FORESHOCK

Every protocol here carries a dated score and the share of it backed by independently verified evidence. Where that share is still thin the assessment says so, is marked Low-signal rather than given a risk band, and holds every unevidenced category at the neutral midpoint instead of assuming it safe. Every score and its reasoning are free to read; the underlying dependency, incident and audit records are part of a plan. Each reading here is fixed at the date beside it. Re-scoring never stops, but a changed reading reaches plan holders on the day it changes rather than this page, which is what a plan is for. How a score is built, how to read one, and how the rubric was tested against real exploits are all in the methodology.

Coverage grows three ways: protocols Foreshock selects at its own discretion, protocols requested through the Request coverage button, and sponsored assessments delivered on an agreed timeline. No path has a guaranteed date except sponsorship.

Scores run from 0, the safest reading, to 100, the riskiest, where 50 is the neutral midpoint every unverified category is held at. Red marks a protocol scoring 50 or above, the band called Elevated: worse than neutral on the evidence gathered. Amber marks one below it, called Moderate. The boundary is fixed. It does not move as coverage grows, and it is not fitted to any backtest result.

Orca DEX

Orca DEX official site N/A

Multi-Chain

:

  • Evidence: this reading is based on 100% of the scored weight, verified against named sources. Categories without verified data are excluded from the reading, never counted as safe.
  • Validation: measured against 1 comparable incident/control in this protocol's TVL, age and category bucket.
In short

Foreshock's independent reading of Orca DEX is Moderate risk, 41.0 out of 100, as of 7 September 2026. The largest single contributor to that reading is code characteristics: admin key: an unidentified controlling contract (no single key can act alone; its signers and any delay are unverified), upgradeable without a meaningful timelock. All nine scored categories are backed by verified evidence. Foreshock publishes the reading and the reasoning behind it. It is not a verdict on whether to use this protocol, and it is not investment advice.

Is Orca DEX safe?
Foreshock does not answer that as a yes or a no. Its independent reading of Orca DEX is Moderate risk, 41.0 out of 100, as of 7 September 2026, led by code characteristics: admin key: an unidentified controlling contract (no single key can act alone; its signers and any delay are unverified), upgradeable without a meaningful timelock. The score and the reasoning are published in full so the reading can be checked rather than trusted.
Has Orca DEX been audited?
8 audits on record, most recent audit is recent (<=180d); the most recent audit found 0 High and 0 Medium severity issues. This reflects code quality at the time of that audit only, not a claim that these specific issues are still unresolved today. An audit describes the code at the time it was reviewed. It is not a statement that the protocol is safe today.
Who controls Orca DEX?
Admin key: an unidentified controlling contract (no single key can act alone; its signers and any delay are unverified), upgradeable without a meaningful timelock. Top 10 holders control 60.39%, adjusted figure may still include pooled custody (untagged exchanges, infrastructure contracts) due to tagging coverage limits; exclusions require positive identification.
Has Orca DEX been exploited before?
No known own or inherited incidents. Foreshock records an incident against a protocol whether it originated there or was inherited from something it depends on.
When was this Orca DEX assessment last updated?
7 September 2026. Readings are recomputed as evidence changes, and every category carries the date of the evidence behind it.
Score by categories
Code characteristics11.3

Admin key: an unidentified controlling contract (no single key can act alone; its signers and any delay are unverified), upgradeable without a meaningful timelock.

Dependency risk8.3

Uses 1 oracle (Orca consumes NO price oracle and this was verified by searching its entire source for pyth, switchboard, chainlink and wormhole with zero matches: there is no external price-feed CPI, no oracle account deserialization and no staleness handling anywhere in the program. THE TRAP WORTH RECORDING: the Whirlpools program contains an account type literally named Oracle, in state/oracle.rs, and it is NOT a price oracle. It holds adaptive-fee state, the AdaptiveFeeConstants and volatility accumulator, and its own comments describe mapping the square of the volatility accumulator to a fee rate. Anything pattern-matching on the name would record Orca as an oracle consumer and invert its risk profile. Orca is a PROVIDER: pool sqrt price and tick state are read by external consumers and Orca publishes its own price API. The real external-code dependency is different and more interesting. Whirlpools supports Token-2022, and its remaining-accounts handling defines TransferHook slices for the A and B tokens, rewards, inputs, intermediates, outputs, deposits and withdrawals, which means an ARBITRARY THIRD-PARTY PROGRAM CAN EXECUTE INSIDE A SWAP for a hooked mint. That exposure is PERMISSIONED rather than open: the source refuses a TransferHook mint unless a TokenBadge account has been initialised for it by Orca's config authority, and the same badge gate applies to PermanentDelegate, MintCloseAuthority, DefaultAccountState and Pausable, with NonTransferable hard-rejected and unknown extensions rejected by default. So the risk is issuer risk admitted by a gatekeeper: a badged PermanentDelegate or Pausable mint means its issuer can seize or freeze tokens sitting in Orca vaults. None of this appears in Orca's user-facing docs; it is read from its own source and its own committed audits.), composable with 3 other protocols.

Governance attack surface7.6

Top 10 holders control 60.39%, adjusted figure may still include pooled custody (untagged exchanges, infrastructure contracts) due to tagging coverage limits; exclusions require positive identification.

TVL profile5.5

TVL is 81% below this protocol's own peak; TVL change (6%) is within a stable range.

Team factors3.0

Anonymous team, a weak but real signal on its own.

Historical incidents2.3

No known own or inherited incidents.

Bug bounty1.5

Has a bug bounty program, hosted on Immunefi.

Protocol age1.5

2020 days live, past the ~1yr floor; treated the same as any older protocol, not scored progressively safer with more age.

Audit profile0.0

8 audits on record, most recent audit is recent (<=180d); the most recent audit found 0 High and 0 Medium severity issues. This reflects code quality at the time of that audit only, not a claim that these specific issues are still unresolved today.

Assets held (0)

No per-symbol breakdown of this protocol's value is published, so there is nothing to read here and nothing has been researched. For an exchange or a bridge this is usually a fact about the protocol rather than a gap: value sits in many user positions rather than in a held set of assets.

Dependencies (2)

Available with a plan. See pricing.

Incident history (0)

Available with a plan. See pricing.

Audit history (8)

Available with a plan. See pricing.

Also covered on Multi-Chain

This assessment follows Foreshock's published methodology. Exact category weights, scoring rules, thresholds, and aggregation logic are proprietary and not shown here. How to interpret this assessment

This reading will change.

This reading is fixed at the date above it, and it stays there. We keep re-scoring Orca DEX as the evidence moves, a new audit, a changed admin control, an incident, and this page is free to read and always will be. The updated reading is what a plan buys: you are told by email on the day it changes, instead of finding out the next time you happen to look.

Orca DEX risk score, audits and admin control · Foreshock