FORESHOCK

Every protocol here carries a dated score and the share of it backed by independently verified evidence. Where that share is still thin the assessment says so, is marked Low-signal rather than given a risk band, and holds every unevidenced category at the neutral midpoint instead of assuming it safe. Every score and its reasoning are free to read; the underlying dependency, incident and audit records are part of a plan. How a score is built, how to read one, and how the rubric was tested against real exploits are all in the methodology.

Coverage grows three ways: protocols Foreshock selects at its own discretion, protocols requested through the Request coverage button, and sponsored assessments delivered on an agreed timeline. No path has a guaranteed date except sponsorship.

Scores run from 0, the safest reading, to 100, the riskiest, where 50 is the neutral midpoint every unverified category is held at. Red marks a protocol scoring 50 or above, the band called Elevated: worse than neutral on the evidence gathered. Amber marks one below it, called Moderate. The boundary is fixed. It does not move as coverage grows, and it is not fitted to any backtest result.

Symbiotic

Symbiotic official site N/A

Ethereum

:

  • Evidence: this reading is based on 100% of the scored weight, verified against named sources. Categories without verified data are excluded from the reading, never counted as safe.
  • Validation: the rubric is backtested against past exploits of protocols in the same TVL, age and category bucket. None has been evaluated for this one yet, so the reading rests on its evidence alone.
Score by categories
Dependency risk8.9

Uses 1 oracle (The dependency set here is unusually concrete because it is readable in Symbiotic's own contract source, not just its prose: AaveV3Adapter, MorphoVaultV2Adapter and EulerAdapter each carry an immutable pointer to the external protocol, and every adapter inherits CoWSwapConverter and MerklClaimer, so CoW Protocol and Merkl are dependencies of ALL of them rather than of one. The corresponding factories are deployed and listed on Symbiotic's own addresses page. On oracles the honest record is a documented silence with a documented risk: Symbiotic's Liquid Lane risk list names 'Oracle provider-related risks (asset prices and NAV reporting)' and warns that underlying asset prices may move unfavourably leading to NAV impairment, but NO provider is named on any page checked, including the RFQ how-it-works page which describes market makers signing bids without saying how price is derived. Symbiotic consumes price and NAV data; it does not publish it. Note also what is deliberately absent: the protocol-wide list of accepted collateral assets is not enumerated in the current V2 docs, so no LST collateral is recorded. Liquid Lane vaults take USDC exclusively. The architecture is permissionless by design and Symbiotic says so, warning that vaults using liquidity adapters carry 'additional operational and financial risks beyond the application's own infrastructure'.), composable with 6 other protocols.

Audit profile8.0

3 audits on record, most recent audit is 1-2 years old; the most recent audit found 0 High and 4 Medium severity issues. This reflects code quality at the time of that audit only, not a claim that these specific issues are still unresolved today.

Governance attack surface7.0

No governance token; control sits with multisig rather than a vote, so decision rights are concentrated rather than capturable. The form of that key is scored separately under code characteristics.

Code characteristics6.7

Admin key: 2/3 multisig (requires 2 of 3 keys to act), open source.

TVL profile5.5

TVL is 83% below this protocol's own peak; TVL change (38%) is within a stable range.

Historical incidents2.2

No known own or inherited incidents.

Team factors1.7

Doxxed team, track record: unknown.

Bug bounty1.5

Has a bug bounty program, up to $500 000.

Protocol age1.5

815 days live, past the ~1yr floor; treated the same as any older protocol, not scored progressively safer with more age.

Assets held (4)

Available with a plan. See pricing.

Dependencies (2)

Available with a plan. See pricing.

Incident history (0)

Available with a plan. See pricing.

Audit history (3)

Available with a plan. See pricing.

This assessment follows Foreshock's published methodology. Exact category weights, scoring rules, thresholds, and aggregation logic are proprietary and not shown here. How to interpret this assessment