FORESHOCK

Every protocol here carries a dated score and the share of it backed by independently verified evidence. Where that share is still thin the assessment says so, is marked Low-signal rather than given a risk band, and holds every unevidenced category at the neutral midpoint instead of assuming it safe. Every score and its reasoning are free to read; the underlying dependency, incident and audit records are part of a plan. How a score is built, how to read one, and how the rubric was tested against real exploits are all in the methodology.

Coverage grows three ways: protocols Foreshock selects at its own discretion, protocols requested through the Request coverage button, and sponsored assessments delivered on an agreed timeline. No path has a guaranteed date except sponsorship.

Scores run from 0, the safest reading, to 100, the riskiest, where 50 is the neutral midpoint every unverified category is held at. Red marks a protocol scoring 50 or above, the band called Elevated: worse than neutral on the evidence gathered. Amber marks one below it, called Moderate. The boundary is fixed. It does not move as coverage grows, and it is not fitted to any backtest result.

Kinetiq kHYPE

Kinetiq kHYPE official site →
Hyperliquid L1

:

  • Evidence: this reading is based on 100% of the scored weight, verified against named sources. Categories without verified data are excluded from the reading, never counted as safe.
  • Validation: the rubric is backtested against past exploits of protocols in the same TVL, age and category bucket. Protocols of this scale and kind have no such history - a limit of the record itself, not unfinished work.
Score by categories
Code characteristics11.2

Admin key: an unidentified controlling contract (no single key can act alone; its signers and any delay are unverified), upgradeable without a meaningful timelock.

Audit profile9.9

5 audits/contests on record, most recent (Pashov Audit Group, 2025-11-23) has unread findings, scored as unknown, not assumed clean.

Dependency risk6.0

Uses 1 oracle (The audited contest source shows a first-party oracle contract where an operator role pushes validator metrics such as balance, uptime, stake and slashing, aggregated behind a challenge period; there is no third-party feed. A separate library calls chain precompiles for positions, balances and delegations. The dependency chain is therefore Hyperliquid's two layers plus Kinetiq's own operator keys, and no external bridge is involved.).

TVL profile5.5

TVL grew 52% recently, moderate inflow.

Governance attack surface5.0

Governance concentration/quorum data unknown.

Historical incidents2.2

No known own or inherited incidents.

Team factors1.7

Doxxed team, track record: mixed.

Protocol age1.5

414 days live, past the ~1yr floor; treated the same as any older protocol, not scored progressively safer with more age.

Bug bounty1.0

Has a bug bounty program, up to $1 000 000.

Assets held (1)

Available with a plan. See pricing.

Dependencies (1)

Available with a plan. See pricing.

Incident history (0)

Available with a plan. See pricing.

Audit history (5)

Available with a plan. See pricing.

This assessment follows Foreshock's published methodology. Exact category weights, scoring rules, thresholds, and aggregation logic are proprietary and not shown here. How to interpret this assessment