BlackHartBlackHart
Scores/dYdX/Provenance/Access Control
D1

Access Control

Permission models, admin surface, reentrancy protection, and authorization boundaries. #1 exploit vector by dollar loss in DeFi history.

Weight 18%88% confidence
76
Good
info

How This Score Is Built

Permission models, admin surface, reentrancy protection, and authorization boundaries. #1 exploit vector by dollar loss in DeFi history.

+23Strong positive
+12Positive
+5Slight positive
−15Strong negative
−8Negative
−3Slight negative

Scoring Tree

BRI Formula
300 + 700 × ∏(Dᵢ/100)^wᵢ
807
Current BRI
D1Access Control
Weight 18%
76
(76/100)^0.18 = 0.9518
Contributing Factors
+15Cosmos-based chain with validator set
+15Smart contract bridge to Ethereum
+15Governance controls protocol parameters
+15Operator permissions for market creation
+15ClobPairIdFilter bypass: authenticator ACL on trading sub-keys can be circumvented, enabling full account drain from restricted keys
Evidence Sources
blackhart_analysisMay 13sha256:a40c26c9f74f....View
blackhart_analysisMay 17sha256:a2861c700c29....View

Score Composition

+15

Cosmos-based chain with validator set

Strong positiveopen_in_newSource CodeMay 13, 2026
+15

Smart contract bridge to Ethereum

Strong positiveopen_in_newSource CodeMay 13, 2026
+15

Governance controls protocol parameters

Strong positiveopen_in_newSource CodeMay 13, 2026
+15

Operator permissions for market creation

Strong positiveopen_in_newSource CodeMay 13, 2026
+15

ClobPairIdFilter bypass: authenticator ACL on trading sub-keys can be circumvented, enabling full account drain from restricted keys

Strong positiveopen_in_newSource CodeMay 13, 2026

Evidence Chain (2 files)

GitHub APIMay 17, 2026, 06:58 PM
open_in_newGitHub (/)
sha256:a2861c700c29...
BlackHart AnalysisMay 13, 2026, 06:30 PM
open_in_newAccess Control — Source Code
sha256:a40c26c9f74f...

Score History

No dimension-level score changes recorded yet.

Methodology: 2.1Formula: 1.1Weights: 1.1