FORESHOCK

Every protocol here carries a dated score and the share of it backed by independently verified evidence. Where that share is still thin the assessment says so, is marked Low-signal rather than given a risk band, and holds every unevidenced category at the neutral midpoint instead of assuming it safe. Every score and its reasoning are free to read; the underlying dependency, incident and audit records are part of a plan. How a score is built, how to read one, and how the rubric was tested against real exploits are all in the methodology.

Coverage grows three ways: protocols Foreshock selects at its own discretion, protocols requested through the Request coverage button, and sponsored assessments delivered on an agreed timeline. No path has a guaranteed date except sponsorship.

Scores run from 0, the safest reading, to 100, the riskiest, where 50 is the neutral midpoint every unverified category is held at. Red marks a protocol scoring 50 or above, the band called Elevated: worse than neutral on the evidence gathered. Amber marks one below it, called Moderate. The boundary is fixed. It does not move as coverage grows, and it is not fitted to any backtest result.

PancakeSwap AMM V3

PancakeSwap AMM V3 official site N/A

Multi-Chain

:

  • Evidence: this reading is based on 100% of the scored weight, verified against named sources. Categories without verified data are excluded from the reading, never counted as safe.
  • Validation: measured against 1 comparable incident/control in this protocol's TVL, age and category bucket.
Score by categories
Audit profile9.9

4 audits on record, most recent audit is over 2 years old; the most recent audit found 0 High and 2 Medium severity issues. This reflects code quality at the time of that audit only, not a claim that these specific issues are still unresolved today.

Code characteristics9.0

Admin key: an unidentified controlling contract (no single key can act alone; its signers and any delay are unverified), open source.

Governance attack surface7.5

Top 10 holders control 71.2%, adjusted figure may still include pooled custody (untagged exchanges, infrastructure contracts) due to tagging coverage limits; exclusions require positive identification.

Dependency risk6.7

Uses 1 oracle (PancakeSwap V3's AMM core has NO external price-oracle dependency, and this was verified in the source rather than inferred: PancakeV3Pool.sol's complete external import list is its own libraries plus one PancakeSwap package, IPancakeV3LmPool, with no Chainlink, Pyth, Band or any other feed anywhere. The direction is the reverse: each pool holds a 65 535-slot observations array and its own Oracle library describes itself as providing 'price and liquidity data useful for a wide variety of system designs', with an OracleLibrary consult() helper in the periphery offered TO integrators returning arithmeticMeanTick and harmonicMeanLiquidity. So the correct dependency framing is downstream, not upstream: the risk sits with protocols relying on V3 TWAPs, not with V3. One cross-chain dependency exists and it belongs to the TOKEN, not to the AMM: CAKE 'uses LayerZero v1 OFT standard to bridge across chains' with BSC as the canonical chain, corroborated by separate audits of the CAKE bridge on PancakeSwap's own registry. V3 pools on each chain are independent deployments with no cross-chain messaging between them, so LayerZero must not be recorded as an AMM dependency.), composable with 1 other protocol.

TVL profile3.5

TVL change (12%) is within a stable range.

Team factors3.0

Anonymous team, a weak but real signal on its own.

Historical incidents2.2

No known own or inherited incidents.

Protocol age1.5

1250 days live, past the ~1yr floor; treated the same as any older protocol, not scored progressively safer with more age.

Bug bounty0.7

Has a bug bounty program, up to $1 000 000, hosted on Immunefi.

Dependencies (2)

Available with a plan. See pricing.

Incident history (0)

Available with a plan. See pricing.

Audit history (4)

Available with a plan. See pricing.

This assessment follows Foreshock's published methodology. Exact category weights, scoring rules, thresholds, and aggregation logic are proprietary and not shown here. How to interpret this assessment

PancakeSwap AMM V3 · Foreshock