliberately scores volatility, not size - the right design on its own, because a protocol shouldn't get a safety credit for being big. But a score that does not move at all, not even by what the formula's own volatility bands would predict, points to the data feeding that category not being refreshed to reflect either collapse. That's a concrete, fixable gap, not a philosophical one, and it's the first thing on our list.

The third miss is a harder question

The Morpho Blue case is not just a coverage gap. Morpho Blue is a permissionless base layer: anyone can create an isolated market with their own collateral and oracle choices. Whether a loss inside one such market counts as the protocol's own incident, or as something one layer removed, changes which part of our methodology should catch it. We're not pretending that's already decided.

What this means for a subscriber right now

As of the window's close, the platform has exactly one active subscription, and its watchlist was added on the last day we measured. We are not going to dress that up as a mature subscriber base. The honest current answer to "how many alerts should I expect per protocol per month" is zero - observed, not projected - and we'd rather say that plainly than compute a friendlier number from one day of data.

What we're building next because of this

Ranked by how many of the 27 events each gap would have caught:

  1. Dependency and counterparty-change detector - 9 events.
  2. Governance and admin-key change detector - 8 events.
  3. TVL-swing and instability alert - 6 events, third by count but first by consequence: it's the only category that would have changed what our one real subscriber actually saw this week.

Publishing this required deciding, in writing, that a 0 percent detection rate is something we say out loud rather than quietly fix and never mention. We think that decision is itself part of what an independent risk platform owes the people relying on it. The full event table, every source, every date, and the reasoning behind every classification call is in the underlying audit for anyone who wants to check our work line by line.

Mentioned protocols

This is research, not financial, legal, or insurance advice - no score or report guarantees safety or risk.