FORESHOCK

Every protocol here carries a dated score and the share of it backed by independently verified evidence. Where that share is still thin the assessment says so, is marked Low-signal rather than given a risk band, and holds every unevidenced category at the neutral midpoint instead of assuming it safe. Every score and its reasoning are free to read; the underlying dependency, incident and audit records are part of a plan. How a score is built, how to read one, and how the rubric was tested against real exploits are all in the methodology.

Coverage grows three ways: protocols Foreshock selects at its own discretion, protocols requested through the Request coverage button, and sponsored assessments delivered on an agreed timeline. No path has a guaranteed date except sponsorship.

Scores run from 0, the safest reading, to 100, the riskiest, where 50 is the neutral midpoint every unverified category is held at. Red marks a protocol scoring 50 or above, the band called Elevated: worse than neutral on the evidence gathered. Amber marks one below it, called Moderate. The boundary is fixed. It does not move as coverage grows, and it is not fitted to any backtest result.

OpenEden TBILL

OpenEden TBILL official site N/A

Multi-Chain

:

  • Evidence: this reading is based on 100% of the scored weight, verified against named sources. Categories without verified data are excluded from the reading, never counted as safe.
  • Validation: the rubric is backtested against past exploits of protocols in the same TVL, age and category bucket. None has been evaluated for this one yet, so the reading rests on its evidence alone.
Score by categories
Audit profile9.9

3 audits/contests on record, most recent (Hacken, 2024-01-01) has unread findings, scored as unknown, not assumed clean.

Dependency risk9.0

Uses 1 oracle (This is a real-world-asset product and the interesting risk is off chain, so it is written out here rather than compressed. The Treasuries are custodied by BNY and managed by BNY Mellon Investment Management Singapore, a fund management company regulated by MAS with a mandate for short-dated US T-bills. The Token Issuer is a British Virgin Islands registered professional fund regulated by the BVI Financial Services Commission under the Securities and Investment Business Act 2010, though OpenEden's own docs never state the fund's legal entity name, referring to it only as the Token Issuer. KYC is a HARD GATE, not advisory: minting and redemption run only through whitelisted, KYC and KYB verified wallets, and TRANSFERS ARE RESTRICTED TO BETWEEN WHITELISTED WALLETS, with a first deposit minimum of 100 000 USDC. Redemption is T+1, typically the next US business day. THERE IS NO PROOF OF RESERVE: no Chainlink PoR and no automated on-chain reserve proof appears anywhere in the TBILL docs; transparency runs on administrator NAV reports plus the annual fund audit, so it is attestation-based rather than cryptographic, and that distinction should be scored. On oracles, the price is OpenEden's own computation pushed on chain with a price-guard circuit breaker whose deviation threshold is not published, and no third-party oracle provider is named. Two things were not established: any bridging model for the multichain deployments, which the docs never describe either way, and the USYC dependency in prose, which is evidenced only by a contract name and two audit filenames.), composable with 5 other protocols.

Code characteristics9.0

Admin key: 4/5 multisig (requires 4 of 5 keys to act), upgradeable without a meaningful timelock, open source.

Governance attack surface7.0

No governance token; control sits with multisig rather than a vote, so decision rights are concentrated rather than capturable. The form of that key is scored separately under code characteristics.

TVL profile3.5

TVL change (-3%) is within a stable range.

Bug bounty3.2

No bug bounty program on record.

Historical incidents2.2

No known own or inherited incidents.

Team factors1.7

Doxxed team, track record: unknown.

Protocol age1.5

1191 days live, past the ~1yr floor; treated the same as any older protocol, not scored progressively safer with more age.

Assets held (1)

Available with a plan. See pricing.

Dependencies (2)

Available with a plan. See pricing.

Incident history (0)

Available with a plan. See pricing.

Audit history (3)

Available with a plan. See pricing.

This assessment follows Foreshock's published methodology. Exact category weights, scoring rules, thresholds, and aggregation logic are proprietary and not shown here. How to interpret this assessment