FORESHOCK

Every protocol here carries a dated score and the share of it backed by independently verified evidence. Where that share is still thin the assessment says so, is marked Low-signal rather than given a risk band, and holds every unevidenced category at the neutral midpoint instead of assuming it safe. Every score and its reasoning are free to read; the underlying dependency, incident and audit records are part of a plan. How a score is built, how to read one, and how the rubric was tested against real exploits are all in the methodology.

Coverage grows three ways: protocols Foreshock selects at its own discretion, protocols requested through the Request coverage button, and sponsored assessments delivered on an agreed timeline. No path has a guaranteed date except sponsorship.

Scores run from 0, the safest reading, to 100, the riskiest, where 50 is the neutral midpoint every unverified category is held at. Red marks a protocol scoring 50 or above, the band called Elevated: worse than neutral on the evidence gathered. Amber marks one below it, called Moderate. The boundary is fixed. It does not move as coverage grows, and it is not fitted to any backtest result.

Meteora DLMM

Meteora DLMM official site N/A

Solana

:

  • Evidence: this reading is based on 100% of the scored weight, verified against named sources. Categories without verified data are excluded from the reading, never counted as safe.
  • Validation: measured against 3 comparable incidents/controls in this protocol's TVL, age and category bucket.
Score by categories
Code characteristics11.3

Admin key: an unidentified controlling contract (no single key can act alone; its signers and any delay are unverified), upgradeable without a meaningful timelock.

Dependency risk8.3

Uses 1 oracle (DLMM provides price data and consumes none, and the direction was established by searching Meteora's own IDL for pyth, switchboard and chainlink with zero matches; the only hardcoded program addresses in the entire IDL are SPL Token, System, Memo, the instructions sysvar and DLMM itself, so there is no external oracle, bridge or lending program referenced anywhere. THE DYNAMIC VAULT QUESTION IS ANSWERED EXPLICITLY AND IN THE NEGATIVE, which matters because it is the obvious assumption for a Meteora product: Meteora's own DLMM page says 'Unlike DAMM pools, DLMM liquidity is not connected to Meteora's Dynamic Vaults for lending yield. DLMM liquidity is used for trading, fee capture, and pool-level incentives where available', and an IDL search for solend, kamino, marginfi, port_finance, francium, tulip, lending and dynamic_vault likewise returns nothing. So the external-lending exposure that applies to Meteora's other products does NOT apply here and no lending protocols are named. The real external-code exposure is Token-2022 transfer hooks, and it is permissioned: Meteora's own page lists supported extensions including transfer fees and metadata, and admits 'TransferHook, only when both the hook program and hook authority are revoked', with freeze-authority mints requiring review and the native Token-2022 mint rejected. At the program level the IDL defines transferHookX, transferHookY, transferHookReward, transferHookMultiReward and transferHookReferral account types passed through remainingAccountsInfo, and transfer-fee handling produced a real high-severity finding in OtterSec's review.), composable with 3 other protocols.

Governance attack surface7.0

No governance token; control sits with contract unidentified rather than a vote, so decision rights are concentrated rather than capturable. The form of that key is scored separately under code characteristics.

TVL profile5.5

TVL is 85% below this protocol's own peak; TVL change (22%) is within a stable range.

Bug bounty3.3

No bug bounty program on record.

Historical incidents2.3

No known own or inherited incidents.

Audit profile2.0

15 audits on record, most recent audit is recent (<=180d); the most recent audit found 1 High and 0 Medium severity issues. This reflects code quality at the time of that audit only, not a claim that these specific issues are still unresolved today.

Team factors1.8

Doxxed team, track record: unknown.

Protocol age1.5

927 days live, past the ~1yr floor; treated the same as any older protocol, not scored progressively safer with more age.

Dependencies (2)

Available with a plan. See pricing.

Incident history (0)

Available with a plan. See pricing.

Audit history (15)

Available with a plan. See pricing.

This assessment follows Foreshock's published methodology. Exact category weights, scoring rules, thresholds, and aggregation logic are proprietary and not shown here. How to interpret this assessment