Axelar
TEMPEREDBridge / Messaging · Multi-chain · $500M+ TVL · 10 contracts
Official site: axelar.network ↗
749
3004756508251000
Confidence77%
Z-Factor0.78
Updated 2026-05-27Public scoreSecurity Profile
Access Control
72
72
Economic Soundness
68
68
Oracle Integrity
75
75
Compositional Risk
55
55
Governance
58
58
Maturity
78
78
Resilience
50
50
Supply Chain
75
75
Cross-Chain Messaging
60
60
Op Security
55
55
Cascade Exposure
99
99
Access Ctrl
72
72
Economic
68
68
Oracle
75
75
Compos.
55
55
Govern.
58
58
Maturity
78
78
Resilience
50
50
Supply Ch.
75
75
X-Chain
60
60
OpSec
55
55
Cascade
99
99
Min
50
Avg
68
Max
99
Audit History
NCC Group
2022-08
Ackee Blockchain
2022-06
Oak Security
2023-09
Bug Bounty Program
$2,250,000
Max payout on Immunefi
Assessment
Cross-chain messaging protocol with 52-month track record, no exploits. D4 and D10 low due to extreme cross-chain composition surface (60+ chains). Governance concerns (D5) and validator centralization risk limit score.
Dimension Breakdown
MethodologyAccess Control
72Weight 16% · 78% confidence
+24Validator set controls message relay (threshold signature)
+24Gateway contract with admin upgrade capability
+24Governance multisig can pause/unpause
-28Concerns: validator collusion threshold, upgrade key centralization
Provenance
Economic Soundness
68Weight 12% · 72% confidence
+17AXL token staking secures network (moderate security budget)
+17No direct lending/borrowing economics to exploit
+17Bridge relay fees are minimal attack surface
+17Risk: validator slashing economics untested at scale
Provenance
Oracle Integrity
75Weight 12% · 75% confidence
+19Validators act as oracle for cross-chain state
+19Multi-validator attestation reduces single-point failure
+19No external price oracle dependency
+19Risk: validator set IS the oracle, shared trust assumption
Provenance
Battle-Tested Maturity
78Weight 11% · 80% confidence
+20Mainnet live since January 2022 (52 months)
+20No protocol-level exploit (bridge hacks are common in sector)
+20Processed billions in cross-chain volume
+20Z-factor: 0.897
Provenance
Adversarial Resilienceredacted
50Weight 10% · 30% confidence
- Maximum resilience under independent adversarial testing
- Comprehensive security coverage across all attack surfaces
- Active bounty program incentivizes continuous scrutiny
- No validated adversarial findings — score set to neutral baseline
Provenance
Compositional Risk
55Weight 9% · 70% confidence
+18Cross-chain message relay = extreme compositional surface
+18GMP (General Message Passing) can compose arbitrary logic
-45Connected to 60+ chains, each adds risk surface
+18Squid Router integration adds DeFi composition layer
Provenance
Governance & Upgradeability
58Weight 9% · 72% confidence
+19Cosmos SDK governance with AXL token voting
+19Gateway upgradeable via governance proposals
-42Validator governance concerns raised by community
+19Limited timelock visibility on critical operations
Provenance
Cross-Chain Messaging
60Weight 9% · 72% confidence
+20Core product IS cross-chain messaging
+2060+ chain connections = massive bridge surface
+20Validator-based relay model (not trustless)
-40Governance concerns about validator centralization
Provenance
Operational Security
55Weight 9% · 60% confidence
-45No branch protection detected
+11Active CI/CD (100% success rate)
+11Commit signing: 94% verified
+11Strong PR review culture (77% reviewed)
Provenance
Cascade Exposure
99Weight 5% · 55% confidence
+33Appears in 1 cross-protocol cascade chain(s)
-1Failure cascades to 1 downstream protocol(s)
+33Member of 2 dependency cluster(s)
+33Source: cross_protocol_composition.json dependency analysis
Provenance
Supply Chain
75Weight 4% · 78% confidence
+19Cosmos SDK base (well-maintained)
+19Solidity gateway contracts on EVM chains
+19Multiple chain deployments increase supply chain surface
+19Dependency on relayer infrastructure
Provenance
Top Score Drivers
Dimensions with the greatest marginal impact on BRI.
Adversarial Resilience
50+32.2 potential
Compositional Risk
55+24.8 potential
Connected to 60+ chains, each adds risk surface
Operational Security
55+24.8 potential
No branch protection detected
Access Control
72+24.2 potential
Concerns: validator collusion threshold, upgrade key centralization
Governance & Upgradeability
58+22.5 potential
Validator governance concerns raised by community
Adversarial Risk Signals
Publicly verifiable security posture indicators.
Disclosure HistoryNot Assessed
Remediation VelocityNot Assessed
Bug Bounty ProgramNot Assessed
Audit CoverageNot Assessed
Incident HistoryNot Assessed
methodology v2.1formula v1.1weights v1.1evidence sha256:sha256:3...
Score History & Verification
Score provenance tracking begins with the next reassessment.
On-Chain Data
- Protocol Slug
- "axelar"
- Oracle
- BRORegistry (Base)
- Evidence
- IPFS (pinned)
- Staleness Threshold
- 24 hours
Read Score
registry.getScore("axelar")Reduce exploitable risk
Continuous adversarial analysis, vulnerability detection, and verified reassessment.
Embed this score
Live, updates automatically. Free for any site. Click-through links open the full report on BlackHart.
Style
Theme
Format
Preview
Copy iframe code
<iframe
src="https://blackhart.io/embed/oracle/axelar?variant=card&theme=dark"
title="BlackHart Risk Index: Axelar"
width="340"
height="290"
frameborder="0"
loading="lazy"
style="border:0; max-width:100%;"
></iframe>