BlackHartBlackHart
Scores/Pyth Network

Pyth Network

DAMASCUS

Oracle Infrastructure · Solana + Multi-chain · N/A (oracle) TVL · 8 contracts

Confidence 73%Z-Factor 0.80Updated 2026-05-13Public Score

Public risk assessment — scores are produced with the same methodology as monitored protocols

845
BRI Score
3004756508251000

Security Profile

Access Ctrl
82
Economic
88
Oracle
90
Compos.
75
Govern.
75
Maturity
72
Resilience
50
Supply Ch.
78
OpSec
80
Cascade
100
Min
50
Avg
79
Max
100

Audit History

OtterSec
2023-05
Zellic
2023-09
Gupta
2024-01

Bug Bounty Program

$500,000
Max payout on Immunefi
View Program →

Assessment

Leading pull-based oracle, second to Chainlink. Younger (24 months EVM) with Wormhole dependency for cross-chain. D5 penalized for centralized governance, D6 for lower maturity vs Chainlink. Clean security record.

Dimension Breakdown

How scores work →
Access Control
Weight 18%75% conf
82
Strong
  • Data provider permissioning by Pyth Data Association
  • Price feed ACL with publisher whitelist
  • Pythnet validator set manages consensus
  • Wormhole guardian attestation for cross-chain delivery
Economic Soundness
Weight 13%82% conf
88
Strong
  • Pull-based model: consumers pay for price updates
  • PYTH token staking for data quality incentives
  • Publisher staking mechanism (emerging)
  • Sustainable fee model from consumer demand
Oracle Integrity
Weight 13%88% conf
90
Excellent
  • Pull-based oracle model (consumer-initiated updates)
  • Confidence intervals quantify price uncertainty
  • EMA (Exponential Moving Average) smoothing
  • Multi-publisher aggregation with outlier filtering
Battle-Tested Maturity
Weight 12%72% conf
72
Good
  • EVM mainnet since 2023 (~24 months)
  • Solana-native since 2021 (48 months)
  • No protocol-level exploit
  • Growing adoption but younger than Chainlink
  • Z-factor: 0.750 (EVM age)
Governance & Upgradeability
Weight 10%70% conf
75
Good
  • Pyth DAO governance via PYTH token (launched Nov 2023)
  • Pyth Data Association retains significant operational control
  • Governance scope limited to token distribution and parameters
  • Decentralization roadmap emerging
Adversarial Resilience
Weight 10%30% conf
50
Concerning
  • Maximum resilience under independent adversarial testing
  • Comprehensive security coverage across all attack surfaces
  • Active bounty program incentivizes continuous scrutiny
  • No validated adversarial findings — score set to neutral baseline
Operational Security
Weight 10%75% conf
80
Strong
  • Professional operations by Pyth Data Association
  • Publisher SLA monitoring
  • Multi-chain deployment and monitoring
  • Growing operational maturity
Compositional Risk
Weight 5%72% conf
75
Good
  • Wormhole dependency for cross-chain price delivery
  • Multi-chain deployment across 50+ chains
  • Pythnet as custom appchain adds unique infrastructure
  • Deep downstream integration (Synthetix, Marginfi, etc.)
Cascade Exposure
Weight 5%55% conf
100
Excellent
  • Appears in 1 cross-protocol cascade chain(s)
  • Member of 2 dependency cluster(s)
  • Score: 100/100 (higher = more isolated from systemic risk)
  • Source: cross_protocol_composition.json dependency analysis
Supply Chain
Weight 4%74% conf
78
Good
  • Rust (Solana/Pythnet) + Solidity (EVM) dual codebase
  • Wormhole SDK dependency for cross-chain
  • Hermes API for off-chain price retrieval
  • Multi-language supply chain adds complexity

Risk Drivers

Primary risk factors driving this score, ordered by severity.

Adversarial Resilience50
Battle-Tested Maturity72
Compositional Risk75

Adversarial Risk Signals

Observable security posture indicators. These signals reflect publicly verifiable information and responsible disclosure outcomes. No specific vulnerability details are exposed.

Disclosure HistoryNot Assessed
Remediation VelocityNot Assessed
Bug Bounty ProgramNot Assessed
Audit CoverageNot Assessed
Incident HistoryNot Assessed
Deployed 2021-08-01Z-Factor 0.80010 active dimensions

Score History & Verification

Score provenance tracking begins with the next reassessment.

On-Chain Data

Protocol Slug
"pyth"
Oracle
BRORegistry (Base)
Evidence
IPFS (pinned)
Staleness Threshold
24 hours
Read Score
registry.getScore("pyth")

Reduce exploitable risk

BlackHart Monitoring provides continuous adversarial analysis, vulnerability detection, remediation support, and verified reassessment when your risk posture improves.