Puffer Finance
DAMASCUSLiquid Restaking · Ethereum · $1B+ TVL · 10 contracts
Official site: puffer.fi ↗
773
3004756508251000
Confidence52%
Z-Factor0.55
Updated 2026-05-27Public scoreSecurity Profile
Access Control
70
70
Economic Soundness
72
72
Oracle Integrity
75
75
Compositional Risk
62
62
Governance
55
55
Maturity
62
62
Resilience
72
72
Supply Chain
78
78
Op Security
56
56
Cascade Exposure
89
89
Access Ctrl
70
70
Economic
72
72
Oracle
75
75
Compos.
62
62
Govern.
55
55
Maturity
62
62
Resilience
72
72
Supply Ch.
78
78
OpSec
56
56
Cascade
89
89
Min
55
Avg
69
Max
89
Audit History
SlowMist
2024-01
BlockSec
2024-02
Code4rena
2024-06
Bug Bounty Program
$100,000
Max payout on Immunefi
Assessment
Liquid restaking protocol with lowest bond requirement (1 ETH). 27+ months live with no exploits. Young protocol with expanding product surface (UniFi). Governance centralization and EigenLayer dependency are main risks.
Dimension Breakdown
MethodologyAccess Control
70Weight 18% · 68% confidence
+23Operator permission system
+23Admin controls for protocol parameters
+23Validator ticket system
-30Centralized admin functions
Provenance
Economic Soundness
72Weight 13% · 68% confidence
+18pufETH liquid restaking model
+181 ETH bond requirement (lowest in market)
+18Validator ticket economics novel
+18UniFi integration adds complexity
Provenance
Oracle Integrity
75Weight 13% · 72% confidence
+19Exchange rate oracle
+19No external price feed in core
+19Rate update mechanism
+19Trust assumption in rate submission
Provenance
Battle-Tested Maturity
62Weight 12% · 60% confidence
+16Live since February 2024 (27+ months)
+16Rapidly growing TVL
+16No exploits
+16Multiple product launches
Provenance
Governance & Upgradeability
55Weight 10% · 60% confidence
+18Early-stage governance
-45Team controls most parameters
+18No meaningful decentralization yet
+18Foundation structure
Provenance
Adversarial Resilienceredacted
72Weight 10% · 68% confidence
- Audited by multiple firms
- Active bounty program
- C4 competition conducted
- Young protocol with evolving surface
Provenance
Operational Security
56Weight 10% · 60% confidence
-22No branch protection detected
-22CI/CD present but unstable (20% success)
+19Strong PR review culture (80% reviewed)
+19Low development activity (4 commits/month)
Provenance
Compositional Risk
62Weight 5% · 65% confidence
+16EigenLayer dependency
+16pufETH integration across DeFi
+16UniFi rollup adds surface
+16Multiple product lines
Provenance
Cascade Exposure
89Weight 5% · 60% confidence
+30Appears in 2 cross-protocol cascade chain(s)
+30Member of 4 dependency cluster(s)
+30Source: cross_protocol_composition.json dependency analysis
Provenance
Supply Chain
78Weight 4% · 75% confidence
+20Standard Solidity
+20OpenZeppelin
+20Verified contracts
+20Moderate dependencies
Provenance
Top Score Drivers
Dimensions with the greatest marginal impact on BRI.
Access Control
70+31.4 potential
Centralized admin functions
Governance & Upgradeability
55+29.1 potential
Team controls most parameters
Operational Security
56+28.2 potential
No branch protection detected
Battle-Tested Maturity
62+27.9 potential
Live since February 2024 (27+ months)
Economic Soundness
72+20.6 potential
pufETH liquid restaking model
Adversarial Risk Signals
Publicly verifiable security posture indicators.
Disclosure HistoryNot Assessed
Remediation VelocityNot Assessed
Bug Bounty ProgramNot Assessed
Audit CoverageNot Assessed
Incident HistoryNot Assessed
methodology v2.1formula v1.0weights v1.0evidence sha256:sha256:a...
Score History & Verification
Score provenance tracking begins with the next reassessment.
On-Chain Data
- Protocol Slug
- "puffer"
- Oracle
- BRORegistry (Base)
- Evidence
- IPFS (pinned)
- Staleness Threshold
- 24 hours
Read Score
registry.getScore("puffer")Reduce exploitable risk
Continuous adversarial analysis, vulnerability detection, and verified reassessment.
Embed this score
Live, updates automatically. Free for any site. Click-through links open the full report on BlackHart.
Style
Theme
Format
Preview
Copy iframe code
<iframe
src="https://blackhart.io/embed/oracle/puffer?variant=card&theme=dark"
title="BlackHart Risk Index: Puffer Finance"
width="340"
height="290"
frameborder="0"
loading="lazy"
style="border:0; max-width:100%;"
></iframe>