FORESHOCK

Every protocol here carries a dated score and the share of it backed by independently verified evidence. Where that share is still thin the assessment says so, is marked Low-signal rather than given a risk band, and holds every unevidenced category at the neutral midpoint instead of assuming it safe. Every score and its reasoning are free to read; the underlying dependency, incident and audit records are part of a plan. How a score is built, how to read one, and how the rubric was tested against real exploits are all in the methodology.

Coverage grows three ways: protocols Foreshock selects at its own discretion, protocols requested through the Request coverage button, and sponsored assessments delivered on an agreed timeline. No path has a guaranteed date except sponsorship.

Scores run from 0, the safest reading, to 100, the riskiest, where 50 is the neutral midpoint every unverified category is held at. Red marks a protocol scoring 50 or above, the band called Elevated: worse than neutral on the evidence gathered. Amber marks one below it, called Moderate. The boundary is fixed. It does not move as coverage grows, and it is not fitted to any backtest result.

Aerodrome Slipstream

Aerodrome Slipstream official site N/A

Base

:

  • Evidence: this reading is based on 100% of the scored weight, verified against named sources. Categories without verified data are excluded from the reading, never counted as safe.
  • Validation: measured against 3 comparable incidents/controls in this protocol's TVL, age and category bucket.
Score by categories
Audit profile10.0

4 audits/contests on record, most recent (MixBytes, 2025-10-03) has unread findings, scored as unknown, not assumed clean.

Dependency risk8.3

Uses 1 oracle (Slipstream consumes no external price data and provides its own, verified by searching its specification and changelog for oracle, observation, TWAP, price feed, Chainlink and bridge, where the only hits are the two lines describing its own UniswapV3-style observation buffer. No bridge dependency exists either. The real coupling is internal and was read from the contract source rather than from prose: CLGauge imports IVoter and reads minter, and CLGaugeFactory holds an immutable voter, derives its reward token via IMinter(IVoter(voter).minter()).aero() and reads IVotingEscrow(IVoter(voter).ve()).team(). So every Slipstream gauge hard-depends on Aerodrome's own Voter, Minter, VotingEscrow and AERO. Note what is NOT a dependency: Velodrome's Superchain infrastructure. Slipstream is a CODE fork of Velodrome's repo with no Velodrome runtime import, and its governance dependency is Aerodrome's own veAERO on Base. Aerodrome's about page does state that 'In 2026, Aerodrome will merge with Velodrome', which is forward-looking organisational risk rather than a live contract dependency. Two flags. Aerodrome's own about page claims it 'has no centralized servers or dependencies', which is a marketing claim rather than a technical one given the Base and Voter couplings above. And the docs registry lists a 'Prices Oracle' at 0xee717411f6E44F9feE011835C8E6FAaC5dEfF166 with NO explanation and no reference to it in any Aerodrome or Velodrome repository; no Slipstream contract was found reading an external price feed, so no dependency on it is recorded.), composable with 3 other protocols.

Governance attack surface7.5

Top 10 holders control 66.7%, adjusted figure may still include pooled custody (untagged exchanges, infrastructure contracts) due to tagging coverage limits; exclusions require positive identification.

Code characteristics6.8

Admin key: 3/7 multisig (requires 3 of 7 keys to act), open source.

TVL profile3.5

TVL change (45%) is within a stable range.

Bug bounty3.2

No bug bounty program on record.

Team factors3.0

Anonymous team, a weak but real signal on its own.

Historical incidents2.2

No known own or inherited incidents.

Protocol age1.5

863 days live, past the ~1yr floor; treated the same as any older protocol, not scored progressively safer with more age.

Assets held (3)

Available with a plan. See pricing.

Dependencies (2)

Available with a plan. See pricing.

Incident history (0)

Available with a plan. See pricing.

Audit history (4)

Available with a plan. See pricing.

This assessment follows Foreshock's published methodology. Exact category weights, scoring rules, thresholds, and aggregation logic are proprietary and not shown here. How to interpret this assessment

Aerodrome Slipstream · Foreshock