Notional Finance
DAMASCUSFixed Rate Lending · Ethereum + Arbitrum · $200M+ TVL · 10 contracts
Official site: notional.finance ↗
771
3004756508251000
Confidence65%
Z-Factor0.79
Updated 2026-05-27Public scoreSecurity Profile
Access Control
75
75
Economic Soundness
70
70
Oracle Integrity
78
78
Compositional Risk
68
68
Governance
60
60
Maturity
72
72
Resilience
50
50
Supply Chain
80
80
Op Security
46
46
Cascade Exposure
100
100
Access Ctrl
75
75
Economic
70
70
Oracle
78
78
Compos.
68
68
Govern.
60
60
Maturity
72
72
Resilience
50
50
Supply Ch.
80
80
OpSec
46
46
Cascade
100
100
Min
46
Avg
70
Max
100
Audit History
Certora (Formal)
2022-06
Sherlock Competition
2023-01
Code4rena
2022-01
Bug Bounty Program
$250,000
Max payout on Immunefi
Assessment
Specialized fixed-rate lending with unique fCash instrument. V1 issues led to proper V2 redesign (shows learning). Moderate maturity for current version. Novel economics (D2=70) and complexity are the main drags.
Dimension Breakdown
MethodologyAccess Control
75Weight 18% · 72% confidence
+19Lending market with admin-controlled parameters
+19fCash (fixed-rate) positions managed through protocol
+19Liquidation permissionless and well-defined
+19V2 had global settlement capability (emergency admin)
Provenance
Economic Soundness
70Weight 13% · 68% confidence
+18Fixed-rate lending via fCash instrument is novel
+18Interest rate curve and settlement mechanics are complex
+18V1 had economic design issues (migrated to V2 redesign)
+18Prime lending (V3) adds variable-rate with different model
Provenance
Oracle Integrity
78Weight 13% · 75% confidence
+20Chainlink oracle dependency for collateral pricing
+20fCash valuation uses internal interest rate model
+20Time-dependent valuation adds oracle timing sensitivity
+20Settlement price is critical trust point
Provenance
Battle-Tested Maturity
72Weight 12% · 72% confidence
+14V1 live 2021, V2 2022, V3 (Prime) 2023
+14V1 had issues leading to redesign (good: learned and fixed)
+14~36 months for V2+, continuous evolution
+14Audited by multiple firms (Sherlock contest, Code4rena)
Provenance
Governance & Upgradeability
60Weight 10% · 68% confidence
+15NOTE token governance with active proposals
+15Governance controls market parameters and listings
+15Timelock on governance actions
+15Moderate participation rate
Provenance
Adversarial Resilienceredacted
50Weight 10% · 30% confidence
- No validated adversarial findings — score set to neutral baseline
Provenance
Operational Security
46Weight 10% · 50% confidence
-54No branch protection detected
+12No CI/CD pipeline detected
+12Minimal development activity (0 commits/month)
+12No CI pipeline for deployment verification
Provenance
Compositional Risk
68Weight 5% · 70% confidence
+17fCash tokens composed in DeFi (limited adoption)
+17Leveraged vault strategy composes external protocols
+17Cross-currency lending creates composition surface
+17More bounded than general lending protocols
Provenance
Cascade Exposure
100Weight 5% · 50% confidence
+33Member of 2 dependency cluster(s)
+33No cross-protocol cascade exposure detected
+33Source: cross_protocol_composition.json dependency analysis
Provenance
Supply Chain
80Weight 4% · 78% confidence
+20OpenZeppelin dependencies
+20Standard Solidity stack
+20Verified on Etherscan
+20Moderate dependency complexity
Provenance
Top Score Drivers
Dimensions with the greatest marginal impact on BRI.
Operational Security
46+38 potential
No branch protection detected
Adversarial Resilience
50+33.8 potential
Access Control
75+25 potential
Lending market with admin-controlled parameters
Governance & Upgradeability
60+24.7 potential
NOTE token governance with active proposals
Economic Soundness
70+22.4 potential
Fixed-rate lending via fCash instrument is novel
Adversarial Risk Signals
Publicly verifiable security posture indicators.
Disclosure HistoryNot Assessed
Remediation VelocityNot Assessed
Bug Bounty ProgramNot Assessed
Audit CoverageNot Assessed
Incident HistoryNot Assessed
methodology v2.1formula v1.1weights v1.1evidence sha256:sha256:f...
Score History & Verification
Score provenance tracking begins with the next reassessment.
On-Chain Data
- Protocol Slug
- "notional"
- Oracle
- BRORegistry (Base)
- Evidence
- IPFS (pinned)
- Staleness Threshold
- 24 hours
Read Score
registry.getScore("notional")Reduce exploitable risk
Continuous adversarial analysis, vulnerability detection, and verified reassessment.
Embed this score
Live, updates automatically. Free for any site. Click-through links open the full report on BlackHart.
Style
Theme
Format
Preview
Copy iframe code
<iframe
src="https://blackhart.io/embed/oracle/notional?variant=card&theme=dark"
title="BlackHart Risk Index: Notional Finance"
width="340"
height="290"
frameborder="0"
loading="lazy"
style="border:0; max-width:100%;"
></iframe>