Reserve Protocol
DAMASCUSStablecoin Framework · Ethereum + Base · $300M+ TVL · 100 contracts
Official site: reserve.org ↗
753
3004756508251000
Confidence70%
Z-Factor0.75
Updated 2026-05-27Public scoreSecurity Profile
Access Control
72
72
Economic Soundness
68
68
Oracle Integrity
70
70
Compositional Risk
55
55
Governance
70
70
Maturity
62
62
Resilience
40
40
Supply Chain
75
75
Op Security
58
58
Cascade Exposure
100
100
Access Ctrl
72
72
Economic
68
68
Oracle
70
70
Compos.
55
55
Govern.
70
70
Maturity
62
62
Resilience
40
40
Supply Ch.
75
75
OpSec
58
58
Cascade
100
100
Min
40
Avg
67
Max
100
Audit History
Trail of Bits
2023-01
Solidified
2023-01
Halborn
2023-06
Code4rena
2023-01
Bug Bounty Program
$10,000,000
Max payout on Cantina
Assessment
Complex basket stablecoin with 100+ contracts and active Cantina bounty ($10M max). D4 very low (55) due to extreme compositional complexity. D6 moderate (62) for 24-month V3 history. Active BlackHart research target.
Dimension Breakdown
MethodologyAccess Control
72Weight 18% · 75% confidence
+18Governor-based ACL with timelocked execution
+18BackingManager controls basket rebalancing
+18StRSR staking for governance participation
+18Complex role hierarchy across 100+ contracts
Provenance
Economic Soundness
68Weight 13% · 72% confidence
+17Basket stablecoin with diversified collateral
+17Revenue distribution and RSR overcollateralization
+17Dutch auction trading for basket rebalancing
+17Complex economic interactions between RToken, RSR, and revenue
Provenance
Oracle Integrity
70Weight 13% · 72% confidence
+18Chainlink feeds with fallback mechanisms
+18Per-collateral oracle configuration
+18Oracle staleness checks with configurable windows
+18Multiple oracle dependencies across collateral basket
Provenance
Battle-Tested Maturity
62Weight 12% · 68% confidence
+16V3 live since mid-2023 (~24 months), V1 concepts since 2021
+16eUSD and other RTokens deployed
+16No protocol-level exploit on V3
+16Z-factor: 0.8
Provenance
Governance & Upgradeability
70Weight 10% · 72% confidence
+18Governor Alexios with timelocked execution
+18StRSR staking for voting power
+18Emergency mechanisms (freezing, pausing)
+18Governance delay provides safety window
Provenance
Adversarial Resilienceredacted
40Weight 10% · 95% confidence
- Score derived from continuous adversarial security research
Provenance
Operational Security
58Weight 10% · 60% confidence
-42No branch protection detected
+12Active CI/CD (100% success rate)
+12Commit signing: 100% verified
+12Minimal development activity (1 commits/month)
Provenance
Compositional Risk
55Weight 5% · 70% confidence
+18Extreme compositional complexity: 100+ contracts
+18RToken composes basket of arbitrary ERC-20 collateral
+18BackingManager, Broker, Distributor, Furnace interactions
-45Each collateral plugin adds composition risk
Provenance
Cascade Exposure
100Weight 5% · 55% confidence
+33Appears in 1 cross-protocol cascade chain(s)
+33Member of 2 dependency cluster(s)
+33Source: cross_protocol_composition.json dependency analysis
Provenance
Supply Chain
75Weight 4% · 72% confidence
+19Modern Solidity (0.8.x) with OpenZeppelin
+19Plugin architecture means varied dependency quality
+19Verified contracts on Etherscan
+19Large codebase increases supply chain surface
Provenance
Top Score Drivers
Dimensions with the greatest marginal impact on BRI.
Adversarial Resilience
40+43.4 potential
Access Control
72+27.6 potential
Governor-based ACL with timelocked execution
Battle-Tested Maturity
62+26.7 potential
V3 live since mid-2023 (~24 months), V1 concepts since 2021
Operational Security
58+25.3 potential
No branch protection detected
Economic Soundness
68+23.3 potential
Basket stablecoin with diversified collateral
Adversarial Risk Signals
Publicly verifiable security posture indicators.
Disclosure HistoryNot Assessed
Remediation VelocityNot Assessed
Bug Bounty ProgramNot Assessed
Audit CoverageNot Assessed
Incident HistoryNot Assessed
methodology v2.1formula v1.1weights v1.1evidence sha256:sha256:6...
Score History & Verification
Score provenance tracking begins with the next reassessment.
On-Chain Data
- Protocol Slug
- "reserve"
- Oracle
- BRORegistry (Base)
- Evidence
- IPFS (pinned)
- Staleness Threshold
- 24 hours
Read Score
registry.getScore("reserve")Reduce exploitable risk
Continuous adversarial analysis, vulnerability detection, and verified reassessment.
Embed this score
Live, updates automatically. Free for any site. Click-through links open the full report on BlackHart.
Style
Theme
Format
Preview
Copy iframe code
<iframe
src="https://blackhart.io/embed/oracle/reserve?variant=card&theme=dark"
title="BlackHart Risk Index: Reserve Protocol"
width="340"
height="290"
frameborder="0"
loading="lazy"
style="border:0; max-width:100%;"
></iframe>