FORESHOCK

Every protocol here carries a dated score and the share of it backed by independently verified evidence. Where that share is still thin the assessment says so, is marked Low-signal rather than given a risk band, and holds every unevidenced category at the neutral midpoint instead of assuming it safe. Every score and its reasoning are free to read; the underlying dependency, incident and audit records are part of a plan. How a score is built, how to read one, and how the rubric was tested against real exploits are all in the methodology.

Coverage grows three ways: protocols Foreshock selects at its own discretion, protocols requested through the Request coverage button, and sponsored assessments delivered on an agreed timeline. No path has a guaranteed date except sponsorship.

Scores run from 0, the safest reading, to 100, the riskiest, where 50 is the neutral midpoint every unverified category is held at. Red marks a protocol scoring 50 or above, the band called Elevated: worse than neutral on the evidence gathered. Amber marks one below it, called Moderate. The boundary is fixed. It does not move as coverage grows, and it is not fitted to any backtest result.

Aave V4

Aave V4 official site N/A

Multi-Chain

:

  • Evidence: this reading is based on 100% of the scored weight, verified against named sources. Categories without verified data are excluded from the reading, never counted as safe.
  • Validation: measured against 1 comparable incident/control in this protocol's TVL, age and category bucket.
Score by categories
Dependency risk12.0

Uses 3 oracles (V4 has no protocol-wide oracle by design, and its own source says so: AaveOracle.sol carries the comment 'Oracles are spoke-specific, due to the usage of reserve id as index of the _sources mapping', and the architecture doc gives the Spoke responsibility for 'Managing oracle interactions (oracles are spoke-specific)'. The contract consumes a generic IPriceFeed per reserve id and hardcodes no vendor, so the oracle risk of any position is the risk of the Spoke that position sits in. The providers named above come from the mainnet activation ARFC on Aave's own governance forum, which is first-party by venue but authored by a risk service provider rather than by Aave Labs, and that distinction is recorded rather than smoothed. NO bridge dependency is recorded: V4 launched single-chain on Ethereum and its Hub and Spoke model is intra-chain. Aave's GOVERNANCE V3 does pass messages across Ethereum, Polygon and Avalanche, but that is the governance system and not V4's liquidity layer, and conflating the two would attribute a bridge risk V4 does not carry. Two things were not established: whether the Reinvestment Module is live on mainnet and, if so, what it deploys into; and the fact that Aave's general oracle documentation page describes Chainlink and CAPO without ever mentioning V4, so it should not be over-read as a V4 source.), composable with 4 other protocols.

Code characteristics11.3

Admin key: an unidentified controlling contract (no single key can act alone; its signers and any delay are unverified), upgradeable without a meaningful timelock.

TVL profile5.5

TVL grew 71% recently, moderate inflow.

Protocol age2.8

158 days live, still young.

Governance attack surface2.5

Top 10 holders control 15.17%, adjusted figure may still include pooled custody (untagged exchanges, infrastructure contracts) due to tagging coverage limits; exclusions require positive identification.

Historical incidents2.2

No known own or inherited incidents.

Team factors1.7

Doxxed team, track record: unknown.

Bug bounty1.0

Has a bug bounty program, up to $3 500 000.

Audit profile0.0

10 audits on record, most recent audit is recent (<=180d); the most recent audit found 0 High and 0 Medium severity issues. This reflects code quality at the time of that audit only, not a claim that these specific issues are still unresolved today.

Assets held (8)

Available with a plan. See pricing.

Dependencies (2)

Available with a plan. See pricing.

Incident history (0)

Available with a plan. See pricing.

Audit history (10)

Available with a plan. See pricing.

This assessment follows Foreshock's published methodology. Exact category weights, scoring rules, thresholds, and aggregation logic are proprietary and not shown here. How to interpret this assessment