Convex Finance
DAMASCUSYield / Governance · Ethereum · $2B+ TVL · 15 contracts
Official site: convexfinance.com ↗
839
3004756508251000
Confidence68%
Z-Factor0.88
Updated 2026-05-27Public scoreSecurity Profile
Access Control
80
80
Economic Soundness
85
85
Oracle Integrity
88
88
Compositional Risk
65
65
Governance
78
78
Maturity
88
88
Resilience
82
82
Supply Chain
82
82
Op Security
42
42
Cascade Exposure
88
88
Access Ctrl
80
80
Economic
85
85
Oracle
88
88
Compos.
65
65
Govern.
78
78
Maturity
88
88
Resilience
82
82
Supply Ch.
82
82
OpSec
42
42
Cascade
88
88
Min
42
Avg
78
Max
88
Audit History
MixBytes
2021-06
Peckshield
2022-01
Bug Bounty Program
$250,000
Max payout on Self-hosted
Assessment
Largest Curve governance aggregator, 60+ months live with zero exploits. Deep Curve dependency is both strength (proven integration) and risk (single protocol dependency). vlCVX governance model well-tested.
Dimension Breakdown
MethodologyAccess Control
80Weight 18% · 80% confidence
+27Multisig admin controls
+27Operator permissions for pool management
+27vlCVX governance for protocol direction
Provenance
Economic Soundness
85Weight 13% · 82% confidence
+21CRV yield amplification model proven
+21CVX tokenomics well-understood
+21Liquid staking of veCRV position
+21Fee distribution transparent
Provenance
Oracle Integrity
88Weight 13% · 85% confidence
+22No external oracle dependency
+22Relies on Curve pool pricing
+22Yield calculations based on on-chain state
+22No manipulation surface in core
Provenance
Battle-Tested Maturity
88Weight 12% · 88% confidence
+22Live since May 2021 (60+ months)
+22Largest Curve governance aggregator
+22Zero protocol-level exploits
+22Stable operations through multiple market cycles
Provenance
Governance & Upgradeability
78Weight 10% · 78% confidence
+20vlCVX governance for gauge weights
+20Multisig for emergency actions
+20Community governance maturing
+20Significant influence over Curve governance
Provenance
Adversarial Resilienceredacted
82Weight 10% · 78% confidence
- Multiple audits
- Clean exploit history
- Active bounty program
- Well-understood attack surface
Provenance
Operational Security
42Weight 10% · 35% confidence
-29No branch protection detected
+10No CI/CD pipeline detected
-29Weak PR review coverage (0%)
+10Minimal development activity (0 commits/month)
Provenance
Compositional Risk
65Weight 5% · 72% confidence
+22Deep dependency on Curve protocol
+22cvxCRV/CVX liquidity essential
+22Frax, Aura compose on top
Provenance
Cascade Exposure
88Weight 5% · 65% confidence
+29Appears in 3 cross-protocol cascade chain(s)
+29Member of 1 dependency cluster(s)
+29Source: cross_protocol_composition.json dependency analysis
Provenance
Supply Chain
82Weight 4% · 82% confidence
+20Standard Solidity
+20OpenZeppelin libraries
+20Verified contracts
+20Moderate dependency graph
Provenance
Top Score Drivers
Dimensions with the greatest marginal impact on BRI.
Operational Security
42+48.9 potential
No branch protection detected
Access Control
80+22.1 potential
Multisig admin controls
Governance & Upgradeability
78+13.6 potential
vlCVX governance for gauge weights
Compositional Risk
65+11.7 potential
Deep dependency on Curve protocol
Economic Soundness
85+11.5 potential
CRV yield amplification model proven
Adversarial Risk Signals
Publicly verifiable security posture indicators.
Disclosure HistoryNot Assessed
Remediation VelocityNot Assessed
Bug Bounty ProgramNot Assessed
Audit CoverageNot Assessed
Incident HistoryNot Assessed
methodology v2.1formula v1.0weights v1.0evidence sha256:sha256:5...
Score History & Verification
Score provenance tracking begins with the next reassessment.
On-Chain Data
- Protocol Slug
- "convex"
- Oracle
- BRORegistry (Base)
- Evidence
- IPFS (pinned)
- Staleness Threshold
- 24 hours
Read Score
registry.getScore("convex")Reduce exploitable risk
Continuous adversarial analysis, vulnerability detection, and verified reassessment.
Embed this score
Live, updates automatically. Free for any site. Click-through links open the full report on BlackHart.
Style
Theme
Format
Preview
Copy iframe code
<iframe
src="https://blackhart.io/embed/oracle/convex?variant=card&theme=dark"
title="BlackHart Risk Index: Convex Finance"
width="340"
height="290"
frameborder="0"
loading="lazy"
style="border:0; max-width:100%;"
></iframe>