FORESHOCK

Every protocol here carries a dated score and the share of it backed by independently verified evidence. Where that share is still thin the assessment says so, is marked Low-signal rather than given a risk band, and holds every unevidenced category at the neutral midpoint instead of assuming it safe. Every score and its reasoning are free to read; the underlying dependency, incident and audit records are part of a plan. How a score is built, how to read one, and how the rubric was tested against real exploits are all in the methodology.

Coverage grows three ways: protocols Foreshock selects at its own discretion, protocols requested through the Request coverage button, and sponsored assessments delivered on an agreed timeline. No path has a guaranteed date except sponsorship.

Scores run from 0, the safest reading, to 100, the riskiest, where 50 is the neutral midpoint every unverified category is held at. Red marks a protocol scoring 50 or above, the band called Elevated: worse than neutral on the evidence gathered. Amber marks one below it, called Moderate. The boundary is fixed. It does not move as coverage grows, and it is not fitted to any backtest result.

Balancer V2

Balancer V2 official site N/A

Multi-Chain

:

  • Evidence: this reading is based on 100% of the scored weight, verified against named sources. Categories without verified data are excluded from the reading, never counted as safe.
  • Validation: measured against 1 comparable incident/control in this protocol's TVL, age and category bucket.
Score by categories
Historical incidents14.2

This protocol has 3 prior incidents of its own, hard floor applied regardless of current size/age.

Audit profile7.9

4 audits on record, most recent audit is over 2 years old; the most recent audit found 0 High and 0 Medium severity issues. This reflects code quality at the time of that audit only, not a claim that these specific issues are still unresolved today.

Code characteristics7.5

Admin key: none, open source.

Dependency risk6.7

Uses 1 oracle (Balancer V2's core AMM math (Weighted Pools, plain Stable Pools) needs no external oracle -- pricing derives from internal pool balances, same self-contained design as a constant-product AMM. Balancer V2 also acts as an oracle PROVIDER for other protocols via accumulator-based TWAP data. Dependency risk is pool-specific and opt-in: certain Boosted/Composable Stable Pools use an optional Rate Provider interface, and Balancer's own docs name a Chainlink-backed rate provider (ChainlinkRateProvider) plus a Lido-backed one for wstETH pools. No bridge dependency found documented anywhere in Balancer's own V2 materials.), composable with 1 other protocol.

TVL profile6.5

TVL is 98% below this protocol's own peak and has not recovered, so the revenue that funds audits, bounties and maintenance is largely gone while the contracts still hold value; TVL change (6%) is within a stable range.

Governance attack surface2.5

Top 10 holders control 18.28%, adjusted figure may still include pooled custody (untagged exchanges, infrastructure contracts) due to tagging coverage limits; exclusions require positive identification.

Team factors1.7

Doxxed team, track record: unknown.

Bug bounty1.5

Has a bug bounty program, hosted on Immunefi.

Protocol age1.5

1963 days live, past the ~1yr floor; treated the same as any older protocol, not scored progressively safer with more age.

Dependencies (2)

Available with a plan. See pricing.

Incident history (3)

Available with a plan. See pricing.

Audit history (4)

Available with a plan. See pricing.

This assessment follows Foreshock's published methodology. Exact category weights, scoring rules, thresholds, and aggregation logic are proprietary and not shown here. How to interpret this assessment