BlackHartBlackHart
Scores/Pendle V2/Provenance/Access Control
D1

Access Control

Permission models, admin surface, reentrancy protection, and authorization boundaries. #1 exploit vector by dollar loss in DeFi history.

Weight 18%78% confidence
73
Good
info

How This Score Is Built

Permission models, admin surface, reentrancy protection, and authorization boundaries. #1 exploit vector by dollar loss in DeFi history.

+23Strong positive
+12Positive
+5Slight positive
−15Strong negative
−8Negative
−3Slight negative

Scoring Tree

BRI Formula
300 + 700 × ∏(Dᵢ/100)^wᵢ
746
Current BRI
D1Access Control
Weight 18%
73
(73/100)^0.18 = 0.9449
Contributing Factors
+187 access control checks across 8 graphs -- moderate coverage for protocol complexity
+18SY/PT/YT token model with complex mint/redeem flows through 1981 functions
+18Reentrancy guards present on core paths
+182-step ownership transfer (claimOwnership) reduces admin takeover risk
-27Permissionless market creation increases attack surface
Evidence Sources
blackhart_analysisMay 4sha256:6738040a0774....View
blackhart_analysisMay 17sha256:40c5cee716ca....View

Score Composition

-27

Permissionless market creation increases attack surface

Strong negativeopen_in_newSource CodeMay 4, 2026
+18

7 access control checks across 8 graphs -- moderate coverage for protocol complexity

Strong positiveopen_in_newSource CodeMay 4, 2026
+18

SY/PT/YT token model with complex mint/redeem flows through 1981 functions

Strong positiveopen_in_newSource CodeMay 4, 2026
+18

Reentrancy guards present on core paths

Strong positiveopen_in_newSource CodeMay 4, 2026
+18

2-step ownership transfer (claimOwnership) reduces admin takeover risk

Evidence Chain (2 files)

GitHub APIMay 17, 2026, 06:58 PM
open_in_newGitHub (/)
sha256:40c5cee716ca...
BlackHart AnalysisMay 4, 2026, 10:00 PM
open_in_newAccess Control — Source Code
sha256:6738040a0774...

Score History

No dimension-level score changes recorded yet.

Methodology: 2.1Formula: 1.1Weights: 1.1