FORESHOCK

Every protocol here carries a dated score and the share of it backed by independently verified evidence. Where that share is still thin the assessment says so, is marked Low-signal rather than given a risk band, and holds every unevidenced category at the neutral midpoint instead of assuming it safe. Every score and its reasoning are free to read; the underlying dependency, incident and audit records are part of a plan. How a score is built, how to read one, and how the rubric was tested against real exploits are all in the methodology.

Coverage grows three ways: protocols Foreshock selects at its own discretion, protocols requested through the Request coverage button, and sponsored assessments delivered on an agreed timeline. No path has a guaranteed date except sponsorship.

Scores run from 0, the safest reading, to 100, the riskiest, where 50 is the neutral midpoint every unverified category is held at. Red marks a protocol scoring 50 or above, the band called Elevated: worse than neutral on the evidence gathered. Amber marks one below it, called Moderate. The boundary is fixed. It does not move as coverage grows, and it is not fitted to any backtest result.

SUNSwap V3

SUNSwap V3 official site N/A

Tron

:

  • Evidence: this reading is based on 100% of the scored weight, verified against named sources. Categories without verified data are excluded from the reading, never counted as safe.
  • Validation: measured against 3 comparable incidents/controls in this protocol's TVL, age and category bucket.
Score by categories
Code characteristics14.3

Admin key: eoa (a single key), upgradeable without a meaningful timelock.

Audit profile10.1

2 audits on record, most recent audit is over 2 years old; the most recent audit found 0 High and 0 Medium severity issues. This reflects code quality at the time of that audit only, not a claim that these specific issues are still unresolved today.

Dependency risk7.6

Uses 1 oracle (SunSwap V3 provides price data and consumes none: the forked core ships Uniswap's Oracle library documented in code as providing 'price and liquidity data useful for a wide variety of system designs' with observations collected in an array, and the periphery's OracleLibrary is a helper for reading SunSwap's OWN pools. A search of the entire repository found no Chainlink, no WinkLink and no external feed of any kind, and neither the SUN V3.0 whitepaper nor the MiCA whitepaper contains the words oracle, TWAP or price feed at all. The one concrete external dependency is WTRX, hard-coded in SunSwap's own scripts config and its front-end, through which the periphery routes native TRX. JustLend is deliberately NOT recorded as a dependency: the only first-party mentions are historical incentive programmes in the SUN whitepaper, not a protocol dependency. Cross-chain is future tense only in the MiCA whitepaper, which says the project 'plans to incorporate cross-chain trading', so no bridge is recorded. ONE SOURCING LIMITATION belongs in this record: docs.sun.io is a client-rendered application whose body text could not be read from this environment, so all of the above rests on the repository, the whitepapers and the front-end bundle rather than on the documentation prose. The docs sitemap was readable and contains no audit, security or bug-bounty page anywhere, which is what supports the negatives elsewhere in this record.), composable with 2 other protocols.

Governance attack surface7.6

Top 10 holders control 80.86%, adjusted figure may still include pooled custody (untagged exchanges, infrastructure contracts) due to tagging coverage limits; exclusions require positive identification.

TVL profile3.5

TVL change (1%) is within a stable range.

Bug bounty3.3

No bug bounty program on record.

Historical incidents2.3

No known own or inherited incidents.

Team factors1.8

Doxxed team, track record: unknown.

Protocol age1.5

963 days live, past the ~1yr floor; treated the same as any older protocol, not scored progressively safer with more age.

Assets held (1)

Available with a plan. See pricing.

Dependencies (2)

Available with a plan. See pricing.

Incident history (0)

Available with a plan. See pricing.

Audit history (2)

Available with a plan. See pricing.

This assessment follows Foreshock's published methodology. Exact category weights, scoring rules, thresholds, and aggregation logic are proprietary and not shown here. How to interpret this assessment