FORESHOCK

Every protocol here carries a dated score and the share of it backed by independently verified evidence. Where that share is still thin the assessment says so, is marked Low-signal rather than given a risk band, and holds every unevidenced category at the neutral midpoint instead of assuming it safe. Every score and its reasoning are free to read; the underlying dependency, incident and audit records are part of a plan. Each reading here is fixed at the date beside it. Re-scoring never stops, but a changed reading reaches plan holders on the day it changes rather than this page, which is what a plan is for. How a score is built, how to read one, and how the rubric was tested against real exploits are all in the methodology.

Coverage grows three ways: protocols Foreshock selects at its own discretion, protocols requested through the Request coverage button, and sponsored assessments delivered on an agreed timeline. No path has a guaranteed date except sponsorship.

Scores run from 0, the safest reading, to 100, the riskiest, where 50 is the neutral midpoint every unverified category is held at. Red marks a protocol scoring 50 or above, the band called Elevated: worse than neutral on the evidence gathered. Amber marks one below it, called Moderate. The boundary is fixed. It does not move as coverage grows, and it is not fitted to any backtest result.

Liquity V1

Liquity V1 official site N/A

Ethereum

:

  • Evidence: this reading is based on 100% of the scored weight, verified against named sources. Categories without verified data are excluded from the reading, never counted as safe.
  • Validation: the rubric is backtested against past exploits of protocols in the same TVL, age and category bucket. None has been evaluated for this one yet, so the reading rests on its evidence alone.
In short

Foreshock's independent reading of Liquity V1 is Moderate risk, 43.0 out of 100, as of 7 September 2026. The largest single contributor to that reading is audit profile: 4 audits/contests on record, most recent (Coinspect, 2021-03-15) has unread findings, scored as unknown, not assumed clean. All nine scored categories are backed by verified evidence. Foreshock publishes the reading and the reasoning behind it. It is not a verdict on whether to use this protocol, and it is not investment advice.

Is Liquity V1 safe?
Foreshock does not answer that as a yes or a no. Its independent reading of Liquity V1 is Moderate risk, 43.0 out of 100, as of 7 September 2026, led by audit profile: 4 audits/contests on record, most recent (Coinspect, 2021-03-15) has unread findings, scored as unknown, not assumed clean. The score and the reasoning are published in full so the reading can be checked rather than trusted.
Has Liquity V1 been audited?
4 audits/contests on record, most recent (Coinspect, 2021-03-15) has unread findings, scored as unknown, not assumed clean. An audit describes the code at the time it was reviewed. It is not a statement that the protocol is safe today.
Who controls Liquity V1?
Admin key: none, open source. No governance token and no admin key: the protocol cannot be changed by a vote or by an owner.
Has Liquity V1 been exploited before?
No known own or inherited incidents. Foreshock records an incident against a protocol whether it originated there or was inherited from something it depends on.
When was this Liquity V1 assessment last updated?
7 September 2026. Readings are recomputed as evidence changes, and every category carries the date of the evidence behind it.
Score by categories
Audit profile10.0

4 audits/contests on record, most recent (Coinspect, 2021-03-15) has unread findings, scored as unknown, not assumed clean.

Dependency risk8.3

Uses 2 oracles (Liquity V1's oracle design is fully specified in its own source and it is the single most important dependency in this record, because the protocol is immutable and cannot be patched if it goes wrong. PriceFeed.sol's own header: it connects to 'Chainlink's live ETH:USD aggregator reference contract, and a wrapper contract TellorCaller... The PriceFeed uses Chainlink as primary oracle, and Tellor as fallback. It contains logic for switching oracles based on oracle failures, timeouts, and conditions for returning to the primary Chainlink oracle.' The feed is STATEFUL and records the last good price. Its own README defines the failure conditions precisely: frozen means no update for more than 4 hours, broken means a revert, an invalid or future timestamp or a non-positive price, and a Chainlink deviation of more than 50 percent between consecutive rounds triggers a switch to Tellor. Returning to Chainlink requires both oracles live, unbroken and within 5 percent of each other. And here is the answer to what happens when both fail: the contract enters bothOraclesUntrusted and RETURNS lastGoodPrice, the most recent price recorded while a source was trusted, and keeps returning it until both recover. There is no third oracle and no human override, which follows directly from the no-admin-key design. A simultaneous Chainlink and Tellor outage leaves V1 operating on a frozen stale price. This is not hypothetical: on 2022-09-17 a researcher reported that TellorCaller used Tellor unsafely, and Liquity's own post says 'Since Liquity's code is completely immutable, it is not possible to alter how the system interacts with Tellor.' The fix had to be made BY TELLOR, upstream, in Tellor360. Liquity notes no user funds were at risk because Chainlink was the live source. NO bridge is recorded: V1's borrowing system exists only on Ethereum mainnet, and although the V1 docs list LUSD addresses on eight other chains, they name no bridge and describe no mechanism for them.), composable with 1 other protocol.

Code characteristics7.5

Admin key: none, open source.

TVL profile6.5

TVL is 95% below this protocol's own peak and has not recovered, so the revenue that funds audits, bounties and maintenance is largely gone while the contracts still hold value; TVL change (27%) is within a stable range.

Bug bounty3.3

No bug bounty program on record.

Historical incidents2.2

No known own or inherited incidents.

Governance attack surface2.0

No governance token and no admin key: the protocol cannot be changed by a vote or by an owner.

Team factors1.7

Doxxed team, track record: unknown.

Protocol age1.5

1981 days live, past the ~1yr floor; treated the same as any older protocol, not scored progressively safer with more age.

Assets held (1)

Available with a plan. See pricing.

Dependencies (2)

Available with a plan. See pricing.

Incident history (0)

Available with a plan. See pricing.

Audit history (4)

Available with a plan. See pricing.

Also covered on Ethereum

This assessment follows Foreshock's published methodology. Exact category weights, scoring rules, thresholds, and aggregation logic are proprietary and not shown here. How to interpret this assessment

This reading will change.

This reading is fixed at the date above it, and it stays there. We keep re-scoring Liquity V1 as the evidence moves, a new audit, a changed admin control, an incident, and this page is free to read and always will be. The updated reading is what a plan buys: you are told by email on the day it changes, instead of finding out the next time you happen to look.