BlackHartBlackHart
Scores/Curve Finance

Curve Finance

MITHRIL

DEX / AMM · Multi-chain · $2B+ TVL · 30 contracts

Confidence 78%Z-Factor 0.93Updated 2026-05-06Public Score

Public risk assessment — scores are produced with the same methodology as monitored protocols

891
BRI Score
3004756508251000

Security Profile

Access Ctrl
90
Economic
92
Oracle
88
Compos.
78
Govern.
85
Maturity
96
Resilience
72
Supply Ch.
78
OpSec
85
Cascade
55
Min
55
Avg
82
Max
96

Audit History

Trail of Bits
2020-02
Quantstamp
2020-01
MixBytes
2023-06

Bug Bounty Program

$250,000
Max payout on Immunefi
View Program →

Assessment

Foundational DeFi AMM, 76+ months live, zero core logic exploits. StableSwap invariant is the most battle-tested AMM formula in DeFi. Vyper compiler dependency and massive downstream integration surface are the main risk vectors.

Dimension Breakdown

How scores work →
Access Control
Weight 18%90% conf
90
Excellent
  • DAO-controlled with veCRV voting
  • Admin functions behind timelock
  • Emergency kill switch on pools
  • Vyper-native reentrancy locks
Economic Soundness
Weight 13%88% conf
92
Excellent
  • StableSwap invariant proven over 5+ years
  • CRV emissions model well-understood
  • Deep liquidity across major pools
  • ve-tokenomics creates long-term alignment
Oracle Integrity
Weight 13%85% conf
88
Strong
  • Internal EMA oracles for TWAP
  • No external oracle dependency for core AMM
  • Price oracle manipulation resistant via EMA
  • Oracle used by external protocols (Curve oracle consumer)
Battle-Tested Maturity
Weight 12%95% conf
96
Excellent
  • Live since January 2020 (76+ months)
  • Survived multiple market crashes
  • Largest stableswap DEX in DeFi
  • Zero protocol-level exploits on V1/V2 core
  • Vyper compiler bug affected some pools (2023) but not core invariant
Governance & Upgradeability
Weight 10%85% conf
85
Strong
  • veCRV governance with 4-year lock maximum
  • Emergency DAO for rapid response
  • Timelock on parameter changes
  • Gauge weight voting transparent on-chain
Adversarial Resilience
Weight 10%85% conf
72
Good
  • Vyper compiler vulnerability disclosed 2023 (external dep, not logic bug)
  • Active bug bounty program
  • Multiple audit firms across versions
  • EMA oracle manipulation vectors researched extensively
Operational Security
Weight 10%82% conf
85
Strong
  • Emergency DAO for rapid pool kills
  • Active monitoring infrastructure
  • Multiple keeper networks
  • Professional team with deep DeFi expertise
Compositional Risk
Weight 5%80% conf
78
Good
  • Deep DeFi integration surface (lending, stablecoins)
  • LP tokens widely used as collateral
  • Metapool pattern adds composition complexity
  • Factory pools reduce per-pool audit coverage
Cascade Exposure
Weight 5%80% conf
55
Moderate
  • Curve pools are foundation for many stablecoin pegs
  • crvUSD creates additional dependency surface
  • Gauge emissions affect downstream protocol economics
  • LP token repricing cascades to lending protocols
Supply Chain
Weight 4%82% conf
78
Good
  • Vyper language (smaller auditor pool)
  • Custom math libraries (no OZ)
  • Verified on Etherscan
  • Factory pattern means new pools may have untested configs

Risk Drivers

Primary risk factors driving this score, ordered by severity.

Cascade Exposure55
Adversarial Resilience72
Compositional Risk78

Adversarial Risk Signals

Observable security posture indicators. These signals reflect publicly verifiable information and responsible disclosure outcomes. No specific vulnerability details are exposed.

Disclosure HistoryNot Assessed
Remediation VelocityNot Assessed
Bug Bounty ProgramNot Assessed
Audit CoverageNot Assessed
Incident HistoryNot Assessed
Deployed 2020-01-20Z-Factor 0.93010 active dimensions

Score History & Verification

Score provenance tracking begins with the next reassessment.

On-Chain Data

Protocol Slug
"curve"
Oracle
BRORegistry (Base)
Evidence
IPFS (pinned)
Staleness Threshold
24 hours
Read Score
registry.getScore("curve")

Reduce exploitable risk

BlackHart Monitoring provides continuous adversarial analysis, vulnerability detection, remediation support, and verified reassessment when your risk posture improves.