FORESHOCK

Every protocol here carries a dated score and the share of it backed by independently verified evidence. Where that share is still thin the assessment says so, is marked Low-signal rather than given a risk band, and holds every unevidenced category at the neutral midpoint instead of assuming it safe. Every score and its reasoning are free to read; the underlying dependency, incident and audit records are part of a plan. How a score is built, how to read one, and how the rubric was tested against real exploits are all in the methodology.

Coverage grows three ways: protocols Foreshock selects at its own discretion, protocols requested through the Request coverage button, and sponsored assessments delivered on an agreed timeline. No path has a guaranteed date except sponsorship.

Scores run from 0, the safest reading, to 100, the riskiest, where 50 is the neutral midpoint every unverified category is held at. Red marks a protocol scoring 50 or above, the band called Elevated: worse than neutral on the evidence gathered. Amber marks one below it, called Moderate. The boundary is fixed. It does not move as coverage grows, and it is not fitted to any backtest result.

Stader

Stader official site N/A

Multi-Chain

:

  • Evidence: this reading is based on 100% of the scored weight, verified against named sources. Categories without verified data are excluded from the reading, never counted as safe.
  • Validation: measured against 2 comparable incidents/controls in this protocol's TVL, age and category bucket.
Score by categories
Audit profile13.9

9 audits on record, most recent audit is over 2 years old; the most recent audit found 1 High and 14 Medium severity issues. This reflects code quality at the time of that audit only, not a claim that these specific issues are still unresolved today.

Dependency risk9.0

Uses 2 oracles (The ETHx exchange rate does not come from a market oracle: it is 'the total ETHx supply divided by the total ETH that is staked + in the process of being staked', reported for the same block number by StaderOracle, and on chain StaderStakePoolsManager.totalAssets() reads that value. The operator set is PERMISSIONED and Stader publishes the admission bar plainly: KYC and KYB verification, demonstrated prior proficiency, security collateral at a level set by Stader DAO, and passing a DAO governance vote. Three consensus rules are documented, a majority rule, a median-of-two-thirds rule, and a deviation-threshold gate, plus a SAFE MODE where an out-of-range rate triggers inspection and 'The Stader manager is expected to verify the validity of the new exchange rate'. Stader's own security page concedes the concentration: the system 'requires a strict majority of Oracle operators to function', and its own staking-risks page lists 'Exchange Rate Manipulation' as a named risk. Node operators run in two pools, one permissionless with a bond of 4 ETH plus at least 0.4 ETH of SD, and one PERMISSIONED whose operators must be whitelisted by the Stader team before they can register at all. An insurance fund contract exists at 0xbe3781CE437Cc3fC8c8167913B4d462347D11F20 with NO published size, funding source or claims process, which is recorded as address-only. One thing that would be easy to get wrong: Stader deploys an 'ETHx_ETH Feed Chainlink V3 Format' adapter at 0xdd487947c579af433AeeF038Bf1573FdBB68d2d3, which is a Chainlink-INTERFACE wrapper over Stader's own oracle rather than a Chainlink feed Stader consumes; recording Chainlink as an upstream dependency would invert the direction. No bridge is recorded: ETHx exists on Arbitrum and Optimism per the repo README but no first-party source describes the mechanism.), composable with 2 other protocols.

Governance attack surface7.5

Top 10 holders control 71.61%, adjusted figure may still include pooled custody (untagged exchanges, infrastructure contracts) due to tagging coverage limits; exclusions require positive identification.

TVL profile3.5

TVL change (29%) is within a stable range.

Code characteristics3.0

Admin key: 168h timelock in place, open source.

Historical incidents2.2

No known own or inherited incidents.

Team factors1.7

Doxxed team, track record: unknown.

Protocol age1.5

1721 days live, past the ~1yr floor; treated the same as any older protocol, not scored progressively safer with more age.

Bug bounty0.7

Has a bug bounty program, up to $1 000 000, hosted on Immunefi.

Assets held (1)

Available with a plan. See pricing.

Dependencies (2)

Available with a plan. See pricing.

Incident history (0)

Available with a plan. See pricing.

Audit history (9)

Available with a plan. See pricing.

This assessment follows Foreshock's published methodology. Exact category weights, scoring rules, thresholds, and aggregation logic are proprietary and not shown here. How to interpret this assessment