BlackHartBlackHart
Scores/DeFi Saver

DeFi Saver

DAMASCUS

DeFi Automation · Ethereum + L2s · $500M+ managed TVL · 20 contracts

Official site: defisaver.com

792
3004756508251000
Confidence67%
Z-Factor0.85
Updated 2026-05-27Public score

Security Profile

Access Ctrl
78
Economic
80
Oracle
78
Compos.
58
Govern.
52
Maturity
85
Resilience
50
Supply Ch.
80
OpSec
57
Cascade
100
Min
50
Avg
72
Max
100

Audit History

Consensys Diligence
2020-06
Dedaub
2022-11

Bug Bounty Program

$350,000
Max payout on Immunefi
View Program

Assessment

Veteran DeFi management tool with excellent maturity and clean track record. Survived Black Thursday stress test. High compositional risk by design (D4=58) and centralized governance (D5=52) are structural limitations. Slightly above Instadapp due to simpler architecture.

Dimension Breakdown

Methodology
Access Control
Weight 18% · 75% confidence
78
+20Smart wallet with owner authority model
+20Automation permissions granted by user explicitly
+20Recipe/action-based architecture with permissioned actions
+20Bot automation requires explicit user opt-in
Provenance
Economic Soundness
Weight 13% · 78% confidence
80
+20Fee-based model on automation actions (boost/repay)
+20No protocol token creating economic distortions
+20Passes through underlying protocol economics cleanly
+20Automation trigger economics well-understood
Provenance
Oracle Integrity
Weight 13% · 75% confidence
78
+20Uses Chainlink for automation trigger prices
+20Inherits oracle deps from underlying protocols (Aave, Maker, etc.)
+20Automation triggers have oracle-sensitive timing
+20Price feed dependency for CDP ratio monitoring
Provenance
Battle-Tested Maturity
Weight 12% · 82% confidence
85
+17Live since 2019 (originally CDP Saver for MakerDAO)
+17No protocol exploit across any version
+17Battle-tested through multiple market crashes (2020, 2022)
+17Automation worked correctly during Black Thursday
Provenance
Governance & Upgradeability
Weight 10% · 65% confidence
52
-12No governance token (team-controlled)
-12Centralized decision-making on feature additions
-12No on-chain governance mechanism
-12Transparent team but unilateral control
Provenance
Adversarial Resilienceredacted
Weight 10% · 30% confidence
50
  • Maximum resilience under independent adversarial testing
  • Comprehensive security coverage across all attack surfaces
  • Mature codebase with extensive battle testing
  • No validated adversarial findings — score set to neutral baseline
Provenance
Operational Security
Weight 10% · 50% confidence
57
-43No branch protection detected
+14No CI/CD pipeline detected
+14Moderate development (17 commits/month)
+14No CI pipeline for deployment verification
Provenance
Compositional Risk
Weight 5% · 72% confidence
58
+14Composes multiple DeFi protocols by design
+14Recipe system creates cross-protocol transaction bundles
+14Flash loan integration adds composition surface
+14Automation bots create time-dependent composition risk
Provenance
Cascade Exposure
Weight 5% · 50% confidence
100
+33Member of 1 dependency cluster(s)
+33No cross-protocol cascade exposure detected
+33Source: cross_protocol_composition.json dependency analysis
Provenance
Supply Chain
Weight 4% · 78% confidence
80
+20Standard Solidity dependencies
+20OpenZeppelin libraries
+20Integration dependencies on target protocols
+20Automation infrastructure is off-chain component
Provenance

Top Score Drivers

Dimensions with the greatest marginal impact on BRI.

Adversarial Resilience
50+35.3 potential
Governance & Upgradeability
52+33.2 potential
No governance token (team-controlled)
Operational Security
57+28.4 potential
No branch protection detected
Access Control
78+22.5 potential
Smart wallet with owner authority model
Oracle Integrity
78+16.2 potential
Uses Chainlink for automation trigger prices

Adversarial Risk Signals

Publicly verifiable security posture indicators.

Disclosure HistoryNot Assessed
Remediation VelocityNot Assessed
Bug Bounty ProgramNot Assessed
Audit CoverageNot Assessed
Incident HistoryNot Assessed
Deployed 2019-09-0110 dimensionsProvenance Ledger
methodology v2.1formula v1.1weights v1.1evidence sha256:sha256:4...

Score History & Verification

Score provenance tracking begins with the next reassessment.

On-Chain Data

Protocol Slug
"defisaver"
Oracle
BRORegistry (Base)
Evidence
IPFS (pinned)
Staleness Threshold
24 hours
Read Score
registry.getScore("defisaver")
Reduce exploitable risk

Continuous adversarial analysis, vulnerability detection, and verified reassessment.

Embed this score

Live, updates automatically. Free for any site. Click-through links open the full report on BlackHart.

Public
Style
Theme
Format
Preview
Copy iframe code
<iframe
  src="https://blackhart.io/embed/oracle/defisaver?variant=card&theme=dark"
  title="BlackHart Risk Index: DeFi Saver"
  width="340"
  height="290"
  frameborder="0"
  loading="lazy"
  style="border:0; max-width:100%;"
></iframe>