Stader Labs
DAMASCUSLiquid Staking · Multi-chain · $300M+ TVL · 10 contracts
Official site: www.staderlabs.com ↗
753
3004756508251000
Confidence67%
Z-Factor0.76
Updated 2026-05-27Public scoreSecurity Profile
Access Control
70
70
Economic Soundness
72
72
Oracle Integrity
72
72
Compositional Risk
65
65
Governance
58
58
Maturity
62
62
Resilience
50
50
Supply Chain
75
75
Op Security
49
49
Cascade Exposure
100
100
Access Ctrl
70
70
Economic
72
72
Oracle
72
72
Compos.
65
65
Govern.
58
58
Maturity
62
62
Resilience
50
50
Supply Ch.
75
75
OpSec
49
49
Cascade
100
100
Min
49
Avg
67
Max
100
Audit History
Sigma Prime
2023-04
Halborn
2023-01
Code4rena
2023-06
Bug Bounty Program
$1,000,000
Max payout on Immunefi
Assessment
Multi-chain liquid staking protocol (28 months for ETHx). D5 moderate (58) for maturing governance. D6 moderate (62) for growing maturity. Established player in liquid staking but behind Lido and Rocket Pool in battle-testing.
Dimension Breakdown
MethodologyAccess Control
70Weight 18% · 70% confidence
+18Admin multisig controls protocol parameters
+18Permissionless staking for users
+18Node operator onboarding with collateral requirements
+18Multi-chain deployment adds access control complexity
Provenance
Economic Soundness
72Weight 13% · 70% confidence
+18ETHx liquid staking derivative
+18Node operator SD token collateral requirement
+18Withdrawal queue mechanism
+18Moderate TVL across multiple chains
Provenance
Oracle Integrity
72Weight 13% · 70% confidence
+18Chainlink feeds for SD token pricing
+18Internal oracle for ETH staking rate
+18Multi-chain oracle dependencies
+18Standard oracle integration patterns
Provenance
Battle-Tested Maturity
62Weight 12% · 65% confidence
+16Live since early 2023 (~28 months for ETHx)
+16Earlier BNB/Polygon variants since 2022
+16Moderate production history
+16Z-factor: 0.824
Provenance
Governance & Upgradeability
58Weight 10% · 62% confidence
+19SD token governance, maturing
+19Admin controls key parameters
+19Limited governance decentralization
Provenance
Adversarial Resilienceredacted
50Weight 10% · 30% confidence
- Maximum resilience under independent adversarial testing
- Comprehensive security coverage across all attack surfaces
- Active bounty program incentivizes continuous scrutiny
- No validated adversarial findings — score set to neutral baseline
Provenance
Operational Security
49Weight 10% · 60% confidence
-26No branch protection detected
-26CI/CD present but unstable (0% success)
+12Strong PR review culture (90% reviewed)
+12Dependabot enabled
Provenance
Compositional Risk
65Weight 5% · 68% confidence
+16ETHx integrates across DeFi (Aave, Curve, etc.)
+16Multi-chain presence adds composition layers
+16Node operator collateral creates internal composition
+16Moderate composition surface
Provenance
Cascade Exposure
100Weight 5% · 50% confidence
+33Member of 1 dependency cluster(s)
+33No cross-protocol cascade exposure detected
+33Source: cross_protocol_composition.json dependency analysis
Provenance
Supply Chain
75Weight 4% · 70% confidence
+19Standard Solidity with OpenZeppelin
+19Modern compiler versions
+19Multi-chain deployment infrastructure
+19Standard dependency set
Provenance
Top Score Drivers
Dimensions with the greatest marginal impact on BRI.
Operational Security
49+33.5 potential
No branch protection detected
Adversarial Resilience
50+32.5 potential
Access Control
70+30 potential
Admin multisig controls protocol parameters
Battle-Tested Maturity
62+26.7 potential
Live since early 2023 (~28 months for ETHx)
Governance & Upgradeability
58+25.4 potential
SD token governance, maturing
Adversarial Risk Signals
Publicly verifiable security posture indicators.
Disclosure HistoryNot Assessed
Remediation VelocityNot Assessed
Bug Bounty ProgramNot Assessed
Audit CoverageNot Assessed
Incident HistoryNot Assessed
methodology v2.1formula v1.1weights v1.1evidence sha256:sha256:a...
Score History & Verification
Score provenance tracking begins with the next reassessment.
On-Chain Data
- Protocol Slug
- "stader"
- Oracle
- BRORegistry (Base)
- Evidence
- IPFS (pinned)
- Staleness Threshold
- 24 hours
Read Score
registry.getScore("stader")Reduce exploitable risk
Continuous adversarial analysis, vulnerability detection, and verified reassessment.
Embed this score
Live, updates automatically. Free for any site. Click-through links open the full report on BlackHart.
Style
Theme
Format
Preview
Copy iframe code
<iframe
src="https://blackhart.io/embed/oracle/stader?variant=card&theme=dark"
title="BlackHart Risk Index: Stader Labs"
width="340"
height="290"
frameborder="0"
loading="lazy"
style="border:0; max-width:100%;"
></iframe>