Convex Finance
MITHRILYield / Governance · Ethereum · $2B+ TVL · 15 contracts
Public risk assessment — scores are produced with the same methodology as monitored protocols
Security Profile
80
85
88
65
78
88
82
82
80
80
85
88
65
78
88
82
82
80
Audit History
Bug Bounty Program
Assessment
Largest Curve governance aggregator, 60+ months live with zero exploits. Deep Curve dependency is both strength (proven integration) and risk (single protocol dependency). vlCVX governance model well-tested.
Dimension Breakdown
How scores work →- Voter proxy pattern for Curve governance
- Multisig admin controls
- Operator permissions for pool management
- vlCVX governance for protocol direction
- CRV yield amplification model proven
- CVX tokenomics well-understood
- Liquid staking of veCRV position
- Fee distribution transparent
- No external oracle dependency
- Relies on Curve pool pricing
- Yield calculations based on on-chain state
- No manipulation surface in core
- Live since May 2021 (60+ months)
- Largest Curve governance aggregator
- Zero protocol-level exploits
- Stable operations through multiple market cycles
- vlCVX governance for gauge weights
- Multisig for emergency actions
- Community governance maturing
- Significant influence over Curve governance
- Multiple audits
- Clean exploit history
- Active bounty program
- Well-understood attack surface
- Professional team operations
- Automated reward distribution
- Monitoring infrastructure
- Responsive to security disclosures
- Deep dependency on Curve protocol
- Voter proxy is single point of integration
- cvxCRV/CVX liquidity essential
- Frax, Aura compose on top
- Standard Solidity
- OpenZeppelin libraries
- Verified contracts
- Moderate dependency graph
Additional Dimensions
- Not assessed — excluded from BRI computation
Risk Drivers
Primary risk factors driving this score, ordered by severity.
Adversarial Risk Signals
Observable security posture indicators. These signals reflect publicly verifiable information and responsible disclosure outcomes. No specific vulnerability details are exposed.
Score History & Verification
Score provenance tracking begins with the next reassessment.
On-Chain Data
- Protocol Slug
- "convex"
- Oracle
- BRORegistry (Base)
- Evidence
- IPFS (pinned)
- Staleness Threshold
- 24 hours
registry.getScore("convex")Reduce exploitable risk
BlackHart Monitoring provides continuous adversarial analysis, vulnerability detection, remediation support, and verified reassessment when your risk posture improves.