Chainlink
MITHRILOracle Infrastructure · Multi-chain · $16B+ secured TVL · 20 contracts
Official site: chain.link ↗
890
3004756508251000
Confidence87%
Z-Factor0.94
Updated 2026-05-27Public scoreSecurity Profile
Access Control
88
88
Economic Soundness
92
92
Oracle Integrity
95
95
Compositional Risk
78
78
Governance
82
82
Maturity
96
96
Resilience
87
87
Supply Chain
90
90
Op Security
69
69
Cascade Exposure
46
46
Access Ctrl
88
88
Economic
92
92
Oracle
95
95
Compos.
78
78
Govern.
82
82
Maturity
96
96
Resilience
87
87
Supply Ch.
90
90
OpSec
69
69
Cascade
46
46
Min
46
Avg
82
Max
96
Audit History
Trail of Bits
2019-06
Sigma Prime
2020-11
Dedaub
2023-06
Bug Bounty Program
$3,000,000
Max payout on Immunefi
Assessment
Gold standard oracle infrastructure. 84+ months live, zero protocol exploits, secures $16B+. D4 penalized for massive downstream integration surface, D5 for centralized governance. Near-ADAMANTINE.
Dimension Breakdown
MethodologyAccess Control
88Weight 18% · 85% confidence
+22Multi-sig node operator management with OCR committee
+22Feed admin controls with configurable parameters
+22Timelocked updates for critical feed configurations
+22Staking v0.2 adds economic security layer
Provenance
Economic Soundness
92Weight 13% · 90% confidence
+23LINK token economics proven over 6+ years
+23Staking mechanism adds validator incentive alignment
+23No flash-loan attack surface in core oracle
+23Fee model sustainable with growing adoption
Provenance
Oracle Integrity
95Weight 13% · 95% confidence
+24Gold standard oracle: aggregation across 30+ node operators
+24Deviation and heartbeat thresholds per feed
+24Proof of Reserve for wrapped/bridged assets
+24CCIP extends oracle model to cross-chain
Provenance
Battle-Tested Maturity
96Weight 12% · 95% confidence
+19Live since May 2019 (84+ months)
+19Zero protocol-level exploits across any version
+19$16B+ TVL secured across DeFi
+1915+ audit firms over lifetime
Provenance
Governance & Upgradeability
82Weight 10% · 78% confidence
+27Chainlink Labs retains significant operational control
-18No on-chain governance token for feed management
+27Node operator selection is permissioned
+27Community program emerging but not decentralized governance
Provenance
Adversarial Resilienceredacted
87Weight 10% · 95% confidence
- Score derived from continuous adversarial security research
Provenance
Operational Security
69Weight 10% · 60% confidence
-16No branch protection detected
-16CI/CD present but unstable (40% success)
+14Commit signing: 100% verified
+14Strong PR review culture (87% reviewed)
Provenance
Compositional Risk
78Weight 5% · 80% confidence
+26Thousands of protocols depend on Chainlink feeds
+26Downstream integration failures are not Chainlink bugs
-22CCIP and VRF expand compositional surface
+26Feed-specific risk isolation (one bad feed != all)
Provenance
Cascade Exposure
46Weight 5% · 60% confidence
+15Appears in 2 cross-protocol cascade chain(s)
-54Failure cascades to 20 downstream protocol(s)
+15Member of 2 dependency cluster(s)
+15Source: cross_protocol_composition.json dependency analysis
Provenance
Supply Chain
90Weight 4% · 90% confidence
+22Standard Solidity, minimal external dependencies
+22Verified on all deployment chains
+22Professional dependency management
+22Regular compiler version updates
Provenance
Top Score Drivers
Dimensions with the greatest marginal impact on BRI.
Cascade Exposure
46+23.3 potential
Failure cascades to 20 downstream protocol(s)
Operational Security
69+22.3 potential
No branch protection detected
Access Control
88+13.7 potential
Multi-sig node operator management with OCR committee
Governance & Upgradeability
82+11.8 potential
Chainlink Labs retains significant operational control
Adversarial Resilience
87+8.3 potential
Adversarial Risk Signals
Publicly verifiable security posture indicators.
Disclosure HistoryNot Assessed
Remediation VelocityNot Assessed
Bug Bounty ProgramNot Assessed
Audit CoverageNot Assessed
Incident HistoryNot Assessed
methodology v2.1formula v1.1weights v1.1evidence sha256:sha256:0...
Score History & Verification
Score provenance tracking begins with the next reassessment.
On-Chain Data
- Protocol Slug
- "chainlink"
- Oracle
- BRORegistry (Base)
- Evidence
- IPFS (pinned)
- Staleness Threshold
- 24 hours
Read Score
registry.getScore("chainlink")Reduce exploitable risk
Continuous adversarial analysis, vulnerability detection, and verified reassessment.
Embed this score
Live, updates automatically. Free for any site. Click-through links open the full report on BlackHart.
Style
Theme
Format
Preview
Copy iframe code
<iframe
src="https://blackhart.io/embed/oracle/chainlink?variant=card&theme=dark"
title="BlackHart Risk Index: Chainlink"
width="340"
height="290"
frameborder="0"
loading="lazy"
style="border:0; max-width:100%;"
></iframe>