FORESHOCK

Every protocol here carries a dated score and the share of it backed by independently verified evidence. Where that share is still thin the assessment says so, is marked Low-signal rather than given a risk band, and holds every unevidenced category at the neutral midpoint instead of assuming it safe. Every score and its reasoning are free to read; the underlying dependency, incident and audit records are part of a plan. How a score is built, how to read one, and how the rubric was tested against real exploits are all in the methodology.

Coverage grows three ways: protocols Foreshock selects at its own discretion, protocols requested through the Request coverage button, and sponsored assessments delivered on an agreed timeline. No path has a guaranteed date except sponsorship.

Scores run from 0, the safest reading, to 100, the riskiest, where 50 is the neutral midpoint every unverified category is held at. Red marks a protocol scoring 50 or above, the band called Elevated: worse than neutral on the evidence gathered. Amber marks one below it, called Moderate. The boundary is fixed. It does not move as coverage grows, and it is not fitted to any backtest result.

Optimism Bridge

Optimism Bridge official site N/A

Multi-Chain

:

  • Evidence: this reading is based on 100% of the scored weight, verified against named sources. Categories without verified data are excluded from the reading, never counted as safe.
  • Validation: the rubric is backtested against past exploits of protocols in the same TVL, age and category bucket. None has been evaluated for this one yet, so the reading rests on its evidence alone.
Score by categories
Dependency risk9.1

Uses 1 oracle (The bridge consumes no oracle; its security is the fault-proof system plus a 7-day withdrawal challenge period, and the residual risk is a key, not a feed. Optimism's own docs: mainnet L2-to-L1 messages 'cannot be relayed for at least 7 days' because 'L1 contracts must give challengers time to prove a published result faulty before acting on it', and DelayedWETH enforces a separate 7-day delay giving authorities 'sufficient time to respond to potential security concerns'. Withdrawals are three steps: initiate on L2, prove on L1 with a Merkle inclusion proof, finalise after the challenge period. The Guardian, which must be a 1-of-1 Safe controlled by the Security Council, can trigger the global pause, BLACKLIST specific FaultDisputeGame contracts that resolve incorrectly, change the respected game type or revert to the permissioned game, and reject roots during an airgap window; Optimism frames it as 'a backstop only in case of a failure in the fault proof game'. THE DOMINANT RESIDUAL RISK IS STATED BY OPTIMISM ITSELF: the 2-of-2 nested multisig can upgrade 'core OP Stack smart contracts without upgrade delays', and its own FAQ concedes that fault proofs offer 'limited improvements to the security of a system if the system still has a multisig' able to upgrade instantly. Censorship resistance is genuinely designed in: 'Users can always bypass the sequencer and include transactions in the L2 chain by sending their L2 transactions directly to the OptimismPortal contract on L1.'), composable with 4 other protocols.

Code characteristics9.1

Admin key: 2/2 multisig (requires 2 of 2 keys to act), upgradeable without a meaningful timelock, open source.

Governance attack surface7.6

Top 10 holders control 52.46%, adjusted figure may still include pooled custody (untagged exchanges, infrastructure contracts) due to tagging coverage limits; exclusions require positive identification.

TVL profile5.6

TVL is 88% below this protocol's own peak; TVL change (17%) is within a stable range.

Team factors3.0

Anonymous team, a weak but real signal on its own.

Historical incidents2.3

No known own or inherited incidents.

Protocol age1.5

2072 days live, past the ~1yr floor; treated the same as any older protocol, not scored progressively safer with more age.

Bug bounty0.8

Has a bug bounty program, up to $2 000 042, hosted on Immunefi.

Audit profile0.0

4 audits on record, most recent audit is recent (<=180d); the most recent audit found 0 High and 0 Medium severity issues. This reflects code quality at the time of that audit only, not a claim that these specific issues are still unresolved today.

Assets held (5)

Available with a plan. See pricing.

Dependencies (2)

Available with a plan. See pricing.

Incident history (0)

Available with a plan. See pricing.

Audit history (4)

Available with a plan. See pricing.

This assessment follows Foreshock's published methodology. Exact category weights, scoring rules, thresholds, and aggregation logic are proprietary and not shown here. How to interpret this assessment