{
  "schemaVersion": 2,
  "title": "D tiers: additional control over capital",
  "status": "Editorial research registry; proposed assignments from cited primary documentation, not contract audits.",
  "runtimeHeuristics": [
    "Match chain ID plus canonical contract address or reviewed deployment/factory provenance; ticker matching alone is prohibited.",
    "Known reviewed runtime bytecode and known factory configuration can inherit a reviewed structural tier, then compose dependencies.",
    "A discovered upgrade admin, live blacklist, pause role, or mint role establishes a control and a knownFloor; it does not establish the absence of other controls.",
    "Reading owner() = zero, missing a proxy storage slot, a verified-source badge, token category, TVL, age, or DAO marketing is never sufficient to infer D0.",
    "New protocol/version/address, unknown hook/oracle, unresolved proxy admin, or unavailable review yields D?; keep the financial observation.",
    "Permanent D0 applies only to the verified immutable mechanism. Fully re-study every other assessment monthly; new deployments and unresolved dependencies never inherit a blanket D0."
  ],
  "lastUpdatedAt": "2026-10-01",
  "rubric": "ethereum-decentralization-index/rubric.json",
  "policyUpdatedAt": "2026-09-29",
  "reviewPolicy": {
    "immutableD0": "A verified D0 assessment is permanent for its exact immutable deployment and reviewed mechanism. No scheduled re-study or age expiry. A new deployment, hook, oracle, wrapper or dependency is a separate assessment; evidence corrections remain possible.",
    "otherAssessments": "Fully re-study every other entity and unresolved position dependency monthly from primary documentation, implementation, roles, pause/upgrade/exit paths and dependencies. A failed check retains the last real reviewedAt and remains overdue; never refresh a date without doing the research.",
    "firstMonthlyRun": "2026-10-01",
    "coverageDenominator": "Conserved mapped L1 protocol holdings, not summed TVL or a claim to cover every L1 application."
  },
  "coverageNotes": [
    "Canonical reviews include the mapped L1 cohort, five previously unmatched large stablecoins and all 27 utility-token IDs in the imported financial snapshot. This is not an exhaustive list of Ethereum deployments.",
    "The unversioned uniswap record intentionally remains unknown: use reviewed exact v1-v4 deployments; UNI has its own token:uniswap review."
  ],
  "entities": [
    {
      "id": "1inch-limit-order-v4",
      "name": "1inch limit-order v4 / router v6",
      "kind": "protocol",
      "proposedTier": 2,
      "assessment": "lower-bound",
      "scope": "Canonical router containing limit-order protocol v4; includes its actual pause and rescue powers.",
      "reason": "Canonical Ethereum AggregationRouterV6 includes owner pause/unpause of trading and rescue of assets held at the router. These powers prevent blanket D0. Close live owner authority and order-selected predicates, interactions and custody scope before completing the grade.",
      "controls": [
        "Canonical Ethereum AggregationRouterV6 includes owner pause/unpause of trading and rescue of assets held at the router"
      ],
      "evidenceUrls": [
        "https://sourcify.dev/server/v2/contract/1/0x111111125421ca6dc452d289314280a0f8842a65?fields=sources,compilation,runtimeBytecode,proxyResolution,deployment",
        "https://etherscan.io/address/0x111111125421ca6dc452d289314280a0f8842a65#code",
        "https://github.com/1inch/limit-order-protocol"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [],
      "canonicalAddresses": {
        "1": "0x111111125421ca6dc452d289314280a0f8842a65"
      },
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ],
      "knownFloor": 2,
      "tierBound": true,
      "limits": [
        "Do not rate only a source mixin while omitting the deployed router authority."
      ],
      "sourceProof": {
        "checkedAt": "2026-10-01",
        "chainId": 1,
        "address": "0x111111125421ca6dc452d289314280a0f8842a65",
        "provider": "sourcify-v2",
        "runtimeSha256": "25ed432292a03b29a9833444092ed36fca80cf3b9d7a04bd05db9351f5b2bbcf",
        "sourcesSha256": "29f4fff8a8056f2ae53fbd3d4336dc81594bdaf70b7397113513dc1904a1e38e",
        "contractName": "AggregationRouterV6",
        "proxyDetected": false,
        "onchainCodeMatchedAt": "2026-10-01",
        "authorityChecks": [
          {
            "method": "owner()",
            "value": "0x0000000000000000000000009f8102b1bb05785bad2874f2c7b1aaea4c6d976a",
            "block": "0x18e39b6"
          }
        ]
      }
    },
    {
      "id": "aave-v2",
      "name": "Aave v2",
      "kind": "protocol",
      "proposedTier": 3,
      "scope": "Ethereum mainnet deployment; asset-level dependencies assessed separately.",
      "reason": "Governance controls protocol updates and a guardian can pause emergency operations.",
      "controls": [
        "Governance execution.",
        "Emergency pausing.",
        "Oracle and collateral dependencies."
      ],
      "evidenceUrls": [
        "https://governance-v2.aave.com/governance/proposal/49/",
        "https://governance.aave.com/t/aave-governance-process-document-v1/18577"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "aave-v2"
      ],
      "dependencies": [],
      "assessment": "assessed",
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "aave-v3",
      "name": "Aave v3",
      "kind": "protocol",
      "proposedTier": 3,
      "scope": "Ethereum mainnet deployment; asset-level dependencies assessed separately.",
      "reason": "Governance can update the lending system; guardians can pause markets and risk roles manage parameters.",
      "controls": [
        "Governance-controlled pool upgrades.",
        "Emergency pause and freeze roles.",
        "Oracle and collateral dependencies."
      ],
      "evidenceUrls": [
        "https://aave.com/help/governance/aave-community",
        "https://governance.aave.com/t/aave-governance-process-document-v1/18577",
        "https://governance.aave.com/t/aave-emergency-guardian-protocol-signer-rotation/24944"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "aave-v3"
      ],
      "dependencies": [],
      "limits": [
        "Proposed tier for Ethereum governance path; other deployments and newer v4/Horizon products need their own review.",
        "A governance delay is not an assured withdrawal window when liquidity is borrowed or a market is paused."
      ],
      "assessment": "assessed",
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "aave-v4",
      "name": "Aave v4",
      "kind": "protocol",
      "proposedTier": 1,
      "knownFloor": 1,
      "assessment": "lower-bound",
      "tierBound": true,
      "scope": "Ethereum-mainnet v4 Hub/Spoke markets; exact live deployment/controller path remains unresolved.",
      "reason": "Aave officially launched v4 on Ethereum with three liquidity Hubs. The DAO can expand caps and add Spokes, establishing governed settings. Full Hub/Spoke implementation, oracle, governance delay and emergency authority closure remains pending; do not inherit Aave v3 or blanket D0.",
      "controls": [
        "DAO-governed caps and Spoke admission."
      ],
      "evidenceUrls": [
        "https://aave.com/blog/aave-v4-live-ethereum",
        "https://governance.aave.com/t/arfc-aave-v4-activation-on-ethereum-mainnet/24293",
        "https://github.com/aave/aave-v4"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [],
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "limits": [
        "Identify all live Hubs and Spokes and complete their material controller/dependency paths."
      ],
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "aerodrome-slipstream",
      "name": "Aerodrome Slipstream",
      "kind": "protocol",
      "proposedTier": 1,
      "scope": "Canonical deployed product; additional asset and chain dependencies compose separately.",
      "reason": "Pool administration and concentrated-liquidity configuration add local powers; underlying Base safeguards still apply.",
      "controls": [],
      "evidenceUrls": [
        "https://aerodrome.finance/security"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [
        "base"
      ],
      "knownFloor": 4,
      "assessment": "lower-bound",
      "tierBound": true,
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "aerodrome-v1",
      "name": "Aerodrome v1",
      "kind": "protocol",
      "proposedTier": 1,
      "scope": "Canonical deployed product; additional asset and chain dependencies compose separately.",
      "reason": "Factory fee and swap-pause roles add administration; underlying Base safeguards still apply.",
      "controls": [
        "Factory can pause swaps.",
        "Separate pool, voter, gauge, and reward roles."
      ],
      "evidenceUrls": [
        "https://github.com/aerodrome-finance/contracts/blob/main/PERMISSIONS.md",
        "https://github.com/aerodrome-finance/contracts/blob/main/contracts/Pool.sol"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [
        "base"
      ],
      "knownFloor": 4,
      "assessment": "lower-bound",
      "tierBound": true,
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "arbitrum",
      "name": "Arbitrum One",
      "kind": "chain",
      "proposedTier": 4,
      "scope": "Arbitrum One; excludes AnyTrust/Nova.",
      "reason": "An elected 9-of-12 council can make immediate emergency changes; ordinary upgrades follow delayed DAO governance.",
      "controls": [
        "9/12 emergency Security Council.",
        "Separate slower governance paths."
      ],
      "evidenceUrls": [
        "https://docs.arbitrum.foundation/dao-constitution",
        "https://docs.arbitrum.foundation/concepts/security-council",
        "https://l2beat.com/layer2s/projects/arbitrum"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "arbitrum-one"
      ],
      "dependencies": [
        "ethereum"
      ],
      "assessment": "assessed",
      "tierBound": false,
      "dimensions": {
        "Validation": "Permissionless BoLD challenges; Ethereum data availability.",
        "Upgrades": "9/12 emergency council; delayed DAO and non-emergency changes.",
        "Accountability": "DAO-elected cohorts, removal powers, organizational limits and a published constitution.",
        "Exits": "L1 inclusion and normal upgrade delays; emergency authority can bypass the delay."
      },
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "balancer-v2",
      "name": "Balancer V2",
      "kind": "protocol",
      "proposedTier": 1,
      "tierBound": true,
      "scope": "Ethereum L1 protocol mechanism; assets and integrations are separate dependencies.",
      "reason": "The v2 Vault has bounded fee/authorizer controls. Its original Vault pause window has expired, but individual pool contracts, rate providers and recovery paths still require review. At least D1; no blanket D0.",
      "controls": [
        "The v2 Vault has bounded fee/authorizer controls. Its original Vault pause window has expired, but individual pool contracts, rate providers and recovery paths still require review. At least D1; no blanket D0."
      ],
      "evidenceUrls": [
        "https://docs.balancer.fi/developer-reference/contracts/vault-config.html",
        "https://docs.balancer.fi/concepts/vault/",
        "https://github.com/balancer/balancer-v2-monorepo/tree/master/pkg/vault/contracts"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [],
      "assessment": "lower-bound",
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "balancer-v3",
      "name": "Balancer V3",
      "kind": "protocol",
      "proposedTier": 2,
      "tierBound": true,
      "scope": "Ethereum L1 protocol mechanism; assets and integrations are separate dependencies.",
      "reason": "The v3 Vault has a four-year pause window and six-month buffer. Paused pools permit permissionless recovery withdrawals, but operational controls, hooks and rate providers remain; at least D2.",
      "controls": [
        "The v3 Vault has a four-year pause window and six-month buffer. Paused pools permit permissionless recovery withdrawals, but operational controls, hooks and rate providers remain; at least D2."
      ],
      "evidenceUrls": [
        "https://docs.balancer.fi/developer-reference/contracts/vault-config.html",
        "https://docs.balancer.fi/concepts/governance/"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [],
      "assessment": "lower-bound",
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "base",
      "name": "Base",
      "kind": "chain",
      "proposedTier": 6,
      "scope": "Base mainnet, chain ID 8453; settlement and data availability on Ethereum.",
      "reason": "An appointed 8-of-11 council and Coinbase must both approve upgrades; there is no timelock or DAO removal route.",
      "controls": [
        "2/2 approval: Coinbase 3/6 and Security Council 8/11.",
        "No upgrade exit window.",
        "Withdrawal pause and privileged configuration roles."
      ],
      "evidenceUrls": [
        "https://l2beat.com/layer2s/projects/base",
        "https://docs.base.org/specifications/security/security-council-for-base"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [
        "ethereum"
      ],
      "assessment": "assessed",
      "tierBound": false,
      "dimensions": {
        "Validation": "TEE and ZK proof arms; permissionless challenges, with Coinbase controlling the TEE allowlist.",
        "Upgrades": "Coinbase 3/6 + Council 8/11 jointly approve; no timelock.",
        "Accountability": "Appointed council with self-administered membership; no token-governance removal route.",
        "Exits": "L1 forced inclusion; immediate upgrades provide no exit window."
      },
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "base-canonical-bridge",
      "name": "Base canonical bridge",
      "kind": "protocol",
      "proposedTier": 6,
      "scope": "Canonical escrow/control path, not an additional capital stock.",
      "reason": "This bridge inherits the upgrade and validation arrangements of base.",
      "controls": [],
      "evidenceUrls": [
        "https://l2beat.com/layer2s/projects/base"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [
        "base"
      ],
      "assessment": "assessed",
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "binance-staked-eth",
      "name": "Binance staked ETH",
      "kind": "protocol",
      "proposedTier": 9,
      "scope": "Canonical deployed product; additional asset and chain dependencies compose separately.",
      "reason": "Binance operates the staking and redemption service represented by WBETH.",
      "controls": [
        "Exchange-operated staking and redemption."
      ],
      "evidenceUrls": [
        "https://www.binance.com/en/earn-faq/dark/eth-staking",
        "https://www.binance.com/en-IN/support/announcement/detail/a1197f34d832445db41654ad01f56b4d"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [],
      "assessment": "assessed",
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "buidl",
      "name": "BUIDL",
      "kind": "asset",
      "proposedTier": 9,
      "scope": "Canonical token mechanism; deployment-specific custody adds inherited bounds.",
      "reason": "Fund ownership and redemption depend on BlackRock, Securitize and qualified-investor transfer controls.",
      "controls": [
        "Fund ownership and redemption depend on BlackRock, Securitize and qualified-investor transfer controls."
      ],
      "evidenceUrls": [
        "https://securitize.io/learn/press/blackrock-launches-first-tokenized-fund-buidl-on-the-ethereum-network"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "BUIDL"
      ],
      "dependencies": [],
      "assessment": "assessed",
      "tierBound": false,
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "cbbtc",
      "name": "cbBTC",
      "kind": "asset",
      "proposedTier": 9,
      "scope": "Ethereum mainnet deployment; asset-level dependencies assessed separately.",
      "reason": "Coinbase holds the BTC backing and controls the wrapped-token contract.",
      "controls": [
        "Custodial BTC backing.",
        "Upgrade, pause, and blacklist administration."
      ],
      "evidenceUrls": [
        "https://www.coinbase.com/cbbtc",
        "https://github.com/coinbase/wrapped-tokens-os/blob/main/doc/tokendesign.md"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "CBBTC",
        "cbBTC"
      ],
      "dependencies": [],
      "assessment": "assessed",
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "cbeth",
      "name": "cbETH",
      "kind": "asset",
      "proposedTier": 9,
      "scope": "Canonical deployed product; additional asset and chain dependencies compose separately.",
      "reason": "Coinbase holds the underlying staking position and controls the token’s administration.",
      "controls": [
        "Custodial staking and redemption.",
        "Upgrade, pause, blacklist, and exchange-rate roles."
      ],
      "evidenceUrls": [
        "https://www.coinbase.com/cbeth/whitepaper",
        "https://github.com/coinbase/wrapped-tokens-os/blob/main/doc/tokendesign.md"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "CBETH",
        "cbETH",
        "coinbase-wrapped-staked-eth"
      ],
      "dependencies": [],
      "assessment": "assessed",
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "celo",
      "name": "Celo",
      "kind": "chain",
      "proposedTier": 8,
      "scope": "Celo L2 mainnet, chain ID 42220; includes EigenDA and OP Succinct Lite dependencies.",
      "reason": "Council participation limits upgrades, but cLabs separately controls proposer/challenger allowlists and withdrawal pauses.",
      "controls": [
        "OP Succinct Lite permits only registered challengers to initiate disputes; data availability also depends on EigenDA.",
        "Joint 6/8 community council and 6/8 cLabs approvals; no enforced delay.",
        "Council participation is real, but allowlist and operational powers are separately held by cLabs.",
        "cLabs can pause withdrawals and change proposer/challenger permissions without joint council approval."
      ],
      "evidenceUrls": [
        "https://l2beat.com/layer2s/projects/celo",
        "https://docs.celo.org/home/protocol/security-council",
        "https://docs.celo.org/home/protocol/challengers"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [
        "ethereum"
      ],
      "assessment": "assessed",
      "tierBound": false,
      "dimensions": {
        "Validation": "OP Succinct Lite permits only registered challengers to initiate disputes; data availability also depends on EigenDA.",
        "Upgrades": "Joint 6/8 community council and 6/8 cLabs approvals; no enforced delay.",
        "Accountability": "Council participation is real, but allowlist and operational powers are separately held by cLabs.",
        "Exits": "cLabs can pause withdrawals and change proposer/challenger permissions without joint council approval."
      },
      "uncertainty": "Five of the six documented challengers are independent entities. An operator-managed allowlist still creates a D8 authority dependency; this does not erase their independence.",
      "reviewBasis": "Editorial mapping from linked first-party governance records and L2BEAT contract-discovery research to this map’s D0–D9 rubric; not a conversion of L2BEAT stages.",
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "compound-v3",
      "name": "Compound III",
      "kind": "protocol",
      "proposedTier": 3,
      "scope": "Canonical deployed product; additional asset and chain dependencies compose separately.",
      "reason": "Timelocked governance can replace Comet and alter its configuration; a guardian can pause operations.",
      "controls": [
        "Governance-controlled proxy and configuration.",
        "Pause guardian.",
        "Oracle and collateral dependencies."
      ],
      "evidenceUrls": [
        "https://docs.compound.finance/governance/",
        "https://www.openzeppelin.com/news/compound-iii-audit"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [],
      "assessment": "assessed",
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "curve",
      "name": "Curve, mixed pools",
      "kind": "protocol",
      "proposedTier": 1,
      "scope": "Ethereum mainnet deployment; asset-level dependencies assessed separately.",
      "reason": "The mapped legacy Curve pool family retains bounded fee/amplification administration, so it is at least D1. Pause powers, rate providers, lending integrations and per-pool ownership vary; no blanket D0 or complete family grade is assigned.",
      "controls": [
        "Legacy kill and admin controls vary.",
        "Pool-specific rate providers and collateral dependencies."
      ],
      "evidenceUrls": [
        "https://github.com/curvefi/curve-contract/blob/master/contracts/pools/steth/StableSwapSTETH.vy",
        "https://github.com/curvefi/curve-dao-contracts/blob/master/contracts/PoolProxy.vy",
        "https://github.com/curvefi/stableswap-ng/blob/main/contracts/main/CurveStableSwapNG.vy"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "curve",
        "curve-dex"
      ],
      "dependencies": [],
      "knownFloor": 0,
      "limits": [
        "Require pool contract/version instead of assigning a brand-wide D0."
      ],
      "assessment": "lower-bound",
      "tierBound": true,
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "dai",
      "name": "DAI",
      "kind": "asset",
      "proposedTier": 2,
      "scope": "Ethereum mainnet deployment; asset-level dependencies assessed separately.",
      "reason": "Governance-authorized issuance inherits Sky and the collateral backing used by the system.",
      "controls": [
        "Authorized issuance via wards.",
        "Governed collateral system."
      ],
      "evidenceUrls": [
        "https://github.com/sky-ecosystem/developerguides/blob/master/dai/dai-token/dai-token.md",
        "https://docs.sky.money/legal/skybase-international/user-risks"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "DAI"
      ],
      "dependencies": [
        "sky"
      ],
      "ownComponentTier": 2,
      "knownFloor": 3,
      "proposedRange": [
        3,
        5
      ],
      "canonicalAddresses": {
        "1": "0x6b175474e89094c44da98b954eedeac495271d0f"
      },
      "limits": [
        "Do not assert that DAI has USDC-style account-freeze powers. Custodial collateral is a separate dependency."
      ],
      "assessment": "lower-bound",
      "tierBound": true,
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ],
      "sourceProof": {
        "checkedAt": "2026-10-01",
        "chainId": 1,
        "address": "0x6b175474e89094c44da98b954eedeac495271d0f",
        "provider": "sourcify-v2",
        "runtimeSha256": "5ce810033426a017721777f241665c27bdd4663ca8a1c27558b4b372a1731f4e",
        "sourcesSha256": "d0a71a4a2d78915511bdc49edb66be596a2a25769e49c395dbf800e0f99209ca",
        "contractName": "Dai",
        "proxyDetected": false,
        "onchainCodeMatchedAt": "2026-10-01"
      }
    },
    {
      "id": "eeth",
      "name": "eETH",
      "kind": "asset",
      "proposedTier": 3,
      "scope": "Ethereum mainnet deployment; asset-level dependencies assessed separately.",
      "reason": "The staking claim inherits ether.fi governance and any restaking dependencies of the underlying position.",
      "controls": [
        "Upgradeable staking claim; allocated backing path must be identified."
      ],
      "evidenceUrls": [
        "https://www.ether.fi/blog/safe-staking-from-doctrine-to-code",
        "https://governance.ether.fi/t/chaos-labs-eigenlayer-eeth-security-upgrade-risk-analysis/2906"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "EETH",
        "eETH"
      ],
      "dependencies": [
        "etherfi-stake"
      ],
      "knownFloor": 3,
      "proposedRange": [
        3,
        4
      ],
      "limits": [
        "Confirm current EigenLayer allocation before a final effective tier."
      ],
      "assessment": "lower-bound",
      "tierBound": true,
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "eigenlayer",
      "name": "EigenLayer",
      "kind": "protocol",
      "proposedTier": 7,
      "scope": "Ethereum mainnet deployment; asset-level dependencies assessed separately.",
      "reason": "An emergency multisig can replace protocol rules immediately, bypassing the normal upgrade timelock.",
      "controls": [
        "Routine upgrades use a 10-day timelock.",
        "Community multisig has emergency upgrade/timelock-replacement powers.",
        "Separate pauser and operations roles."
      ],
      "evidenceUrls": [
        "https://docs.eigenfoundation.org/protocol-governance/technical-architecture"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "eigenlayer",
        "eigencloud"
      ],
      "dependencies": [],
      "limits": [
        "AVS slashing and operator dependencies also depend on the chosen restaking position."
      ],
      "assessment": "assessed",
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "ethena",
      "name": "Ethena",
      "kind": "protocol",
      "proposedTier": 9,
      "scope": "Ethereum mainnet deployment; asset-level dependencies assessed separately.",
      "reason": "The backing strategy depends on custodians, exchanges, and privileged mint/redeem operations.",
      "controls": [],
      "evidenceUrls": [
        "https://docs.ethena.fi/solution-overview/risks",
        "https://docs.ethena.fi/solution-design/key-trust-assumptions"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "ethena"
      ],
      "dependencies": [],
      "assessment": "assessed",
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "ethereum",
      "name": "Ethereum L1",
      "kind": "chain",
      "proposedTier": 0,
      "scope": "Baseline by definition; not a claim of absolute or maximal decentralization in every dimension.",
      "reason": "Open ground for everyone. Even the tallest institutions stand stronger on a shared foundation.",
      "controls": [],
      "evidenceUrls": [
        "https://ethereum.org/developers/docs/intro-to-ethereum/"
      ],
      "reviewedAt": "2026-09-08",
      "aliases": [],
      "dependencies": [],
      "assessment": "assessed",
      "reviewCadence": "permanent-D0",
      "nextReviewAt": null,
      "immutableIdentity": "Ethereum mainnet chain 1 baseline; protocol forks and other chains are separate identities."
    },
    {
      "id": "etherfi-stake",
      "name": "ether.fi staking",
      "kind": "protocol",
      "proposedTier": 3,
      "scope": "Ethereum mainnet deployment; asset-level dependencies assessed separately.",
      "reason": "Contract changes are timelocked; a separate operator role can pause or invalidate pending withdrawals.",
      "controls": [
        "Published 10-day upgrade delay.",
        "Separate upgrade and operating multisigs.",
        "Oracle bounds and emergency controls."
      ],
      "evidenceUrls": [
        "https://beta.ether.fi/blog/non-custodial-actively-defended",
        "https://www.ether.fi/blog/hardening-weeth-creating-the-market-standard"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "ether.fi",
        "ether.fi-stake",
        "etherfi"
      ],
      "dependencies": [],
      "limits": [
        "This is the local staking tier; restaked allocations inherit EigenLayer/AVS controls where applicable. Crosschain variants add bridge dependencies."
      ],
      "assessment": "assessed",
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "euler-v2",
      "name": "Euler V2",
      "kind": "protocol",
      "proposedTier": 2,
      "tierBound": true,
      "scope": "Ethereum L1 protocol mechanism; assets and integrations are separate dependencies.",
      "reason": "Governed vaults expose oracle, collateral, hook and parameter controls. Finalizing the vault governor does not remove factory beacon upgrades or dependency controls. At least D2 for the reviewed governed family; exact vault deployments need separate ratings.",
      "controls": [
        "Governed vaults expose oracle, collateral, hook and parameter controls. Finalizing the vault governor does not remove factory beacon upgrades or dependency controls. At least D2 for the reviewed governed family; exact vault deployments need separate ratings."
      ],
      "evidenceUrls": [
        "https://docs.euler.finance/learn/vault-types/",
        "https://docs.euler.finance/security/"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [],
      "assessment": "lower-bound",
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "ezeth",
      "name": "ezETH",
      "kind": "asset",
      "proposedTier": 3,
      "scope": "Canonical deployed product; additional asset and chain dependencies compose separately.",
      "reason": "Renzo governance, its withdrawal arrangements and EigenLayer all affect the staking claim.",
      "controls": [
        "Protocol pause can disable instant withdrawals.",
        "EigenLayer strategy exposure."
      ],
      "evidenceUrls": [
        "https://docs.renzoprotocol.com/docs/products/withdrawals",
        "https://docs.renzoprotocol.com/docs/products/instant-withdrawals",
        "https://docs.renzoprotocol.com/docs/introduction"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "EZETH",
        "ezETH"
      ],
      "dependencies": [
        "eigenlayer"
      ],
      "knownFloor": 4,
      "assessment": "lower-bound",
      "tierBound": true,
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "fdusd",
      "name": "FDUSD token",
      "kind": "asset",
      "proposedTier": 9,
      "assessment": "assessed",
      "scope": "Ethereum-mainnet issuer-backed token, including material offchain reserve custody and redemption.",
      "reason": "First Digital issuer terms control issuance, backing and the availability of redemption. Current upgradeable source contains privileged mint/freeze controls.",
      "controls": [
        "First Digital issuer terms control issuance, backing and the availability of redemption"
      ],
      "evidenceUrls": [
        "https://sourcify.dev/server/v2/contract/1/0xc5f0f7b66764f6ec8c8dff7ba683102295e16409?fields=sources,compilation,runtimeBytecode,proxyResolution,deployment",
        "https://etherscan.io/address/0xc5f0f7b66764f6ec8c8dff7ba683102295e16409#code",
        "https://www.firstdigitallabs.com/legal/fdd-terms"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "stable:119"
      ],
      "dependencies": [],
      "canonicalAddresses": {
        "1": "0xc5f0f7b66764f6ec8c8dff7ba683102295e16409"
      },
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ],
      "sourceProof": {
        "checkedAt": "2026-10-01",
        "chainId": 1,
        "address": "0xc5f0f7b66764f6ec8c8dff7ba683102295e16409",
        "provider": "sourcify-v2",
        "runtimeSha256": "927043b52a56c3880196a6a4ffe9aaf8a942465cb05613109038583f58c66971",
        "sourcesSha256": "88eb5d15d8f93f4bcf76071deb99169bcf2a7c031288c0f985b98d4cbd13418f",
        "contractName": "TransparentUpgradeableProxy",
        "proxyDetected": true,
        "implementation": {
          "address": "0xa6b2C3D2910246FB0ADB02e5f6B39e29026e6D50",
          "name": "StablecoinV2"
        },
        "onchainCodeMatchedAt": "2026-10-01"
      }
    },
    {
      "id": "fluid",
      "name": "Fluid",
      "kind": "protocol",
      "proposedTier": 2,
      "scope": "Ethereum mainnet deployment; asset-level dependencies assessed separately.",
      "reason": "The liquidity layer has configurable withdrawal limits and replaceable code. Its current upgrade safeguards need a deployment-specific review.",
      "controls": [
        "Infinite Proxy liquidity layer.",
        "Admin-controlled access and risk limits."
      ],
      "evidenceUrls": [
        "https://github.com/Instadapp/fluid-contracts-public/blob/main/docs/docs.md",
        "https://github.com/Instadapp/fluid-contracts-public/blob/main/contracts/protocols/lending/fToken/main.sol"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "fluid",
        "fluid-lending",
        "fluid-dex"
      ],
      "dependencies": [],
      "knownFloor": 3,
      "proposedRange": [
        3,
        4
      ],
      "limits": [
        "Current deployment admin and shortest upgrade delay not fully established in this review."
      ],
      "assessment": "lower-bound",
      "tierBound": true,
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "frxeth",
      "name": "frxETH",
      "kind": "asset",
      "proposedTier": 3,
      "scope": "Canonical deployed product; additional asset and chain dependencies compose separately.",
      "reason": "Frax governance and staking operators administer issuance and backing; emergency safeguards require further review.",
      "controls": [
        "Protocol-controlled staking and issuance."
      ],
      "evidenceUrls": [
        "https://docs.frax.com/protocol/assets/frxeth/overview",
        "https://github.com/FraxFinance/frax-governance"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "FRXETH",
        "frxETH"
      ],
      "dependencies": [],
      "knownFloor": 2,
      "assessment": "lower-bound",
      "tierBound": true,
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "gusd",
      "name": "GUSD token",
      "kind": "asset",
      "proposedTier": 9,
      "assessment": "assessed",
      "scope": "Ethereum-mainnet issuer-backed token, including material offchain reserve custody and redemption.",
      "reason": "Gemini controls backing and redemption. Legacy proxy/store/custodian contracts support privileged transfer-rule replacement and seizure. Automated negative proxy detection does not remove these controls.",
      "controls": [
        "Gemini controls backing and redemption"
      ],
      "evidenceUrls": [
        "https://sourcify.dev/server/v2/contract/1/0x056fd409e1d7a124bd7017459dfea2f387b6d5cd?fields=sources,compilation,runtimeBytecode,proxyResolution,deployment",
        "https://etherscan.io/address/0x056fd409e1d7a124bd7017459dfea2f387b6d5cd#code",
        "https://www.gemini.com/legal/gemini-trust-user-agreement"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "stable:19"
      ],
      "dependencies": [],
      "canonicalAddresses": {
        "1": "0x056fd409e1d7a124bd7017459dfea2f387b6d5cd"
      },
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ],
      "sourceProof": {
        "checkedAt": "2026-10-01",
        "chainId": 1,
        "address": "0x056fd409e1d7a124bd7017459dfea2f387b6d5cd",
        "provider": "sourcify-v2",
        "runtimeSha256": "25d41fae9030301e0268b39be66ae598d0a1241f54cb69411552185cc50375c0",
        "sourcesSha256": "cdcb3c7549a7a3d89d3c7a23183ace11fc5f123d7428a7cb12ae9705238032a3",
        "contractName": "ERC20Proxy",
        "proxyDetected": true,
        "onchainCodeMatchedAt": "2026-10-01"
      }
    },
    {
      "id": "ink",
      "name": "Ink",
      "kind": "chain",
      "proposedTier": 5,
      "scope": "Ink mainnet, chain ID 57073.",
      "reason": "The Optimism council and Foundation jointly control immediate upgrades; public proving and L1 inclusion do not remove those keys.",
      "controls": [
        "Public fault-proof participation; transaction data on Ethereum.",
        "SuperchainProxyAdminOwner requires both Foundation and Council; no enforced upgrade exit window.",
        "Optimism governance and council oversight, with Foundation fallback and guardian roles.",
        "L1 inclusion and self-proposal are available; privileged pauses and upgrades remain."
      ],
      "evidenceUrls": [
        "https://l2beat.com/layer2s/projects/ink",
        "https://docs.optimism.io/op-stack/protocol/privileged-roles"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [
        "ethereum"
      ],
      "assessment": "assessed",
      "tierBound": false,
      "dimensions": {
        "Validation": "Public fault-proof participation; transaction data on Ethereum.",
        "Upgrades": "SuperchainProxyAdminOwner requires both Foundation and Council; no enforced upgrade exit window.",
        "Accountability": "Optimism governance and council oversight, with Foundation fallback and guardian roles.",
        "Exits": "L1 inclusion and self-proposal are available; privileged pauses and upgrades remain."
      },
      "uncertainty": "The upstream assessment flags ongoing changes. This grade evaluates the documented authority paths, not a claim that every implementation byte was independently audited.",
      "reviewBasis": "Editorial mapping from linked first-party governance records and L2BEAT contract-discovery research to this map’s D0–D9 rubric; not a conversion of L2BEAT stages.",
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "lido",
      "name": "Lido",
      "kind": "protocol",
      "proposedTier": 3,
      "scope": "Ethereum mainnet deployment; asset-level dependencies assessed separately.",
      "reason": "Lido V3 core, oracle and withdrawal proxies are governed by DAO upgrades. CircuitBreaker pause powers, Reseal extension and Dual Governance protections must be evaluated together. D3 is a documented minimum; the entire live role/dependency graph is not certified complete.",
      "controls": [
        "DAO-controlled proxies.",
        "Dual Governance veto and rage-quit machinery.",
        "Oracle committees and withdrawal pause roles."
      ],
      "evidenceUrls": [
        "https://docs.lido.fi/guides/protocol-levers/",
        "https://docs.lido.fi/guides/dg-guide/"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "lido"
      ],
      "dependencies": [],
      "knownFloor": 3,
      "proposedRange": [
        3,
        4
      ],
      "limits": [
        "Do not call Lido D1 or infer unconditional exit protection from Dual Governance. Some emergency powers are time-limited; current expiry/roles require onchain verification."
      ],
      "assessment": "lower-bound",
      "tierBound": true,
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "lighter-robinhood-perps",
      "name": "Lighter on Robinhood",
      "kind": "protocol",
      "proposedTier": 2,
      "scope": "Canonical deployed product; additional asset and chain dependencies compose separately.",
      "reason": "The application has its own operator and proof system and is built on Robinhood; its full local authority is still being reviewed.",
      "controls": [
        "Application-specific ZK execution.",
        "USDG margin held through contracts on Robinhood Chain."
      ],
      "evidenceUrls": [
        "https://docs.robinhood.com/chain/lighter-domains/",
        "https://l2beat.com/layer2s/projects/lighter-robinhood",
        "https://robinhood.com/us/en/support/articles/robinhood-wallet-perpetual-futures/"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [
        "robinhood"
      ],
      "knownFloor": 4,
      "assessment": "lower-bound",
      "tierBound": true,
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "linea",
      "name": "Linea",
      "kind": "chain",
      "proposedTier": 8,
      "scope": "Linea mainnet, chain ID 59144; canonical rollup and forced-transaction route.",
      "reason": "Immediate upgrade authority combines with permissioned proposals and an address filter on forced transactions; the L1 route does not guarantee uncensorable exit.",
      "controls": [
        "ZK proofs validate state; proposers are permissioned during normal operation.",
        "Council-controlled proxy administrators can upgrade immediately.",
        "Council and operational roles remain privileged; a council name alone does not establish an independent user veto.",
        "Forced inclusion is address-filtered. A six-month inactivity fallback is not an ordinary permissionless exit guarantee."
      ],
      "evidenceUrls": [
        "https://l2beat.com/layer2s/projects/linea",
        "https://github.com/Consensys/linea-monorepo"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [
        "ethereum"
      ],
      "assessment": "assessed",
      "tierBound": false,
      "dimensions": {
        "Validation": "ZK proofs validate state; proposers are permissioned during normal operation.",
        "Upgrades": "Council-controlled proxy administrators can upgrade immediately.",
        "Accountability": "Council and operational roles remain privileged; a council name alone does not establish an independent user veto.",
        "Exits": "Forced inclusion is address-filtered. A six-month inactivity fallback is not an ordinary permissionless exit guarantee."
      },
      "uncertainty": "Proof correctness, asset backing and withdrawal liquidity are not certified by the authority grade.",
      "reviewBasis": "Editorial mapping from linked first-party governance records and L2BEAT contract-discovery research to this map’s D0–D9 rubric; not a conversion of L2BEAT stages.",
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "liquity-v1",
      "name": "Liquity V1",
      "kind": "protocol",
      "proposedTier": 2,
      "tierBound": true,
      "scope": "Ethereum L1 protocol mechanism; assets and integrations are separate dependencies.",
      "reason": "The borrowing core has no admin key and is immutable. Liquidations depend on Chainlink with Tellor fallback: that oracle dependency prevents a blanket D0 for the complete position.",
      "controls": [
        "The borrowing core has no admin key and is immutable. Liquidations depend on Chainlink with Tellor fallback: that oracle dependency prevents a blanket D0 for the complete position."
      ],
      "evidenceUrls": [
        "https://docs.liquity.org/liquity-v1/faq/general",
        "https://docs.liquity.org/liquity-v1/faq/stability-pool-and-liquidations"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [],
      "assessment": "lower-bound",
      "ownComponentTier": 0,
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "liquity-v2",
      "name": "Liquity V2",
      "kind": "protocol",
      "proposedTier": 2,
      "tierBound": true,
      "scope": "Ethereum L1 protocol mechanism; assets and integrations are separate dependencies.",
      "reason": "The borrowing mechanism is immutable, but Chainlink prices and collateral-specific controls affect liquidations and redemptions. wstETH/rETH branches also inherit their issuers; at least D2.",
      "controls": [
        "The borrowing mechanism is immutable, but Chainlink prices and collateral-specific controls affect liquidations and redemptions. wstETH/rETH branches also inherit their issuers; at least D2."
      ],
      "evidenceUrls": [
        "https://docs.liquity.org/v2-faq/general",
        "https://docs.liquity.org/v2-documentation/risk-disclosure"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [],
      "assessment": "lower-bound",
      "ownComponentTier": 0,
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "mantle",
      "name": "Mantle",
      "kind": "chain",
      "proposedTier": 8,
      "scope": "Mantle mainnet, chain ID 5000; current OP Succinct configuration.",
      "reason": "The administrative multisig controls both immediate upgrades and the approved proposer set; withdrawals depend on those proposers.",
      "controls": [
        "OP Succinct validity proofs with Ethereum data availability; proposals remain permissioned.",
        "A 6/14 security multisig can immediately upgrade core contracts and change verifier configuration.",
        "Administrative authority includes proof mode and approved-proposer management.",
        "L1 requests exist, but proposer failure can stop withdrawals."
      ],
      "evidenceUrls": [
        "https://l2beat.com/layer2s/projects/mantle"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [
        "ethereum"
      ],
      "assessment": "assessed",
      "tierBound": false,
      "dimensions": {
        "Validation": "OP Succinct validity proofs with Ethereum data availability; proposals remain permissioned.",
        "Upgrades": "A 6/14 security multisig can immediately upgrade core contracts and change verifier configuration.",
        "Accountability": "Administrative authority includes proof mode and approved-proposer management.",
        "Exits": "L1 requests exist, but proposer failure can stop withdrawals."
      },
      "uncertainty": "This review uses the current Ethereum-blob/OP Succinct design; it does not reuse the older external-DA description.",
      "reviewBasis": "Editorial mapping from linked first-party governance records and L2BEAT contract-discovery research to this map’s D0–D9 rubric; not a conversion of L2BEAT stages.",
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "morpho-blue",
      "name": "Morpho markets",
      "kind": "protocol",
      "proposedTier": 0,
      "scope": "Immutable Morpho Blue lending core; market oracles, collateral and managed vaults are separate.",
      "reason": "Morpho Blue’s core cannot be upgraded or paused. Governance can enable parameters for new markets and set a bounded fee, but cannot replace existing market parameters. The holdings feed does not resolve market oracles, so positions remain incomplete; managed vaults do not inherit the core’s D0.",
      "controls": [
        "Core code immutable.",
        "Governance fee switch and whitelisting of future market parameters.",
        "Each market chooses its own oracle."
      ],
      "evidenceUrls": [
        "https://docs.morpho.org/learn/governance/organization/",
        "https://docs.morpho.org/learn/concepts/oracle/",
        "https://github.com/morpho-org/morpho-blue/blob/78a059bd7318418465b06b8da96dc133e31ed3d9/src/Morpho.sol",
        "https://docs.morpho.org/developers/contracts/addresses/",
        "https://github.com/DefiLlama/DefiLlama-Adapters/blob/main/projects/morpho-blue/index.js"
      ],
      "reviewedAt": "2026-09-29",
      "aliases": [
        "morpho-blue",
        "morpho"
      ],
      "dependencies": [],
      "ownComponentTier": 0,
      "knownFloor": 0,
      "limits": [
        "Do not assign all Morpho TVL D0 merely because the core is immutable."
      ],
      "assessment": "assessed",
      "tierBound": false,
      "immutableIdentity": "Ethereum 1 Morpho Blue 0xBBBBBbbBBb9cC5e90e3b3Af64bdAF62C37EEFFCb; source commit 78a059bd7318418465b06b8da96dc133e31ed3d9",
      "positionDependenciesUnreviewed": true,
      "reviewCadence": "permanent-D0",
      "nextReviewAt": null,
      "positionReview": {
        "cadence": "monthly",
        "reviewedAt": "2026-10-01",
        "nextReviewAt": "2026-11-01",
        "status": "unresolved",
        "reason": "The aggregate financial feed lacks per-position hook/oracle identity."
      },
      "canonicalAddresses": {
        "1": "0xbbbbbbbbbb9cc5e90e3b3af64bdaf62c37eeffcb"
      },
      "sourceProof": {
        "checkedAt": "2026-09-29",
        "chainId": 1,
        "address": "0xbbbbbbbbbb9cc5e90e3b3af64bdaf62c37eeffcb",
        "provider": "sourcify-v2",
        "runtimeSha256": "fd5aa16eea01735e0e33e51e913a27f7d5ed998adc0cec2bf1f9ea368d9e1bdf",
        "sourcesSha256": "a0a725d0111a45213bc455b8e9be8f421010168e14d22d17d21425c73c0c6157",
        "contractName": "Morpho",
        "proxyDetected": false,
        "onchainCodeMatchedAt": "2026-09-29"
      }
    },
    {
      "id": "morpho-vaults",
      "name": "Morpho vaults",
      "kind": "protocol",
      "proposedTier": 2,
      "scope": "Ethereum mainnet deployment; asset-level dependencies assessed separately.",
      "reason": "Managed Morpho vaults add curator, allocator, owner and strategy controls. V2 gates can restrict withdrawals; adapters and their governance remain dependencies. These vaults do not inherit the Blue core’s D0.",
      "controls": [
        "Owner, curator, allocator, and guardian/sentinel roles.",
        "Vault v2 gates may restrict deposits, withdrawals, or receipt-token transfers."
      ],
      "evidenceUrls": [
        "https://docs.morpho.org/learn/resources/risks/",
        "https://docs.morpho.org/learn/concepts/vault-v2/"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "morpho-vaults"
      ],
      "dependencies": [],
      "knownFloor": 1,
      "limits": [
        "Vault v1/v2 and each configuration have different controls. No brand-wide tier."
      ],
      "assessment": "lower-bound",
      "tierBound": true,
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "native-eth",
      "name": "ETH",
      "kind": "asset",
      "proposedTier": 0,
      "scope": "Native asset rules on L1; custody, staking, smart-wallet modules and protocol placement must be assessed separately.",
      "reason": "Native ETH follows Ethereum account and consensus rules without a separate token issuer.",
      "controls": [],
      "evidenceUrls": [
        "https://ethereum.org/developers/docs/accounts/"
      ],
      "reviewedAt": "2026-09-08",
      "aliases": [
        "ETH",
        "asset:ethereum"
      ],
      "dependencies": [],
      "assessment": "assessed",
      "reviewCadence": "permanent-D0",
      "nextReviewAt": null,
      "immutableIdentity": "Native ETH on Ethereum mainnet chain 1; excludes staking, custody and bridges."
    },
    {
      "id": "optimism",
      "name": "OP Mainnet",
      "kind": "chain",
      "proposedTier": 5,
      "scope": "OP Mainnet; an OP Stack brand alone is not sufficient to assign another chain.",
      "reason": "A 10-of-13 elected council and the Foundation jointly authorize upgrades; a signer-loss fallback can return authority to the Foundation.",
      "controls": [
        "Joint Foundation and Security Council upgrade authority.",
        "Guardian pause and dispute-game safeguards."
      ],
      "evidenceUrls": [
        "https://l2beat.com/layer2s/projects/op-mainnet",
        "https://docs.optimism.io/op-stack/protocol/privileged-roles"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "op-mainnet",
        "op"
      ],
      "dependencies": [
        "ethereum"
      ],
      "assessment": "assessed",
      "tierBound": false,
      "dimensions": {
        "Validation": "Permissionless fault-proof participation; Ethereum data availability.",
        "Upgrades": "Joint Foundation + 10/13 Council approval; immediate emergency execution.",
        "Accountability": "Elected cohorts and a charter; Foundation fallback if council availability drops below eight.",
        "Exits": "L1 forced inclusion; there is no enforced exit window for immediate upgrades."
      },
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "optimism-canonical-bridge",
      "name": "OP canonical bridge",
      "kind": "protocol",
      "proposedTier": 5,
      "scope": "Canonical escrow/control path, not an additional capital stock.",
      "reason": "This bridge inherits the upgrade and validation arrangements of optimism.",
      "controls": [],
      "evidenceUrls": [
        "https://docs.optimism.io/op-stack/protocol/privileged-roles",
        "https://docs.optimism.io/op-stack/fault-proofs/fp-security"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [
        "optimism"
      ],
      "assessment": "assessed",
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "paxg",
      "name": "PAXG",
      "kind": "asset",
      "proposedTier": 9,
      "scope": "Ethereum mainnet deployment; asset-level dependencies assessed separately.",
      "reason": "Paxos issuer custody and asset-protection controls remain part of the asset.",
      "controls": [
        "Offchain backing.",
        "Issuer freeze and balance-wipe powers."
      ],
      "evidenceUrls": [
        "https://github.com/paxosglobal/paxos-token-contracts"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "PAXG"
      ],
      "dependencies": [],
      "assessment": "assessed",
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "pendle-v2",
      "name": "Pendle v2",
      "kind": "protocol",
      "proposedTier": 2,
      "scope": "Canonical deployed product; additional asset and chain dependencies compose separately.",
      "reason": "Yield wrappers and underlying yield protocols add dependencies that differ by market.",
      "controls": [
        "Market-specific yield-asset and adapter dependencies."
      ],
      "evidenceUrls": [
        "https://docs.pendle.finance/pendle-v2/Security",
        "https://docs.pendle.finance/pendle-v2/FAQ"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [],
      "knownFloor": 0,
      "assessment": "lower-bound",
      "tierBound": true,
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "pyusd",
      "name": "PYUSD",
      "kind": "asset",
      "proposedTier": 9,
      "scope": "Ethereum mainnet deployment; asset-level dependencies assessed separately.",
      "reason": "Paxos issuer custody and asset-protection controls remain part of the asset.",
      "controls": [
        "Offchain backing.",
        "Issuer freeze and balance-wipe powers."
      ],
      "evidenceUrls": [
        "https://github.com/paxosglobal/paxos-token-contracts"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "PYUSD"
      ],
      "dependencies": [],
      "assessment": "assessed",
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "reth",
      "name": "rETH",
      "kind": "asset",
      "proposedTier": 0,
      "scope": "Ethereum mainnet deployment; asset-level dependencies assessed separately.",
      "reason": "The rETH claim inherits Rocket Pool governance and oracle reporting.",
      "controls": [
        "Protocol-managed staking backing and exchange rate."
      ],
      "evidenceUrls": [
        "https://docs.rocketpool.net/odao/overview"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "RETH",
        "rETH"
      ],
      "dependencies": [
        "rocket-pool"
      ],
      "knownFloor": 3,
      "proposedRange": [
        3,
        4
      ],
      "assessment": "assessed",
      "tierBound": false,
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "rlusd",
      "name": "RLUSD token",
      "kind": "asset",
      "proposedTier": 9,
      "assessment": "assessed",
      "scope": "Ethereum-mainnet issuer-backed token, including material offchain reserve custody and redemption.",
      "reason": "Ripple issuer terms and current upgradeable implementation permit issuer-directed freezing, burning and redemption restrictions. Offchain reserves/redemption are material dependencies.",
      "controls": [
        "Ripple issuer terms and current upgradeable implementation permit issuer-directed freezing, burning and redemption restrictions"
      ],
      "evidenceUrls": [
        "https://sourcify.dev/server/v2/contract/1/0x8292bb45bf1ee4d140127049757c2e0ff06317ed?fields=sources,compilation,runtimeBytecode,proxyResolution,deployment",
        "https://etherscan.io/address/0x8292bb45bf1ee4d140127049757c2e0ff06317ed#code",
        "https://ripple.com/legal/stablecoin/"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "stable:250"
      ],
      "dependencies": [],
      "canonicalAddresses": {
        "1": "0x8292bb45bf1ee4d140127049757c2e0ff06317ed"
      },
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ],
      "sourceProof": {
        "checkedAt": "2026-10-01",
        "chainId": 1,
        "address": "0x8292bb45bf1ee4d140127049757c2e0ff06317ed",
        "provider": "sourcify-v2",
        "runtimeSha256": "3cdada1041aee049edb12621061b4f063217a1f2c77b15a854d1b59f971e6783",
        "sourcesSha256": "387d844ce2df59b5c5ceb13385d49dfd8ffd23d0e674f56b60d338b69b043a04",
        "contractName": "StablecoinProxy",
        "proxyDetected": true,
        "implementation": {
          "address": "0x9747a0d261c2d56Eb93f542068e5d1E23170fa9e",
          "name": "StablecoinUpgradeableV2"
        },
        "onchainCodeMatchedAt": "2026-10-01"
      }
    },
    {
      "id": "robinhood",
      "name": "Robinhood Chain",
      "kind": "chain",
      "proposedTier": 8,
      "scope": "Robinhood mainnet, chain ID 4663; Ethereum-settled rollup, not a child of Arbitrum One.",
      "reason": "Immediate upgrades, two whitelisted challengers and operator transaction filtering concentrate authority beyond a public security council model.",
      "controls": [
        "No enforced upgrade delay.",
        "Whitelisted challengers.",
        "Transaction filtering can prevent inclusion even through the L1 route."
      ],
      "evidenceUrls": [
        "https://l2beat.com/layer2s/projects/robinhood",
        "https://docs.robinhood.com/chain/differences-from-ethereum/"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [
        "ethereum"
      ],
      "assessment": "assessed",
      "tierBound": false,
      "dimensions": {
        "Validation": "Fraud proofs are deployed, but only two whitelisted actors may challenge.",
        "Upgrades": "No enforced upgrade delay; operator-governed administration.",
        "Accountability": "No independent elected security council is documented for this deployment.",
        "Exits": "Transaction filtering can defeat forced inclusion; permissionless exit guarantees are limited."
      },
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "robinhood-chain-bridge",
      "name": "Robinhood canonical bridge",
      "kind": "protocol",
      "proposedTier": 8,
      "scope": "Canonical bridge contracts; balances represented on Robinhood must not also be counted as separate L1 capital.",
      "reason": "This bridge inherits the upgrade and validation arrangements of robinhood.",
      "controls": [
        "Upgradeable escrow and messaging contracts."
      ],
      "evidenceUrls": [
        "https://l2beat.com/layer2s/projects/robinhood"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [
        "robinhood"
      ],
      "assessment": "assessed",
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "rocket-pool",
      "name": "Rocket Pool",
      "kind": "protocol",
      "proposedTier": 2,
      "scope": "Ethereum mainnet deployment; asset-level dependencies assessed separately.",
      "reason": "Oracle reporting and upgrade governance add dependencies; the complete current emergency and delay boundaries remain under review.",
      "controls": [
        "Oracle DAO reporting.",
        "Oracle DAO contract replacement authority.",
        "Protocol DAO and Security Council roles."
      ],
      "evidenceUrls": [
        "https://docs.rocketpool.net/odao/proposals",
        "https://dao.rocketpool.net/t/rocket-pool-powers-and-authorities/2176",
        "https://docs.rocketpool.net/pdao/overview"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "rocket-pool"
      ],
      "dependencies": [],
      "knownFloor": 3,
      "proposedRange": [
        3,
        4
      ],
      "limits": [
        "Do not equate permissionless validator entry with immutable pooled-asset custody."
      ],
      "assessment": "lower-bound",
      "tierBound": true,
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "rseth",
      "name": "rsETH",
      "kind": "asset",
      "proposedTier": 9,
      "scope": "Canonical deployed product; additional asset and chain dependencies compose separately.",
      "reason": "The issuer documents per-address transfer holds and recovery of frozen balances to custody.",
      "controls": [
        "Address-specific freeze and recovery powers.",
        "Upgradeable restaking token."
      ],
      "evidenceUrls": [
        "https://kerneldao.gitbook.io/kernel/getting-started/kelp/smart-contracts/upgrades",
        "https://github.com/Kelp-DAO/LRT-rsETH"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "RSETH",
        "rsETH"
      ],
      "dependencies": [
        "eigenlayer"
      ],
      "assessment": "assessed",
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "sablier-flow",
      "name": "Sablier Flow",
      "kind": "protocol",
      "proposedTier": 1,
      "tierBound": true,
      "scope": "Ethereum L1 protocol mechanism; assets and integrations are separate dependencies.",
      "reason": "The fixed streaming mechanism has bounded Comptroller administration. Stream participants retain contractual pause/refund powers, and asset controls remain separate. At least D1 for the family; assess each stream configuration.",
      "controls": [
        "The fixed streaming mechanism has bounded Comptroller administration. Stream participants retain contractual pause/refund powers, and asset controls remain separate. At least D1 for the family; assess each stream configuration."
      ],
      "evidenceUrls": [
        "https://docs.sablier.com/concepts/governance",
        "https://docs.sablier.com/concepts/flow/overview"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [],
      "assessment": "lower-bound",
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "sablier-lockup",
      "name": "Sablier Lockup",
      "kind": "protocol",
      "proposedTier": 1,
      "tierBound": true,
      "scope": "Ethereum L1 protocol mechanism; assets and integrations are separate dependencies.",
      "reason": "Distribution code is non-upgradeable and the protocol admin cannot pause streams or seize user funds. Comptroller settings, fees and hook permissions remain; cancellation and token dependencies vary by stream. At least D1 for the current family.",
      "controls": [
        "Distribution code is non-upgradeable and the protocol admin cannot pause streams or seize user funds. Comptroller settings, fees and hook permissions remain; cancellation and token dependencies vary by stream. At least D1 for the current family."
      ],
      "evidenceUrls": [
        "https://docs.sablier.com/concepts/governance",
        "https://docs.sablier.com/concepts/lockup/overview"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [],
      "assessment": "lower-bound",
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "scroll",
      "name": "Scroll",
      "kind": "chain",
      "proposedTier": 7,
      "scope": "Scroll mainnet, chain ID 534352; reviewed current authority and permissionless fallback routes.",
      "reason": "The team admin multisig holds immediate upgrade authority, while public proving and L1 inclusion provide ordinary operator-failure fallbacks.",
      "controls": [
        "ZK proofs; public software supports independent proposals.",
        "Team-controlled ScrollAdminMultisig can use the zero-delay emergency path.",
        "The reviewed governance record describes replacement of the independent council in June 2026; token voting does not directly execute upgrades.",
        "Forced inclusion and self-proposal exist, but an immediate upgrade can bypass an exit window."
      ],
      "evidenceUrls": [
        "https://l2beat.com/layer2s/projects/scroll"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [
        "ethereum"
      ],
      "assessment": "assessed",
      "tierBound": false,
      "dimensions": {
        "Validation": "ZK proofs; public software supports independent proposals.",
        "Upgrades": "Team-controlled ScrollAdminMultisig can use the zero-delay emergency path.",
        "Accountability": "The reviewed governance record describes replacement of the independent council in June 2026; token voting does not directly execute upgrades.",
        "Exits": "Forced inclusion and self-proposal exist, but an immediate upgrade can bypass an exit window."
      },
      "uncertainty": "Authority, not a maturity stage, determines D7. Later council changes require a fresh review of actual on-chain powers.",
      "reviewBasis": "Editorial mapping from linked first-party governance records and L2BEAT contract-discovery research to this map’s D0–D9 rubric; not a conversion of L2BEAT stages.",
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "seaport-v1.6",
      "name": "Seaport 1.6",
      "kind": "protocol",
      "proposedTier": 0,
      "assessment": "assessed",
      "scope": "Canonical immutable Ethereum settlement core; excludes unreviewed zones, conduit channels, NFT contracts and contract offerers.",
      "reason": "The canonical nonproxy Seaport 1.6 settlement core has no administrator, pause or implementation replacement path. Order makers choose assets, zones, conduits and contract offerers; those selected dependencies are separate reviews.",
      "controls": [],
      "evidenceUrls": [
        "https://sourcify.dev/server/v2/contract/1/0x0000000000000068f116a894984e2db1123eb395?fields=sources,compilation,runtimeBytecode,proxyResolution,deployment",
        "https://etherscan.io/address/0x0000000000000068f116a894984e2db1123eb395#code",
        "https://github.com/ProjectOpenSea/seaport/blob/main/docs/Deployment.md"
      ],
      "reviewedAt": "2026-09-29",
      "aliases": [],
      "dependencies": [],
      "canonicalAddresses": {
        "1": "0x0000000000000068f116a894984e2db1123eb395"
      },
      "reviewCadence": "permanent-D0",
      "nextReviewAt": null,
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ],
      "immutableIdentity": "Ethereum 1 Seaport 1.6 0x0000000000000068f116a894984e2db1123eb395",
      "positionDependenciesUnreviewed": true,
      "positionReview": {
        "cadence": "monthly",
        "reviewedAt": "2026-10-01",
        "nextReviewAt": "2026-11-01",
        "status": "unresolved",
        "reason": "Order-specific zones, conduits and asset controls are not identified by an aggregate app label."
      },
      "sourceProof": {
        "checkedAt": "2026-09-29",
        "chainId": 1,
        "address": "0x0000000000000068f116a894984e2db1123eb395",
        "provider": "sourcify-v2",
        "runtimeSha256": "ddb298880d43346e28e2d6668b23f4e76112e68922d2df9e17cd02315908fb71",
        "sourcesSha256": "0142ac203955965098563efe1fd81af0f454c53df2d1a38339ee786dbaba72e7",
        "contractName": "Seaport",
        "proxyDetected": false,
        "onchainCodeMatchedAt": "2026-09-29"
      }
    },
    {
      "id": "sfrxeth",
      "name": "sfrxETH",
      "kind": "asset",
      "proposedTier": 0,
      "scope": "Canonical deployed product; additional asset and chain dependencies compose separately.",
      "reason": "The yield wrapper inherits frxETH and its staking system.",
      "controls": [],
      "evidenceUrls": [
        "https://docs.frax.com/protocol/assets/frxeth/technical"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "SFRXETH",
        "sfrxETH"
      ],
      "dependencies": [
        "frxeth"
      ],
      "knownFloor": 2,
      "assessment": "assessed",
      "tierBound": false,
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "sky",
      "name": "Sky / Maker",
      "kind": "protocol",
      "proposedTier": 3,
      "scope": "Ethereum mainnet deployment; asset-level dependencies assessed separately.",
      "reason": "Governance controls issuance, collateral policy, and system changes through executive actions.",
      "controls": [
        "Governance-controlled collateral and issuance parameters.",
        "Oracle and collateral dependencies vary by vault."
      ],
      "evidenceUrls": [
        "https://github.com/sky-ecosystem/developerguides/blob/master/dai/dai-token/dai-token.md",
        "https://vote.sky.money/polling/QmX7MC2S"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "makerdao",
        "maker",
        "sky-lending"
      ],
      "dependencies": [],
      "limits": [
        "The building tier describes governance; custodial collateral can give particular capital a higher effective tier."
      ],
      "assessment": "assessed",
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "soneium",
      "name": "Soneium",
      "kind": "chain",
      "proposedTier": 8,
      "scope": "Soneium mainnet, chain ID 1868; protocol authority, not website terms alone.",
      "reason": "Permissioned state proposals and challenges make ordinary exits depend on designated operators, in addition to immediate Foundation/council upgrades.",
      "controls": [
        "Only designated proposers/challengers participate. The reviewed discovery reports a placeholder dispute prestate, not an independently executable fault-proof route.",
        "Optimism Foundation and Security Council control upgrades without an enforced exit window.",
        "Shared Optimism governance does not make Soneium validation permissionless.",
        "L1 inclusion exists; withdrawals can still stop when designated proposers stop."
      ],
      "evidenceUrls": [
        "https://l2beat.com/layer2s/projects/soneium",
        "https://docs.soneium.org/docs/tos/"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [
        "ethereum"
      ],
      "assessment": "assessed",
      "tierBound": false,
      "dimensions": {
        "Validation": "Only designated proposers/challengers participate. The reviewed discovery reports a placeholder dispute prestate, not an independently executable fault-proof route.",
        "Upgrades": "Optimism Foundation and Security Council control upgrades without an enforced exit window.",
        "Accountability": "Shared Optimism governance does not make Soneium validation permissionless.",
        "Exits": "L1 inclusion exists; withdrawals can still stop when designated proposers stop."
      },
      "uncertainty": "The deployment review carries an upstream change warning; the permissioned validation and exit dependency is the controlling D8 finding.",
      "reviewBasis": "Editorial mapping from linked first-party governance records and L2BEAT contract-discovery research to this map’s D0–D9 rubric; not a conversion of L2BEAT stages.",
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "spark-liquidity-layer",
      "name": "Spark Liquidity Layer",
      "kind": "protocol",
      "proposedTier": 3,
      "scope": "Ethereum mainnet deployment; asset-level dependencies assessed separately.",
      "reason": "Governance controls allocation across destinations; each destination can add further administration or custody.",
      "controls": [
        "Upgradeable conduit contracts.",
        "Allocations into DeFi, centralized finance, and real-world assets."
      ],
      "evidenceUrls": [
        "https://github.com/sparkdotfi/sparklend-conduits",
        "https://docs.spark.finance/"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [],
      "knownFloor": 3,
      "proposedRange": [
        3,
        5
      ],
      "assessment": "lower-bound",
      "tierBound": true,
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "spark-savings",
      "name": "Spark Savings",
      "kind": "protocol",
      "proposedTier": 3,
      "scope": "Canonical deployed product; additional asset and chain dependencies compose separately.",
      "reason": "Savings and allocation contracts inherit Sky governance; destination-specific custody may add stronger restrictions.",
      "controls": [
        "Savings claims and underlying allocation dependencies."
      ],
      "evidenceUrls": [
        "https://docs.spark.finance/",
        "https://developers.skyeco.com/protocol/tokens/susds/"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [],
      "knownFloor": 3,
      "assessment": "lower-bound",
      "tierBound": true,
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "sparklend",
      "name": "SparkLend",
      "kind": "protocol",
      "proposedTier": 3,
      "scope": "Ethereum mainnet deployment; asset-level dependencies assessed separately.",
      "reason": "Governance can upgrade the pool and execute changes after the governance delay.",
      "controls": [
        "Upgradeable lending pool.",
        "Dedicated freezer and pauser roles.",
        "Collateral and price-feed dependencies."
      ],
      "evidenceUrls": [
        "https://github.com/sparkdotfi/sparklend-deployments",
        "https://github.com/sparkdotfi/sparklend-freezer",
        "https://vote.makerdao.com/polling/QmZND8WW"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "spark",
        "spark-lending"
      ],
      "dependencies": [],
      "limits": [
        "Only SparkLend; Spark Liquidity Layer, savings products, and RWA allocations are distinct dependency paths."
      ],
      "assessment": "assessed",
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "starknet",
      "name": "Starknet",
      "kind": "chain",
      "proposedTier": 8,
      "scope": "Starknet mainnet core and mapped canonical asset routes; ancillary bridge escrows may have separate administration.",
      "reason": "Validity proofs constrain state correctness, but users still need permissioned operators or a council minority to get censored transactions processed.",
      "controls": [
        "STARK-based validity proofs; state updates require a designated operator.",
        "Core normal route: StarkWare multisig with eight-day delay. A 9/12 appointed council can act immediately; other bridge escrows have separate immediate administrators.",
        "Foundation-appointed council; token votes do not create permissionless execution rights.",
        "L1 complaints cannot force execution. A 3/12 council minority can intervene, so independent exit still depends on that group."
      ],
      "evidenceUrls": [
        "https://l2beat.com/layer2s/projects/starknet",
        "https://github.com/starknet-io/SNIPs/blob/main/SNIPS/snip-25.md"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [
        "ethereum"
      ],
      "assessment": "assessed",
      "tierBound": false,
      "dimensions": {
        "Validation": "STARK-based validity proofs; state updates require a designated operator.",
        "Upgrades": "Core normal route: StarkWare multisig with eight-day delay. A 9/12 appointed council can act immediately; other bridge escrows have separate immediate administrators.",
        "Accountability": "Foundation-appointed council; token votes do not create permissionless execution rights.",
        "Exits": "L1 complaints cannot force execution. A 3/12 council minority can intervene, so independent exit still depends on that group."
      },
      "uncertainty": "D8 follows the exit/validation dimension despite stronger safeguards on the ordinary core upgrade path. Bridge-specific rights and proof assumptions remain separate risks.",
      "reviewBasis": "Editorial mapping from linked first-party governance records and L2BEAT contract-discovery research to this map’s D0–D9 rubric; not a conversion of L2BEAT stages.",
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "steth",
      "name": "stETH",
      "kind": "asset",
      "proposedTier": 0,
      "scope": "Ethereum mainnet deployment; asset-level dependencies assessed separately.",
      "reason": "The stETH claim inherits Lido governance, oracle and withdrawal arrangements.",
      "controls": [
        "Rebasing staking claim.",
        "Redemption through Lido withdrawal machinery."
      ],
      "evidenceUrls": [
        "https://docs.lido.fi/guides/lido-tokens-integration-guide/",
        "https://docs.lido.fi/contracts/lido/",
        "https://docs.lido.fi/deployed-contracts/"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "STETH",
        "stETH"
      ],
      "dependencies": [
        "lido"
      ],
      "knownFloor": 3,
      "proposedRange": [
        3,
        4
      ],
      "canonicalAddresses": {
        "1": "0xae7ab96520de3a18e5e111b5eaab095312d7fe84"
      },
      "assessment": "lower-bound",
      "tierBound": true,
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ],
      "sourceProof": {
        "checkedAt": "2026-10-01",
        "chainId": 1,
        "address": "0xae7ab96520de3a18e5e111b5eaab095312d7fe84",
        "provider": "sourcify-v2",
        "runtimeSha256": "a0c39c8f8658ba7d2f91e20e81ca0ecf754ded062ee08b4f24c82902d98c2865",
        "sourcesSha256": "859307e5ff81c76eb25759c07a648fb2fd28d18b2aa29b2929c712ab46eade65",
        "contractName": "AppProxyUpgradeable",
        "proxyDetected": true,
        "onchainCodeMatchedAt": "2026-10-01"
      }
    },
    {
      "id": "susde",
      "name": "sUSDe",
      "kind": "asset",
      "proposedTier": 9,
      "scope": "Ethereum mainnet deployment; asset-level dependencies assessed separately.",
      "reason": "The staking receipt retains USDe’s custodial-backing dependencies.",
      "controls": [
        "Receipt contract has additional administrative restrictions."
      ],
      "evidenceUrls": [
        "https://github.com/ethena-labs/bbp-public-assets/blob/main/contracts/contracts/StakedUSDe.sol"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "SUSDE",
        "sUSDe"
      ],
      "dependencies": [
        "usde"
      ],
      "assessment": "assessed",
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "susds",
      "name": "sUSDS",
      "kind": "asset",
      "proposedTier": 3,
      "scope": "Ethereum mainnet deployment; asset-level dependencies assessed separately.",
      "reason": "The savings contract inherits USDS governance, collateral backing and its own upgrade arrangements.",
      "controls": [
        "Upgradeable ERC-4626 savings claim."
      ],
      "evidenceUrls": [
        "https://developers.skyeco.com/protocol/tokens/susds/"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "SUSDS",
        "sUSDS"
      ],
      "dependencies": [
        "usds"
      ],
      "ownComponentTier": 3,
      "knownFloor": 3,
      "proposedRange": [
        3,
        5
      ],
      "assessment": "lower-bound",
      "tierBound": true,
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "tbtc",
      "name": "tBTC",
      "kind": "asset",
      "proposedTier": 2,
      "scope": "Canonical token mechanism; deployment-specific custody adds inherited bounds.",
      "reason": "BTC redemption relies on an external threshold-signing network; governance and bridge safeguards add dependencies.",
      "controls": [
        "BTC redemption relies on an external threshold-signing network; governance and bridge safeguards add dependencies."
      ],
      "evidenceUrls": [
        "https://docs.threshold.network/applications/tbtc-v2"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "tBTC"
      ],
      "dependencies": [],
      "assessment": "lower-bound",
      "tierBound": true,
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "token:0x",
      "name": "0x Protocol token",
      "kind": "asset",
      "proposedTier": 0,
      "assessment": "assessed",
      "scope": "Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.",
      "reason": "Nonproxy ZRX initializes a fixed supply and exposes holder-authorized ERC20 transfers and allowances. No privileged mint, freeze or replacement path exists. Exchange protocol contracts are separate.",
      "controls": [],
      "evidenceUrls": [
        "https://sourcify.dev/server/v2/contract/1/0xe41d2489571d322189246dafa5ebde1f4699f498?fields=sources,compilation,runtimeBytecode,proxyResolution,deployment",
        "https://etherscan.io/address/0xe41d2489571d322189246dafa5ebde1f4699f498#code"
      ],
      "reviewedAt": "2026-09-29",
      "aliases": [],
      "dependencies": [],
      "canonicalAddresses": {
        "1": "0xe41d2489571d322189246dafa5ebde1f4699f498"
      },
      "reviewCadence": "permanent-D0",
      "nextReviewAt": null,
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ],
      "sourceProof": {
        "checkedAt": "2026-09-29",
        "chainId": 1,
        "address": "0xe41d2489571d322189246dafa5ebde1f4699f498",
        "provider": "sourcify-v2",
        "runtimeSha256": "d2bee6e7704049047c72210dcbc9cb6a4d433eeddad59fcdda66b2479522f35e",
        "sourcesSha256": "e2e4bc6cc784d7371243bd136de00ae0fe3716ef6745c80bcbbf937139625f62",
        "contractName": "ZRXToken",
        "proxyDetected": false,
        "onchainCodeMatchedAt": "2026-09-29"
      },
      "immutableIdentity": "Chain 1 0xe41d2489571d322189246dafa5ebde1f4699f498; reviewed runtime SHA256 d2bee6e7704049047c72210dcbc9cb6a4d433eeddad59fcdda66b2479522f35e."
    },
    {
      "id": "token:1inch",
      "name": "1INCH token",
      "kind": "asset",
      "proposedTier": 0,
      "assessment": "assessed",
      "scope": "Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.",
      "reason": "Matched nonproxy OneInch code restricts mint and ownership changes to onlyOwner. The live owner is zero, making those paths permanently unreachable; the complete inherited ERC20/permit/burn code has no alternative mint, freeze, upgrade or controller path. Runtime was independently matched at the recorded block. This token holding is separate from router pauses and orders.",
      "controls": [],
      "evidenceUrls": [
        "https://sourcify.dev/server/v2/contract/1/0x111111111117dc0aa78b770fa6a738034120c302?fields=sources,compilation,runtimeBytecode,proxyResolution,deployment",
        "https://etherscan.io/address/0x111111111117dc0aa78b770fa6a738034120c302#code"
      ],
      "reviewedAt": "2026-09-29",
      "aliases": [],
      "dependencies": [],
      "canonicalAddresses": {
        "1": "0x111111111117dc0aa78b770fa6a738034120c302"
      },
      "reviewCadence": "permanent-D0",
      "nextReviewAt": null,
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ],
      "sourceProof": {
        "checkedAt": "2026-09-29",
        "chainId": 1,
        "address": "0x111111111117dc0aa78b770fa6a738034120c302",
        "provider": "sourcify-v2",
        "runtimeSha256": "0c9c93408618ecb9b6080ae60b04cea125d14d5932f51c67e1219ec1266a949d",
        "sourcesSha256": "59a8152385fec0ae1a290c1966777a481b140d15c1d9581bec98a73703537ec8",
        "contractName": "OneInch",
        "proxyDetected": false,
        "authorityChecks": [
          {
            "method": "owner()",
            "value": "0x0000000000000000000000000000000000000000000000000000000000000000",
            "block": "0x18e0c5c"
          }
        ],
        "onchainCodeMatchedAt": "2026-09-29"
      },
      "knownFloor": 0,
      "tierBound": false,
      "limits": [
        "D0 applies to this token holding, not the 1inch router or unreviewed representations."
      ],
      "immutableIdentity": "Ethereum 1 0x111111111117dc0aa78b770fa6a738034120c302; runtime SHA256 0c9c93408618ecb9b6080ae60b04cea125d14d5932f51c67e1219ec1266a949d; irreversibly renounced ownership."
    },
    {
      "id": "token:aave",
      "name": "Aave token",
      "kind": "asset",
      "proposedTier": 3,
      "assessment": "lower-bound",
      "scope": "Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.",
      "reason": "AAVE is an admin-upgradeable token, currently resolved to AaveTokenV3. The EIP1967 admin slot is nonzero. Implementation replacement can change balance/transfer rules; complete the admin execution, delay and emergency paths before assigning a complete grade. Aave lending versions are separate.",
      "controls": [
        "AAVE is an admin-upgradeable token, currently resolved to AaveTokenV3"
      ],
      "evidenceUrls": [
        "https://sourcify.dev/server/v2/contract/1/0x7fc66500c84a76ad7e9c93437bfc5ac33e2ddae9?fields=sources,compilation,runtimeBytecode,proxyResolution,deployment",
        "https://etherscan.io/address/0x7fc66500c84a76ad7e9c93437bfc5ac33e2ddae9#code"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [],
      "canonicalAddresses": {
        "1": "0x7fc66500c84a76ad7e9c93437bfc5ac33e2ddae9"
      },
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ],
      "sourceProof": {
        "checkedAt": "2026-10-01",
        "chainId": 1,
        "address": "0x7fc66500c84a76ad7e9c93437bfc5ac33e2ddae9",
        "provider": "sourcify-v2",
        "runtimeSha256": "a6399a3c59bc187d50c6fe611bd8767f7058e3a516399c64141a5cb3c61ff676",
        "sourcesSha256": "ef4524405c605c7f12dcf3b9975a97eec2807a57295c55521f7a4a6251381436",
        "contractName": "InitializableAdminUpgradeabilityProxy",
        "proxyDetected": true,
        "implementation": {
          "address": "0x5D4Aa78B08Bc7C530e21bf7447988b1Be7991322",
          "name": "AaveTokenV3"
        },
        "onchainCodeMatchedAt": "2026-10-01",
        "authorityChecks": [
          {
            "method": "admin",
            "value": "0x00000000000000000000000086c3ffee349a7cff7ca88c449717b1b133bfb517",
            "block": "0x18e39b6"
          }
        ]
      },
      "knownFloor": 3,
      "tierBound": true,
      "limits": [
        "Live role/controller/dependency closure remains incomplete; keep the established floor."
      ]
    },
    {
      "id": "token:aerodrome-finance",
      "name": "Aerodrome Finance token",
      "kind": "asset",
      "proposedTier": 1,
      "assessment": "lower-bound",
      "scope": "Ordinary holding of the recorded token deployment on chain 8453; excludes protocol positions and unreviewed representations.",
      "reason": "Native AERO on Base chain 8453 has a changeable minter and mint path. This is not an Ethereum-mainnet ERC20. Close minter/controller roles and compose Base chain authority; Aerodrome pools and bridged representations are separate.",
      "controls": [
        "Native AERO on Base chain 8453 has a changeable minter and mint path"
      ],
      "evidenceUrls": [
        "https://sourcify.dev/server/v2/contract/8453/0x940181a94a35a4569e4529a3cdfb74e38fd98631?fields=sources,compilation,runtimeBytecode,proxyResolution,deployment",
        "https://basescan.org/address/0x940181a94a35a4569e4529a3cdfb74e38fd98631#code"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [
        "base"
      ],
      "canonicalAddresses": {
        "8453": "0x940181a94a35a4569e4529a3cdfb74e38fd98631"
      },
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ],
      "sourceProof": {
        "checkedAt": "2026-10-01",
        "chainId": 8453,
        "address": "0x940181a94a35a4569e4529a3cdfb74e38fd98631",
        "provider": "sourcify-v2",
        "runtimeSha256": "b1c9be00acc529956bb2ebd62982fe177365982d715e905b6285e5727614f735",
        "sourcesSha256": "fe9ede49edd3afbdf38a40eb4a72d76d6d418ac154e8275a8211ad3e295941ca",
        "contractName": "Aero",
        "proxyDetected": false,
        "onchainCodeMatchedAt": "2026-10-01",
        "authorityChecks": [
          {
            "method": "minter()",
            "value": "0x000000000000000000000000eb018363f0a9af8f91f06fee6613a751b2a33fe5",
            "block": "0x31a0979"
          }
        ]
      },
      "knownFloor": 1,
      "tierBound": true,
      "limits": [
        "Live role/controller/dependency closure remains incomplete; keep the established floor."
      ]
    },
    {
      "id": "token:arbitrum",
      "name": "Arbitrum token",
      "kind": "asset",
      "proposedTier": 3,
      "assessment": "lower-bound",
      "scope": "Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.",
      "reason": "Ethereum ARB is an upgradeable L1 bridge representation with a nonzero proxy admin. Its gateway can mint and burn balances. Close gateway custody, native ARB backing and DAO/council upgrade timing; Arbitrum chain governance is a separate reviewed dependency.",
      "controls": [
        "Ethereum ARB is an upgradeable L1 bridge representation with a nonzero proxy admin"
      ],
      "evidenceUrls": [
        "https://sourcify.dev/server/v2/contract/1/0xb50721bcf8d664c30412cfbc6cf7a15145234ad1?fields=sources,compilation,runtimeBytecode,proxyResolution,deployment",
        "https://etherscan.io/address/0xb50721bcf8d664c30412cfbc6cf7a15145234ad1#code"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [
        "arbitrum"
      ],
      "canonicalAddresses": {
        "1": "0xb50721bcf8d664c30412cfbc6cf7a15145234ad1"
      },
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ],
      "sourceProof": {
        "checkedAt": "2026-10-01",
        "chainId": 1,
        "address": "0xb50721bcf8d664c30412cfbc6cf7a15145234ad1",
        "provider": "sourcify-v2",
        "runtimeSha256": "5673f7712b62a6106cbc2f1ce59b0894f537065ad84197f7b875cac051161ff7",
        "sourcesSha256": "ca94afa7abcc521dc4310621b716c4c9a79d82cd9669db5f8ad4478649bada4b",
        "contractName": "TransparentUpgradeableProxy",
        "proxyDetected": true,
        "implementation": {
          "address": "0xAD0C361Ef902A7D9851Ca7DcC85535DA2d3C6Fc7",
          "name": "L1ArbitrumToken"
        },
        "onchainCodeMatchedAt": "2026-10-01",
        "authorityChecks": [
          {
            "method": "admin",
            "value": "0x0000000000000000000000005613af0474eb9c528a34701a5b1662e3c8fa0678",
            "block": "0x18e39b8"
          }
        ]
      },
      "knownFloor": 3,
      "tierBound": true,
      "limits": [
        "Live role/controller/dependency closure remains incomplete; keep the established floor."
      ]
    },
    {
      "id": "token:balancer",
      "name": "Balancer token",
      "kind": "asset",
      "proposedTier": 1,
      "assessment": "lower-bound",
      "scope": "Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.",
      "reason": "BAL has fixed token transfer code. Live enumeration found zero default admins and one minter; the initial admin-grant power is therefore absent. Close the remaining minter contract and its reachable issuance/controller path before a complete holding grade. Balancer vaults, pools and emergency roles are separate.",
      "controls": [
        "One live minter role; its reachable issuance/controller path remains unresolved."
      ],
      "evidenceUrls": [
        "https://sourcify.dev/server/v2/contract/1/0xba100000625a3754423978a60c9317c58a424e3d?fields=sources,compilation,runtimeBytecode,proxyResolution,deployment",
        "https://etherscan.io/address/0xba100000625a3754423978a60c9317c58a424e3d#code"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [],
      "canonicalAddresses": {
        "1": "0xba100000625a3754423978a60c9317c58a424e3d"
      },
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ],
      "sourceProof": {
        "checkedAt": "2026-10-01",
        "chainId": 1,
        "address": "0xba100000625a3754423978a60c9317c58a424e3d",
        "provider": "sourcify-v2",
        "runtimeSha256": "53fe465c676ff40f4512e3153a600abc685718de4dbe5250bbf5c216e70c393c",
        "sourcesSha256": "45a799b433f14d3f6ea633e6562451b33936a64fbb2ee8acb36f9a886a29fa6a",
        "contractName": "BalancerGovernanceToken",
        "proxyDetected": false,
        "onchainCodeMatchedAt": "2026-10-01",
        "authorityChecks": [
          {
            "method": "getRoleMemberCount(bytes32):admin",
            "value": "0x0000000000000000000000000000000000000000000000000000000000000000",
            "block": "0x18e39b8"
          },
          {
            "method": "getRoleMemberCount(bytes32):minter",
            "value": "0x0000000000000000000000000000000000000000000000000000000000000001",
            "block": "0x18e39b8"
          }
        ]
      },
      "knownFloor": 1,
      "tierBound": true,
      "limits": [
        "Live role/controller/dependency closure remains incomplete; keep the established floor."
      ]
    },
    {
      "id": "token:basic-attention-token",
      "name": "Basic Attention token",
      "kind": "asset",
      "proposedTier": 0,
      "assessment": "assessed",
      "scope": "Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.",
      "reason": "Nonproxy BAT is irreversibly finalized: live isFinalized() returned true and source provides no reset. Crowdsale creation/refund paths are disabled thereafter. Ordinary transfers have no administrator, freeze or replacement path. Brave services are separate.",
      "controls": [],
      "evidenceUrls": [
        "https://sourcify.dev/server/v2/contract/1/0x0d8775f648430679a709e98d2b0cb6250d2887ef?fields=sources,compilation,runtimeBytecode,proxyResolution,deployment",
        "https://etherscan.io/address/0x0d8775f648430679a709e98d2b0cb6250d2887ef#code"
      ],
      "reviewedAt": "2026-09-29",
      "aliases": [],
      "dependencies": [],
      "canonicalAddresses": {
        "1": "0x0d8775f648430679a709e98d2b0cb6250d2887ef"
      },
      "reviewCadence": "permanent-D0",
      "nextReviewAt": null,
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ],
      "sourceProof": {
        "checkedAt": "2026-09-29",
        "chainId": 1,
        "address": "0x0d8775f648430679a709e98d2b0cb6250d2887ef",
        "provider": "sourcify-v2",
        "runtimeSha256": "03906e66023fe3e276ea9ba6bde9114049968682b0120956b4d3502e871eaa07",
        "sourcesSha256": "94480650dba3f7b92047fc361d4733b12c5d675861654ba8ebee7bcee4ca7fc4",
        "contractName": "BAToken",
        "proxyDetected": false,
        "onchainCodeMatchedAt": "2026-09-29",
        "stateChecks": [
          {
            "method": "isFinalized()",
            "value": "0x0000000000000000000000000000000000000000000000000000000000000001"
          }
        ]
      },
      "immutableIdentity": "Chain 1 0x0d8775f648430679a709e98d2b0cb6250d2887ef; reviewed runtime SHA256 03906e66023fe3e276ea9ba6bde9114049968682b0120956b4d3502e871eaa07."
    },
    {
      "id": "token:chainlink",
      "name": "Chainlink token",
      "kind": "asset",
      "proposedTier": 0,
      "assessment": "assessed",
      "scope": "Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.",
      "reason": "Fixed-supply nonproxy LINK transfer code has no privileged mint, pause, confiscation or implementation replacement. ERC677 callbacks are selected by the sending holder; Chainlink oracle and staking contracts are separate mechanisms.",
      "controls": [],
      "evidenceUrls": [
        "https://sourcify.dev/server/v2/contract/1/0x514910771af9ca656af840dff83e8264ecf986ca?fields=sources,compilation,runtimeBytecode,proxyResolution,deployment",
        "https://etherscan.io/address/0x514910771af9ca656af840dff83e8264ecf986ca#code"
      ],
      "reviewedAt": "2026-09-29",
      "aliases": [],
      "dependencies": [],
      "canonicalAddresses": {
        "1": "0x514910771af9ca656af840dff83e8264ecf986ca"
      },
      "reviewCadence": "permanent-D0",
      "nextReviewAt": null,
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ],
      "sourceProof": {
        "checkedAt": "2026-09-29",
        "chainId": 1,
        "address": "0x514910771af9ca656af840dff83e8264ecf986ca",
        "provider": "sourcify-v2",
        "runtimeSha256": "9792a60e149086e16264936114044e08b07981f87f64293339df5cd659e92a29",
        "sourcesSha256": "62a0f0aecf5fef68f5533975dfd08fc58ab10d0e9f005d00ece1801bdb53efd3",
        "contractName": "LinkToken",
        "proxyDetected": false,
        "onchainCodeMatchedAt": "2026-09-29"
      },
      "immutableIdentity": "Chain 1 0x514910771af9ca656af840dff83e8264ecf986ca; reviewed runtime SHA256 9792a60e149086e16264936114044e08b07981f87f64293339df5cd659e92a29."
    },
    {
      "id": "token:compound-governance-token",
      "name": "Compound token",
      "kind": "asset",
      "proposedTier": 0,
      "assessment": "assessed",
      "scope": "Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.",
      "reason": "Nonproxy COMP mints its fixed supply in the constructor. Transfers and governance delegation do not give a controller power to mint, seize, pause or replace token balances. Compound lending markets are separate.",
      "controls": [],
      "evidenceUrls": [
        "https://sourcify.dev/server/v2/contract/1/0xc00e94cb662c3520282e6f5717214004a7f26888?fields=sources,compilation,runtimeBytecode,proxyResolution,deployment",
        "https://etherscan.io/address/0xc00e94cb662c3520282e6f5717214004a7f26888#code"
      ],
      "reviewedAt": "2026-09-29",
      "aliases": [],
      "dependencies": [],
      "canonicalAddresses": {
        "1": "0xc00e94cb662c3520282e6f5717214004a7f26888"
      },
      "reviewCadence": "permanent-D0",
      "nextReviewAt": null,
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ],
      "sourceProof": {
        "checkedAt": "2026-09-29",
        "chainId": 1,
        "address": "0xc00e94cb662c3520282e6f5717214004a7f26888",
        "provider": "sourcify-v2",
        "runtimeSha256": "fa6dc25f20e09166adfad047d01c8eebb1a4762ee9adfb2c37e96631e21674af",
        "sourcesSha256": "9e4773d4eb790689804bb44336ea8675f29e4c666329e66e324f250247ab791e",
        "contractName": "Comp",
        "proxyDetected": false,
        "onchainCodeMatchedAt": "2026-09-29"
      },
      "immutableIdentity": "Chain 1 0xc00e94cb662c3520282e6f5717214004a7f26888; reviewed runtime SHA256 fa6dc25f20e09166adfad047d01c8eebb1a4762ee9adfb2c37e96631e21674af."
    },
    {
      "id": "token:cow-protocol",
      "name": "CoW Protocol token",
      "kind": "asset",
      "proposedTier": 1,
      "assessment": "assessed",
      "scope": "Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.",
      "reason": "COW has nonproxy transfer code and a fixed CoW DAO authority for minting, capped at 3% per year. The simulation delegatecall always reverts, including state changes; it is not an implementation upgrade path. Settlement solvers and orders are separate.",
      "controls": [
        "COW has nonproxy transfer code and a fixed CoW DAO authority for minting, capped at 3% per year"
      ],
      "evidenceUrls": [
        "https://sourcify.dev/server/v2/contract/1/0xdef1ca1fb7fbcdc777520aa7f396b4e015f497ab?fields=sources,compilation,runtimeBytecode,proxyResolution,deployment",
        "https://etherscan.io/address/0xdef1ca1fb7fbcdc777520aa7f396b4e015f497ab#code"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [],
      "canonicalAddresses": {
        "1": "0xdef1ca1fb7fbcdc777520aa7f396b4e015f497ab"
      },
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ],
      "sourceProof": {
        "checkedAt": "2026-10-01",
        "chainId": 1,
        "address": "0xdef1ca1fb7fbcdc777520aa7f396b4e015f497ab",
        "provider": "sourcify-v2",
        "runtimeSha256": "0f65fc1ac2495625030a21fab0c761bb57a9759a8c07134894587846c1557070",
        "sourcesSha256": "3e5573a46ec1e55954179edc2d6edc71ae6cdeb1eb481614734d7db4fb8d8f36",
        "contractName": "CowProtocolToken",
        "proxyDetected": false,
        "onchainCodeMatchedAt": "2026-10-01"
      }
    },
    {
      "id": "token:curve-dao-token",
      "name": "Curve DAO token",
      "kind": "asset",
      "proposedTier": 1,
      "assessment": "lower-bound",
      "scope": "Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.",
      "reason": "CRV source bounds emissions by its supply schedule and once-set minter. Admin can change token metadata/admin, not replace transfer code. Close the live minter and admin identity path before completing the holding review; Curve pools and gauges are separate.",
      "controls": [
        "CRV source bounds emissions by its supply schedule and once-set minter"
      ],
      "evidenceUrls": [
        "https://sourcify.dev/server/v2/contract/1/0xd533a949740bb3306d119cc777fa900ba034cd52?fields=sources,compilation,runtimeBytecode,proxyResolution,deployment",
        "https://etherscan.io/address/0xd533a949740bb3306d119cc777fa900ba034cd52#code"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [],
      "canonicalAddresses": {
        "1": "0xd533a949740bb3306d119cc777fa900ba034cd52"
      },
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ],
      "sourceProof": {
        "checkedAt": "2026-10-01",
        "chainId": 1,
        "address": "0xd533a949740bb3306d119cc777fa900ba034cd52",
        "provider": "sourcify-v2",
        "runtimeSha256": "ee63e02cb73d0899542d9f646d0d6e304716e54b6af556ac06474983c75323a0",
        "sourcesSha256": "6b010f5461111dae5a2d0cf7e51a00dcde4714ead470dee68f5436c69f2d6cb0",
        "contractName": "Vyper_contract",
        "proxyDetected": false,
        "onchainCodeMatchedAt": "2026-10-01",
        "authorityChecks": [
          {
            "method": "minter()",
            "value": "0x000000000000000000000000d061d61a4d941c39e5453435b6345dc261c2fce0",
            "block": "0x18e39b8"
          },
          {
            "method": "admin()",
            "value": "0x00000000000000000000000040907540d8a6c65c637785e8f8b742ae6b0b9968",
            "block": "0x18e39b8"
          }
        ]
      },
      "knownFloor": 1,
      "tierBound": true,
      "limits": [
        "Live role/controller/dependency closure remains incomplete; keep the established floor."
      ]
    },
    {
      "id": "token:eigenlayer",
      "name": "EigenCloud (prev. EigenLayer) token",
      "kind": "asset",
      "proposedTier": 3,
      "assessment": "lower-bound",
      "scope": "Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.",
      "reason": "EIGEN is a transparent proxy with a nonzero live admin. Current Eigen code wraps bEIGEN and contains issuance/transfer-restriction state. Complete proxy admin timing, restriction state and the bEIGEN backing/controller path before a complete holding grade.",
      "controls": [
        "EIGEN is a transparent proxy with a nonzero live admin"
      ],
      "evidenceUrls": [
        "https://sourcify.dev/server/v2/contract/1/0xec53bf9167f50cdeb3ae105f56099aaab9061f83?fields=sources,compilation,runtimeBytecode,proxyResolution,deployment",
        "https://etherscan.io/address/0xec53bf9167f50cdeb3ae105f56099aaab9061f83#code"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [],
      "canonicalAddresses": {
        "1": "0xec53bf9167f50cdeb3ae105f56099aaab9061f83"
      },
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ],
      "sourceProof": {
        "checkedAt": "2026-10-01",
        "chainId": 1,
        "address": "0xec53bf9167f50cdeb3ae105f56099aaab9061f83",
        "provider": "sourcify-v2",
        "runtimeSha256": "f8c11cd116ee7500f2dfdce440a872b725af06dbc0560aa539030fa7cf4ad07f",
        "sourcesSha256": "73f4d2d14f3eabab85f4477087d6f7a8e0177547eaee31b05e132880a62807c0",
        "contractName": "TransparentUpgradeableProxy",
        "proxyDetected": true,
        "implementation": {
          "address": "0x2C4A81e257381F87F5A5C4bd525116466D972E50",
          "name": "Eigen"
        },
        "onchainCodeMatchedAt": "2026-10-01",
        "authorityChecks": [
          {
            "method": "admin",
            "value": "0x0000000000000000000000008b9566ada63b64d1e1dcf1418b43fd1433b72444",
            "block": "0x18e39b8"
          }
        ]
      },
      "knownFloor": 3,
      "tierBound": true,
      "limits": [
        "Live role/controller/dependency closure remains incomplete; keep the established floor."
      ]
    },
    {
      "id": "token:ethena",
      "name": "Ethena token",
      "kind": "asset",
      "proposedTier": 1,
      "assessment": "assessed",
      "scope": "Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.",
      "reason": "ENA is a nonproxy token with owner issuance capped at 10% of supply per mint after a 365-day interval. The source provides no owner freeze or replacement of ordinary transfer balances. ENA is separate from issuer-controlled USDe backing/redemption.",
      "controls": [
        "ENA is a nonproxy token with owner issuance capped at 10% of supply per mint after a 365-day interval"
      ],
      "evidenceUrls": [
        "https://sourcify.dev/server/v2/contract/1/0x57e114b691db790c35207b2e685d4a43181e6061?fields=sources,compilation,runtimeBytecode,proxyResolution,deployment",
        "https://etherscan.io/address/0x57e114b691db790c35207b2e685d4a43181e6061#code"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [],
      "canonicalAddresses": {
        "1": "0x57e114b691db790c35207b2e685d4a43181e6061"
      },
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ],
      "sourceProof": {
        "checkedAt": "2026-10-01",
        "chainId": 1,
        "address": "0x57e114b691db790c35207b2e685d4a43181e6061",
        "provider": "sourcify-v2",
        "runtimeSha256": "91dddace2e56af97a1595498afca4b48b813e73cddbdf03000e1a1a8a07e5054",
        "sourcesSha256": "06364d5098c7ab186e3dc2139c2c4eda369ebf4d9653858c71e3ff64945a5102",
        "contractName": "ENA",
        "proxyDetected": false,
        "onchainCodeMatchedAt": "2026-10-01",
        "authorityChecks": [
          {
            "method": "owner()",
            "value": "0x000000000000000000000000e8dc0fab349ea169283c48ccfd09d797e6db7c94",
            "block": "0x18e39b8"
          }
        ]
      }
    },
    {
      "id": "token:ether-fi",
      "name": "Ether.fi token",
      "kind": "asset",
      "proposedTier": 0,
      "assessment": "assessed",
      "scope": "Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.",
      "reason": "Nonproxy ETHFI has constructor-only issuance. Burn and permit require the holder or their allowance/signature; vote delegation does not control transfers. No external administrator or upgrade entry point exists in the reachable token implementation. Ether.fi staking is separate.",
      "controls": [],
      "evidenceUrls": [
        "https://sourcify.dev/server/v2/contract/1/0xfe0c30065b384f05761f15d0cc899d4f9f9cc0eb?fields=sources,compilation,runtimeBytecode,proxyResolution,deployment",
        "https://etherscan.io/address/0xfe0c30065b384f05761f15d0cc899d4f9f9cc0eb#code"
      ],
      "reviewedAt": "2026-09-29",
      "aliases": [],
      "dependencies": [],
      "canonicalAddresses": {
        "1": "0xfe0c30065b384f05761f15d0cc899d4f9f9cc0eb"
      },
      "reviewCadence": "permanent-D0",
      "nextReviewAt": null,
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ],
      "sourceProof": {
        "checkedAt": "2026-09-29",
        "chainId": 1,
        "address": "0xfe0c30065b384f05761f15d0cc899d4f9f9cc0eb",
        "provider": "sourcify-v2",
        "runtimeSha256": "209588c7aeb5e0da0ee273dd1c274cceed09ae7471696b56d0da4f8df02910f6",
        "sourcesSha256": "2e27e325c366b8f6e16835eea51318c0662cf0cc1095d8da331d2fda1e0a3478",
        "contractName": "EtherFiGovernanceToken",
        "proxyDetected": false,
        "onchainCodeMatchedAt": "2026-09-29"
      },
      "immutableIdentity": "Chain 1 0xfe0c30065b384f05761f15d0cc899d4f9f9cc0eb; reviewed runtime SHA256 209588c7aeb5e0da0ee273dd1c274cceed09ae7471696b56d0da4f8df02910f6."
    },
    {
      "id": "token:ethereum-name-service",
      "name": "Ethereum Name Service token",
      "kind": "asset",
      "proposedTier": 1,
      "assessment": "assessed",
      "scope": "Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.",
      "reason": "ENS has fixed nonproxy transfer code and owner minting capped at 2% of supply per mint with a 365-day interval. Registrar, resolver and DAO execution powers are separate from the token holding.",
      "controls": [
        "ENS has fixed nonproxy transfer code and owner minting capped at 2% of supply per mint with a 365-day interval"
      ],
      "evidenceUrls": [
        "https://sourcify.dev/server/v2/contract/1/0xc18360217d8f7ab5e7c516566761ea12ce7f9d72?fields=sources,compilation,runtimeBytecode,proxyResolution,deployment",
        "https://etherscan.io/address/0xc18360217d8f7ab5e7c516566761ea12ce7f9d72#code"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [],
      "canonicalAddresses": {
        "1": "0xc18360217d8f7ab5e7c516566761ea12ce7f9d72"
      },
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ],
      "sourceProof": {
        "checkedAt": "2026-10-01",
        "chainId": 1,
        "address": "0xc18360217d8f7ab5e7c516566761ea12ce7f9d72",
        "provider": "sourcify-v2",
        "runtimeSha256": "f9d7b2afea6ec6542b7015bedc286e0f483b1622619cd67dff3e2de6776d0f61",
        "sourcesSha256": "96f1b612c5dfb0845b7acbfb7fef30199d62183964d6426e38193965b2365ce8",
        "contractName": "ENSToken",
        "proxyDetected": false,
        "onchainCodeMatchedAt": "2026-10-01",
        "authorityChecks": [
          {
            "method": "owner()",
            "value": "0x000000000000000000000000fe89cc7abb2c4183683ab71653c4cdc9b02d44b7",
            "block": "0x18e39b8"
          }
        ]
      }
    },
    {
      "id": "token:golem",
      "name": "Golem token",
      "kind": "asset",
      "proposedTier": 0,
      "assessment": "lower-bound",
      "scope": "Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.",
      "reason": "GLM inherits a minter role that can add minters and issue tokens. Constructor grants the migration agent that role and renounces the deployer role. Active minter membership and migration-agent authority are unresolved: neither permanent D0 nor an active inflation controller is established by this source review.",
      "controls": [
        "GLM inherits a minter role that can add minters and issue tokens"
      ],
      "evidenceUrls": [
        "https://sourcify.dev/server/v2/contract/1/0x7dd9c5cba05e151c895fde1cf355c9a1d5da6429?fields=sources,compilation,runtimeBytecode,proxyResolution,deployment",
        "https://etherscan.io/address/0x7dd9c5cba05e151c895fde1cf355c9a1d5da6429#code"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [],
      "canonicalAddresses": {
        "1": "0x7dd9c5cba05e151c895fde1cf355c9a1d5da6429"
      },
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ],
      "sourceProof": {
        "checkedAt": "2026-10-01",
        "chainId": 1,
        "address": "0x7dd9c5cba05e151c895fde1cf355c9a1d5da6429",
        "provider": "sourcify-v2",
        "runtimeSha256": "39ab539a9b9f92d6884b3c504b5267b4aac33235965cca2a6b38e216ff463544",
        "sourcesSha256": "b6ecb908706268d9dca2cd61408588cc2daed2c5718eabcc60dfbd1477e81d89",
        "contractName": "NewGolemNetworkToken",
        "proxyDetected": false,
        "onchainCodeMatchedAt": "2026-10-01"
      },
      "knownFloor": 0,
      "tierBound": true,
      "limits": [
        "Live role/controller/dependency closure remains incomplete; keep the established floor."
      ]
    },
    {
      "id": "token:havven",
      "name": "Synthetix token",
      "kind": "asset",
      "proposedTier": 3,
      "assessment": "lower-bound",
      "scope": "Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.",
      "reason": "SNX uses legacy ProxyERC20 owner-controlled target replacement and optional delegatecall. Live owner and target are nonzero even though the source provider reports no detected proxy. Close target, TokenState and governance timing before a complete holding grade.",
      "controls": [
        "SNX uses legacy ProxyERC20 owner-controlled target replacement and optional delegatecall"
      ],
      "evidenceUrls": [
        "https://sourcify.dev/server/v2/contract/1/0xc011a73ee8576fb46f5e1c5751ca3b9fe0af2a6f?fields=sources,compilation,runtimeBytecode,proxyResolution,deployment",
        "https://etherscan.io/address/0xc011a73ee8576fb46f5e1c5751ca3b9fe0af2a6f#code"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [],
      "canonicalAddresses": {
        "1": "0xc011a73ee8576fb46f5e1c5751ca3b9fe0af2a6f"
      },
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ],
      "sourceProof": {
        "checkedAt": "2026-10-01",
        "chainId": 1,
        "address": "0xc011a73ee8576fb46f5e1c5751ca3b9fe0af2a6f",
        "provider": "sourcify-v2",
        "runtimeSha256": "f1087f0e7102ca35d50742dbe25877c43d2b250662f7196ec435133ea0ce20ea",
        "sourcesSha256": "64c551e0e597d65e8bbb3417544bffcee735442975f5a1ed25ce15c6916fb34a",
        "contractName": "ProxyERC20",
        "proxyDetected": true,
        "onchainCodeMatchedAt": "2026-10-01",
        "authorityChecks": [
          {
            "method": "owner()",
            "value": "0x000000000000000000000000eb3107117fead7de89cd14d463d340a2e6917769",
            "block": "0x18e39b8"
          },
          {
            "method": "target()",
            "value": "0x000000000000000000000000c5f0b4194455e0c175ab68c501400e46c7203504",
            "block": "0x18e39b8"
          }
        ]
      },
      "knownFloor": 3,
      "tierBound": true,
      "limits": [
        "Live role/controller/dependency closure remains incomplete; keep the established floor."
      ]
    },
    {
      "id": "token:lido-dao",
      "name": "Lido DAO token",
      "kind": "asset",
      "proposedTier": 3,
      "assessment": "lower-bound",
      "scope": "Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.",
      "reason": "LDO MiniMe token delegates transfer/mint/burn/enableTransfers controls to a controller. The live controller is the Lido Aragon TokenManager, whose implementation can change through governance. Close governance delay/veto/emergency paths; LDO is separate from stETH and staking custody.",
      "controls": [
        "LDO MiniMe token delegates transfer/mint/burn/enableTransfers controls to a controller"
      ],
      "evidenceUrls": [
        "https://sourcify.dev/server/v2/contract/1/0x5a98fcbea516cf06857215779fd812ca3bef1b32?fields=sources,compilation,runtimeBytecode,proxyResolution,deployment",
        "https://etherscan.io/address/0x5a98fcbea516cf06857215779fd812ca3bef1b32#code",
        "https://docs.lido.fi/guides/lido-tokens-integration-guide/"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [],
      "canonicalAddresses": {
        "1": "0x5a98fcbea516cf06857215779fd812ca3bef1b32"
      },
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ],
      "sourceProof": {
        "checkedAt": "2026-10-01",
        "chainId": 1,
        "address": "0x5a98fcbea516cf06857215779fd812ca3bef1b32",
        "provider": "sourcify-v2",
        "runtimeSha256": "c34bcd329af3f7e1290f440e02fc0113792419ad6d5dfb84b685868cb9ac503f",
        "sourcesSha256": "36f666022dbb1a6fae33bd8f93889d5548ad197a1e9b0eac2de6c5fc04672305",
        "contractName": "MiniMeToken",
        "proxyDetected": false,
        "onchainCodeMatchedAt": "2026-10-01",
        "stateChecks": [
          {
            "method": "controller()",
            "value": "0x000000000000000000000000f73a1260d222f447210581ddf212d915c09a3249"
          }
        ]
      },
      "knownFloor": 3,
      "tierBound": true,
      "limits": [
        "Live role/controller/dependency closure remains incomplete; keep the established floor."
      ]
    },
    {
      "id": "token:loopring",
      "name": "Loopring token",
      "kind": "asset",
      "proposedTier": 0,
      "assessment": "assessed",
      "scope": "Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.",
      "reason": "Nonproxy LRC_v2 has fixed constructor supply. Batch transfers spend the caller balance and burns spend the holder balance or allowance. No privileged mint, pause or upgrade path exists. Loopring exchange and L2 custody are separate.",
      "controls": [],
      "evidenceUrls": [
        "https://sourcify.dev/server/v2/contract/1/0xbbbbca6a901c926f240b89eacb641d8aec7aeafd?fields=sources,compilation,runtimeBytecode,proxyResolution,deployment",
        "https://etherscan.io/address/0xbbbbca6a901c926f240b89eacb641d8aec7aeafd#code"
      ],
      "reviewedAt": "2026-09-29",
      "aliases": [],
      "dependencies": [],
      "canonicalAddresses": {
        "1": "0xbbbbca6a901c926f240b89eacb641d8aec7aeafd"
      },
      "reviewCadence": "permanent-D0",
      "nextReviewAt": null,
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ],
      "sourceProof": {
        "checkedAt": "2026-09-29",
        "chainId": 1,
        "address": "0xbbbbca6a901c926f240b89eacb641d8aec7aeafd",
        "provider": "sourcify-v2",
        "runtimeSha256": "a6aee166dcb4af2a586c7bc0e4d37f603dab5683f8a72470314e6aad50a05ac2",
        "sourcesSha256": "21ca753a667403ee99a7f32bf7cb2f1b64749e4915964649e7d31d09e543d306",
        "contractName": "LRC_v2",
        "proxyDetected": false,
        "onchainCodeMatchedAt": "2026-09-29"
      },
      "immutableIdentity": "Chain 1 0xbbbbca6a901c926f240b89eacb641d8aec7aeafd; reviewed runtime SHA256 a6aee166dcb4af2a586c7bc0e4d37f603dab5683f8a72470314e6aad50a05ac2."
    },
    {
      "id": "token:morpho",
      "name": "Morpho token",
      "kind": "asset",
      "proposedTier": 3,
      "assessment": "lower-bound",
      "scope": "Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.",
      "reason": "MORPHO is an ERC1967/UUPS token. Current MorphoTokenEthereum code permits owner minting and owner-authorized upgrades; live owner() is nonzero. Controller execution and timing remain unresolved. The immutable Morpho Blue lending core does not make MORPHO token D0.",
      "controls": [
        "MORPHO is an ERC1967/UUPS token"
      ],
      "evidenceUrls": [
        "https://sourcify.dev/server/v2/contract/1/0x58d97b57bb95320f9a05dc918aef65434969c2b2?fields=sources,compilation,runtimeBytecode,proxyResolution,deployment",
        "https://etherscan.io/address/0x58d97b57bb95320f9a05dc918aef65434969c2b2#code"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [],
      "canonicalAddresses": {
        "1": "0x58d97b57bb95320f9a05dc918aef65434969c2b2"
      },
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ],
      "sourceProof": {
        "checkedAt": "2026-10-01",
        "chainId": 1,
        "address": "0x58d97b57bb95320f9a05dc918aef65434969c2b2",
        "provider": "sourcify-v2",
        "runtimeSha256": "31c77a09bfc4a3046629fb0148e5fa98409591c4f512b0493bf2fb0a9adf1e19",
        "sourcesSha256": "53add47cf1f5ae45af2af269c578c178808ffc82b2f61c1d61c16b8d4e437982",
        "contractName": "ERC1967Proxy",
        "proxyDetected": true,
        "implementation": {
          "address": "0x4364fd2371b6318159366abFA51f190df5C24852",
          "name": "MorphoTokenEthereum"
        },
        "onchainCodeMatchedAt": "2026-10-01",
        "authorityChecks": [
          {
            "method": "owner()",
            "value": "0x000000000000000000000000cba28b38103307ec8da98377fff9816c164f9afa",
            "block": "0x18e39b8"
          }
        ]
      },
      "knownFloor": 3,
      "tierBound": true,
      "limits": [
        "Live role/controller/dependency closure remains incomplete; keep the established floor."
      ]
    },
    {
      "id": "token:optimism",
      "name": "Optimism token",
      "kind": "asset",
      "proposedTier": 1,
      "assessment": "lower-bound",
      "scope": "Ordinary holding of the recorded token deployment on chain 10; excludes protocol positions and unreviewed representations.",
      "reason": "Native OP on chain 10 has owner-only minting. This is not an Ethereum-mainnet ERC20. Close the owner/issuance path and compose Optimism chain authority; an unknown bridged OP deployment cannot inherit this address review.",
      "controls": [
        "Native OP on chain 10 has owner-only minting"
      ],
      "evidenceUrls": [
        "https://sourcify.dev/server/v2/contract/10/0x4200000000000000000000000000000000000042?fields=sources,compilation,runtimeBytecode,proxyResolution,deployment",
        "https://optimistic.etherscan.io/address/0x4200000000000000000000000000000000000042#code"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [
        "optimism"
      ],
      "canonicalAddresses": {
        "10": "0x4200000000000000000000000000000000000042"
      },
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ],
      "sourceProof": {
        "checkedAt": "2026-10-01",
        "chainId": 10,
        "address": "0x4200000000000000000000000000000000000042",
        "provider": "sourcify-v2",
        "runtimeSha256": "b2718c87baa3cbba999fa606bc960463aafcfe05770e377fd1c72ee142d33dcc",
        "sourcesSha256": "7371c008ed52c452ae5fbabed2f0e208162d8bca06cd7fec11bfe67a7f7696dd",
        "contractName": "GovernanceToken",
        "proxyDetected": false,
        "onchainCodeMatchedAt": "2026-10-01",
        "authorityChecks": [
          {
            "method": "owner()",
            "value": "0x0000000000000000000000005c4e7ba1e219e47948e6e3f55019a647ba501005",
            "block": "0x9654b20"
          }
        ]
      },
      "knownFloor": 1,
      "tierBound": true,
      "limits": [
        "Live role/controller/dependency closure remains incomplete; keep the established floor."
      ]
    },
    {
      "id": "token:pendle",
      "name": "Pendle token",
      "kind": "asset",
      "proposedTier": 1,
      "assessment": "lower-bound",
      "scope": "Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.",
      "reason": "PENDLE governance can alter emissions, inflation, destination and voluntary burn configuration after a hardcoded seven-day config delay. The live governance path remains unresolved. These issuance/configuration powers are separate from Pendle markets and yield-bearing positions.",
      "controls": [
        "PENDLE governance can alter emissions, inflation, destination and voluntary burn configuration after a hardcoded seven-day config delay"
      ],
      "evidenceUrls": [
        "https://sourcify.dev/server/v2/contract/1/0x808507121b80c02388fad14726482e061b8da827?fields=sources,compilation,runtimeBytecode,proxyResolution,deployment",
        "https://etherscan.io/address/0x808507121b80c02388fad14726482e061b8da827#code"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [],
      "canonicalAddresses": {
        "1": "0x808507121b80c02388fad14726482e061b8da827"
      },
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ],
      "sourceProof": {
        "checkedAt": "2026-10-01",
        "chainId": 1,
        "address": "0x808507121b80c02388fad14726482e061b8da827",
        "provider": "sourcify-v2",
        "runtimeSha256": "d2a234646d555c25823246bc4ce5d89bced2327702dfd4e206974c04ea32d32f",
        "sourcesSha256": "2e867e0889c7414cf2093cddbafc4206ebd612925fb8bdf6dd0ae03a4da2d3c6",
        "contractName": "PENDLE",
        "proxyDetected": false,
        "onchainCodeMatchedAt": "2026-10-01",
        "authorityChecks": [
          {
            "method": "governance()",
            "value": "0x0000000000000000000000008119ec16f0573b7dac7c0cb94eb504fb32456ee1",
            "block": "0x18e39bb"
          }
        ]
      },
      "knownFloor": 1,
      "tierBound": true,
      "limits": [
        "Live role/controller/dependency closure remains incomplete; keep the established floor."
      ]
    },
    {
      "id": "token:rocket-pool",
      "name": "Rocket Pool token",
      "kind": "asset",
      "proposedTier": 1,
      "assessment": "lower-bound",
      "scope": "Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.",
      "reason": "RPL token inflation consults RocketStorage and protocol settings; constructor-fixed token code alone does not close that dependency. Review live inflation settings, RocketStorage authority and the reachable replacement paths. RETH backing and node staking are separate.",
      "controls": [
        "RPL token inflation consults RocketStorage and protocol settings; constructor-fixed token code alone does not close that dependency"
      ],
      "evidenceUrls": [
        "https://sourcify.dev/server/v2/contract/1/0xd33526068d116ce69f19a9ee46f0bd304f21a51f?fields=sources,compilation,runtimeBytecode,proxyResolution,deployment",
        "https://etherscan.io/address/0xd33526068d116ce69f19a9ee46f0bd304f21a51f#code"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [],
      "canonicalAddresses": {
        "1": "0xd33526068d116ce69f19a9ee46f0bd304f21a51f"
      },
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ],
      "sourceProof": {
        "checkedAt": "2026-10-01",
        "chainId": 1,
        "address": "0xd33526068d116ce69f19a9ee46f0bd304f21a51f",
        "provider": "sourcify-v2",
        "runtimeSha256": "e871b0482bf45d88788fc20d4ee5915130ebe132b828f9908b25b0a4d9627c5e",
        "sourcesSha256": "846cf6796cbc9ea964db603a4299d35221e6dfe8d0eb27867ca7fd3c6a6b806c",
        "contractName": "RocketTokenRPL",
        "proxyDetected": false,
        "onchainCodeMatchedAt": "2026-10-01"
      },
      "knownFloor": 1,
      "tierBound": true,
      "limits": [
        "Live role/controller/dependency closure remains incomplete; keep the established floor."
      ]
    },
    {
      "id": "token:safe",
      "name": "Safe token",
      "kind": "asset",
      "proposedTier": 0,
      "assessment": "assessed",
      "scope": "Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.",
      "reason": "Nonproxy SAFE has fixed constructor supply and can only unpause once. The live paused() check returned false; no function can pause again. Owner rescue operates on assets accidentally sent to the token contract, and SAFE transfers to that contract are prohibited. Safe wallets and governance are separate.",
      "controls": [],
      "evidenceUrls": [
        "https://sourcify.dev/server/v2/contract/1/0x5afe3855358e112b5647b952709e6165e1c1eeee?fields=sources,compilation,runtimeBytecode,proxyResolution,deployment",
        "https://etherscan.io/address/0x5afe3855358e112b5647b952709e6165e1c1eeee#code",
        "https://forum.safefoundation.org/t/discussion-unpause-safe-token-contract-enabling-transferability/4874"
      ],
      "reviewedAt": "2026-09-29",
      "aliases": [],
      "dependencies": [],
      "canonicalAddresses": {
        "1": "0x5afe3855358e112b5647b952709e6165e1c1eeee"
      },
      "reviewCadence": "permanent-D0",
      "nextReviewAt": null,
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ],
      "sourceProof": {
        "checkedAt": "2026-09-29",
        "chainId": 1,
        "address": "0x5afe3855358e112b5647b952709e6165e1c1eeee",
        "provider": "sourcify-v2",
        "runtimeSha256": "e723310bc4706784d4c4ea0dbefe67b3153a00a660d93d0efb9876a7cba505fb",
        "sourcesSha256": "efc0c5b799e9676ab1d7bdb5c75f4c6ff14a14d7f2bcd115a6fe75d6e2076b63",
        "contractName": "SafeToken",
        "proxyDetected": false,
        "onchainCodeMatchedAt": "2026-09-29",
        "stateChecks": [
          {
            "method": "paused()",
            "value": "0x0000000000000000000000000000000000000000000000000000000000000000"
          }
        ]
      },
      "immutableIdentity": "Chain 1 0x5afe3855358e112b5647b952709e6165e1c1eeee; reviewed runtime SHA256 e723310bc4706784d4c4ea0dbefe67b3153a00a660d93d0efb9876a7cba505fb."
    },
    {
      "id": "token:sushi",
      "name": "Sushi token",
      "kind": "asset",
      "proposedTier": 1,
      "assessment": "lower-bound",
      "scope": "Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.",
      "reason": "SUSHI token has an owner-only mint path without a token-level supply cap. The live owner and its reachable controller powers remain a monthly closure task. Sushi pools and farms have separate identities.",
      "controls": [
        "SUSHI token has an owner-only mint path without a token-level supply cap"
      ],
      "evidenceUrls": [
        "https://sourcify.dev/server/v2/contract/1/0x6b3595068778dd592e39a122f4f5a5cf09c90fe2?fields=sources,compilation,runtimeBytecode,proxyResolution,deployment",
        "https://etherscan.io/address/0x6b3595068778dd592e39a122f4f5a5cf09c90fe2#code"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [],
      "canonicalAddresses": {
        "1": "0x6b3595068778dd592e39a122f4f5a5cf09c90fe2"
      },
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ],
      "sourceProof": {
        "checkedAt": "2026-10-01",
        "chainId": 1,
        "address": "0x6b3595068778dd592e39a122f4f5a5cf09c90fe2",
        "provider": "sourcify-v2",
        "runtimeSha256": "1dd270c4319f93d16cc4e552193cde74b19c7a016050c90a9dce46f6dc8d7877",
        "sourcesSha256": "e48518fc077d52e97c69233ebda36abba400374e6f671a6c00321b2f5f17b343",
        "contractName": "SushiToken",
        "proxyDetected": false,
        "onchainCodeMatchedAt": "2026-10-01",
        "authorityChecks": [
          {
            "method": "owner()",
            "value": "0x000000000000000000000000c2edad668740f1aa35e4d8f227fb8e17dca888cd",
            "block": "0x18e39bb"
          }
        ]
      },
      "knownFloor": 1,
      "tierBound": true,
      "limits": [
        "Live role/controller/dependency closure remains incomplete; keep the established floor."
      ]
    },
    {
      "id": "token:the-graph",
      "name": "The Graph token",
      "kind": "asset",
      "proposedTier": 1,
      "assessment": "lower-bound",
      "scope": "Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.",
      "reason": "GRT exposes governor-controlled minter membership and minting in nonproxy token code. The governor/minter authority path still needs live closure. Graph staking, indexing and curation are separate mechanisms.",
      "controls": [
        "GRT exposes governor-controlled minter membership and minting in nonproxy token code"
      ],
      "evidenceUrls": [
        "https://sourcify.dev/server/v2/contract/1/0xc944e90c64b2c07662a292be6244bdf05cda44a7?fields=sources,compilation,runtimeBytecode,proxyResolution,deployment",
        "https://etherscan.io/address/0xc944e90c64b2c07662a292be6244bdf05cda44a7#code"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [],
      "canonicalAddresses": {
        "1": "0xc944e90c64b2c07662a292be6244bdf05cda44a7"
      },
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ],
      "sourceProof": {
        "checkedAt": "2026-10-01",
        "chainId": 1,
        "address": "0xc944e90c64b2c07662a292be6244bdf05cda44a7",
        "provider": "sourcify-v2",
        "runtimeSha256": "9ad202677a3f359e01ed7330e8e2764c4a0b523a085a20c7d16147e15da9ad9f",
        "sourcesSha256": "75a31d659709dd943cc13206d1c8c9fa5a14a9300f6aa9525d06c862a009f5f8",
        "contractName": "GraphToken",
        "proxyDetected": false,
        "onchainCodeMatchedAt": "2026-10-01",
        "authorityChecks": [
          {
            "method": "governor()",
            "value": "0x00000000000000000000000048301fe520f72994d32ead72e2b6a8447873cf50",
            "block": "0x18e39bb"
          }
        ]
      },
      "knownFloor": 1,
      "tierBound": true,
      "limits": [
        "Live role/controller/dependency closure remains incomplete; keep the established floor."
      ]
    },
    {
      "id": "token:uniswap",
      "name": "Uniswap token",
      "kind": "asset",
      "proposedTier": 1,
      "assessment": "assessed",
      "scope": "Ordinary holding of the recorded token deployment on chain 1; excludes protocol positions and unreviewed representations.",
      "reason": "UNI has fixed nonproxy transfer code but a changeable minter can issue at most 2% of supply per mint, with at least 365 days between mints. These issuance settings prevent permanent D0 for UNI; Uniswap v1-v4 cores are separate identities.",
      "controls": [
        "UNI has fixed nonproxy transfer code but a changeable minter can issue at most 2% of supply per mint, with at least 365 days between mints"
      ],
      "evidenceUrls": [
        "https://sourcify.dev/server/v2/contract/1/0x1f9840a85d5af5bf1d1762f925bdaddc4201f984?fields=sources,compilation,runtimeBytecode,proxyResolution,deployment",
        "https://etherscan.io/address/0x1f9840a85d5af5bf1d1762f925bdaddc4201f984#code"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [],
      "canonicalAddresses": {
        "1": "0x1f9840a85d5af5bf1d1762f925bdaddc4201f984"
      },
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ],
      "sourceProof": {
        "checkedAt": "2026-10-01",
        "chainId": 1,
        "address": "0x1f9840a85d5af5bf1d1762f925bdaddc4201f984",
        "provider": "sourcify-v2",
        "runtimeSha256": "77ea2b530607db6cb87c7cce18016aa12dd0762c4357355bceee2cb11721bebe",
        "sourcesSha256": "0f4ff2503549b975995c3fde7c5d2a856dade1311c568af8b516e7c7d66256c9",
        "contractName": "Uni",
        "proxyDetected": false,
        "onchainCodeMatchedAt": "2026-10-01",
        "authorityChecks": [
          {
            "method": "minter()",
            "value": "0x0000000000000000000000001a9c8182c09f50c8318d769245bea52c32be35bc",
            "block": "0x18e39bb"
          }
        ]
      }
    },
    {
      "id": "tusd",
      "name": "TUSD token",
      "kind": "asset",
      "proposedTier": 9,
      "assessment": "assessed",
      "scope": "Ethereum-mainnet issuer-backed token, including material offchain reserve custody and redemption.",
      "reason": "Issuer controls reserve custody and redemption and can restrict/freeze accounts. The legacy OwnedUpgradeabilityProxy is replaceable even when automated proxy detection is negative.",
      "controls": [
        "Issuer controls reserve custody and redemption and can restrict/freeze accounts"
      ],
      "evidenceUrls": [
        "https://sourcify.dev/server/v2/contract/1/0x0000000000085d4780b73119b644ae5ecd22b376?fields=sources,compilation,runtimeBytecode,proxyResolution,deployment",
        "https://etherscan.io/address/0x0000000000085d4780b73119b644ae5ecd22b376#code",
        "https://app.tusd.io/terms-of-use"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "stable:7"
      ],
      "dependencies": [],
      "canonicalAddresses": {
        "1": "0x0000000000085d4780b73119b644ae5ecd22b376"
      },
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ],
      "sourceProof": {
        "checkedAt": "2026-10-01",
        "chainId": 1,
        "address": "0x0000000000085d4780b73119b644ae5ecd22b376",
        "provider": "sourcify-v2",
        "runtimeSha256": "638a54ec38735b55152fdb49fc33ecf679652f4a0ab9748ce369217e718d66ae",
        "sourcesSha256": "8bc4ddf05827f8b0e1d50ea40328e9c75ad0d72643abee02887ddf2d16aaaa0e",
        "contractName": "OwnedUpgradeabilityProxy",
        "proxyDetected": true,
        "onchainCodeMatchedAt": "2026-10-01"
      }
    },
    {
      "id": "unichain",
      "name": "Unichain",
      "kind": "chain",
      "proposedTier": 5,
      "scope": "Unichain mainnet, chain ID 130; both documented owner arrangements retain the same D5 authority category.",
      "reason": "Council and Foundation approval are required for upgrades. The documented three-party owner also includes Unichain; a proposed two-party transition does not remove the Foundation/council trust.",
      "controls": [
        "Permissionless fault proofs and self-proposal; Ethereum data availability.",
        "Current documented 3/3 owner: Unichain, Foundation and Council. September proposal removes Unichain from that owner set; execution is not independently confirmed here.",
        "Optimism governance/council model with Foundation safeguards and fallback roles.",
        "L1 forced inclusion; immediate upgrades have no enforced exit window."
      ],
      "evidenceUrls": [
        "https://l2beat.com/layer2s/projects/unichain",
        "https://gov.optimism.io/t/maintenance-upgrade-proposal-unichain-proxyadmin-owner-transition-to-standard-optimism-governance/10839"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [
        "ethereum"
      ],
      "assessment": "assessed",
      "tierBound": false,
      "dimensions": {
        "Validation": "Permissionless fault proofs and self-proposal; Ethereum data availability.",
        "Upgrades": "Current documented 3/3 owner: Unichain, Foundation and Council. September proposal removes Unichain from that owner set; execution is not independently confirmed here.",
        "Accountability": "Optimism governance/council model with Foundation safeguards and fallback roles.",
        "Exits": "L1 forced inclusion; immediate upgrades have no enforced exit window."
      },
      "uncertainty": "A proposal is not treated as an executed upgrade. The classification is unchanged under either documented owner arrangement.",
      "reviewBasis": "Editorial mapping from linked first-party governance records and L2BEAT contract-discovery research to this map’s D0–D9 rubric; not a conversion of L2BEAT stages.",
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "uniswap",
      "name": "Uniswap, unspecified version",
      "kind": "protocol",
      "proposedTier": null,
      "scope": "Ethereum mainnet deployment; asset-level dependencies assessed separately.",
      "reason": "A version and pool scope are required; a brand-wide tier would conceal hook and wrapper differences.",
      "controls": [],
      "evidenceUrls": [
        "https://developers.uniswap.org/docs/get-started/concepts/glossary"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "uniswap"
      ],
      "dependencies": [],
      "knownFloor": 0,
      "assessment": "unreviewed",
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "uniswap-v1",
      "name": "Uniswap V1",
      "kind": "protocol",
      "proposedTier": 0,
      "tierBound": false,
      "scope": "Ethereum L1 protocol mechanism; assets and integrations are separate dependencies.",
      "reason": "Canonical v1 exchanges have fixed exchange and withdrawal code, with no protocol administrator able to replace the core. Token controls remain separate.",
      "controls": [
        "Canonical v1 exchanges have fixed exchange and withdrawal code, with no protocol administrator able to replace the core. Token controls remain separate."
      ],
      "evidenceUrls": [
        "https://github.com/Uniswap/v1-contracts/blob/master/contracts/uniswap_exchange.vy",
        "https://github.com/Uniswap/v1-contracts/blob/master/contracts/uniswap_factory.vy"
      ],
      "reviewedAt": "2026-09-29",
      "aliases": [],
      "dependencies": [],
      "assessment": "assessed",
      "immutableIdentity": "Ethereum canonical v1 factory/exchange deployment family; no forks or wrappers.",
      "reviewCadence": "permanent-D0",
      "nextReviewAt": null,
      "canonicalAddresses": {
        "1": "0xc0a47dfe034b400b47bdad5fecda2621de6c4d95"
      }
    },
    {
      "id": "uniswap-v2",
      "name": "Uniswap v2",
      "kind": "protocol",
      "proposedTier": 0,
      "scope": "Authentic v2 core pairs; excludes token issuers, routers with custody, hosted interfaces, and external staking wrappers.",
      "reason": "Core pool custody and LP exits are immutable; token controls are assessed separately.",
      "controls": [
        "Governance can configure the protocol fee; it cannot upgrade a deployed core pair or veto its ordinary LP exit."
      ],
      "evidenceUrls": [
        "https://developers.uniswap.org/docs/get-started/concepts/how-uniswap-works",
        "https://developers.uniswap.org/docs/get-started/concepts/fees",
        "https://github.com/Uniswap/v2-core/blob/master/contracts/UniswapV2Pair.sol",
        "https://developers.uniswap.org/docs/protocols/v2/deployments"
      ],
      "reviewedAt": "2026-09-29",
      "aliases": [
        "uniswap-v2"
      ],
      "dependencies": [],
      "assessment": "assessed",
      "immutableIdentity": "Ethereum canonical v2 factory and its immutable pool code; bounded protocol fees cannot replace principal or exit logic.",
      "reviewCadence": "permanent-D0",
      "nextReviewAt": null,
      "canonicalAddresses": {
        "1": "0x5c69bee701ef814a2b6a3edd4b1652cb9cc5aa6f"
      },
      "sourceProof": {
        "checkedAt": "2026-09-29",
        "chainId": 1,
        "address": "0x5c69bee701ef814a2b6a3edd4b1652cb9cc5aa6f",
        "provider": "sourcify-v2",
        "runtimeSha256": "3abc53f12a9cb8ae37ebfada9efc261c1ab4c2759d161e341a49bf67df3f8321",
        "sourcesSha256": "5a89a050c9b1c2cb7f0eb4836e87b108102ba56966dd05f0986f91acc92da2bf",
        "contractName": "UniswapV2Factory",
        "proxyDetected": false,
        "onchainCodeMatchedAt": "2026-09-29"
      }
    },
    {
      "id": "uniswap-v3",
      "name": "Uniswap v3",
      "kind": "protocol",
      "proposedTier": 0,
      "scope": "Authentic v3 core pools; excludes frontends, managed positions, and asset-issuer dependencies.",
      "reason": "Core pool custody and LP exits are immutable; token controls are assessed separately.",
      "controls": [
        "Governance has bounded protocol-fee powers; deployed pool code and principal exit logic are not upgradeable."
      ],
      "evidenceUrls": [
        "https://developers.uniswap.org/docs/protocols/v3/concepts/architecture",
        "https://app.uniswap.org/whitepaper-v3.pdf",
        "https://github.com/Uniswap/v3-core/blob/main/contracts/UniswapV3Pool.sol",
        "https://developers.uniswap.org/docs/protocols/v3/deployments"
      ],
      "reviewedAt": "2026-09-29",
      "aliases": [
        "uniswap-v3"
      ],
      "dependencies": [],
      "assessment": "assessed",
      "immutableIdentity": "Ethereum canonical v3 factory and its immutable pool code; bounded protocol fees cannot replace principal or exit logic.",
      "reviewCadence": "permanent-D0",
      "nextReviewAt": null,
      "canonicalAddresses": {
        "1": "0x1f98431c8ad98523631ae4a59f267346ea31f984"
      },
      "sourceProof": {
        "checkedAt": "2026-09-29",
        "chainId": 1,
        "address": "0x1f98431c8ad98523631ae4a59f267346ea31f984",
        "provider": "sourcify-v2",
        "runtimeSha256": "fd5e0ec0633afeb92b2f6b6cac36e13a9732bd1914f8158a78f127d51d54a572",
        "sourcesSha256": "89c483b012934ed73d5e095787733b5749cb0e412afc6c486504a7bee3487304",
        "contractName": "UniswapV3Factory",
        "proxyDetected": false,
        "onchainCodeMatchedAt": "2026-09-29"
      }
    },
    {
      "id": "uniswap-v4",
      "name": "Uniswap v4",
      "kind": "protocol",
      "proposedTier": 0,
      "scope": "Canonical immutable PoolManager core. Pool hooks and token controls are assessed separately for each position.",
      "reason": "The Uniswap v4 PoolManager core is D0: its custody and settlement code cannot be upgraded. Protocol fees do not permit replacement of principal or withdrawal logic. Optional hooks can change a pool’s behavior; the aggregate holdings feed does not identify them, so those positions retain incomplete dependency reviews.",
      "controls": [
        "Hooks may affect swaps and liquidity operations; permissions are chosen per pool."
      ],
      "evidenceUrls": [
        "https://developers.uniswap.org/docs/protocols/v4/deployments",
        "https://developers.uniswap.org/docs/protocols/v4/concepts/hooks",
        "https://github.com/Uniswap/v4-core/blob/main/src/PoolManager.sol",
        "https://github.com/Uniswap/v4-core/blob/main/src/ProtocolFees.sol",
        "https://developers.uniswap.org/deployments.json"
      ],
      "reviewedAt": "2026-09-29",
      "aliases": [
        "uniswap-v4"
      ],
      "dependencies": [],
      "ownComponentTier": 0,
      "knownFloor": 0,
      "limits": [
        "No blanket D0 for all v4 hooks or custom accounting."
      ],
      "assessment": "assessed",
      "tierBound": false,
      "immutableIdentity": "Ethereum 1 PoolManager 0x000000000004444c5dc75cB358380D2e3dE08A90",
      "positionDependenciesUnreviewed": true,
      "reviewCadence": "permanent-D0",
      "nextReviewAt": null,
      "positionReview": {
        "cadence": "monthly",
        "reviewedAt": "2026-10-01",
        "nextReviewAt": "2026-11-01",
        "status": "unresolved",
        "reason": "The aggregate financial feed lacks per-position hook/oracle identity."
      },
      "canonicalAddresses": {
        "1": "0x000000000004444c5dc75cb358380d2e3de08a90"
      },
      "sourceProof": {
        "checkedAt": "2026-09-29",
        "chainId": 1,
        "address": "0x000000000004444c5dc75cb358380d2e3de08a90",
        "provider": "sourcify-v2",
        "runtimeSha256": "3316c7b1c67095ef6fc9b7e62fc754ad1e46e1c9119564ea4f5615a252af893e",
        "sourcesSha256": "61dc745f9f56188a3268d9924f540589fd755a8c800107da545bf031b459deb6",
        "contractName": "PoolManager",
        "proxyDetected": false,
        "onchainCodeMatchedAt": "2026-09-29"
      }
    },
    {
      "id": "usd1",
      "name": "USD1 token",
      "kind": "asset",
      "proposedTier": 9,
      "assessment": "assessed",
      "scope": "Ethereum-mainnet issuer-backed token, including material offchain reserve custody and redemption.",
      "reason": "BitGo issuance, custody of reserves and offchain redemption establish issuer-controlled backing. Current proxy/source adds privileged mint/freeze/upgrade powers.",
      "controls": [
        "BitGo issuance, custody of reserves and offchain redemption establish issuer-controlled backing"
      ],
      "evidenceUrls": [
        "https://sourcify.dev/server/v2/contract/1/0x8d0d000ee44948fc98c9b98a4fa4921476f08b0d?fields=sources,compilation,runtimeBytecode,proxyResolution,deployment",
        "https://etherscan.io/address/0x8d0d000ee44948fc98c9b98a4fa4921476f08b0d#code",
        "https://docs.worldlibertyfinancial.com/resources/faq"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "stable:262"
      ],
      "dependencies": [],
      "canonicalAddresses": {
        "1": "0x8d0d000ee44948fc98c9b98a4fa4921476f08b0d"
      },
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ],
      "sourceProof": {
        "checkedAt": "2026-10-01",
        "chainId": 1,
        "address": "0x8d0d000ee44948fc98c9b98a4fa4921476f08b0d",
        "provider": "sourcify-v2",
        "runtimeSha256": "927043b52a56c3880196a6a4ffe9aaf8a942465cb05613109038583f58c66971",
        "sourcesSha256": "88eb5d15d8f93f4bcf76071deb99169bcf2a7c031288c0f985b98d4cbd13418f",
        "contractName": "TransparentUpgradeableProxy",
        "proxyDetected": true,
        "implementation": {
          "address": "0x694Aa534bdef8eD63244eB902E7914e527891F08",
          "name": "StablecoinV2"
        },
        "onchainCodeMatchedAt": "2026-10-01"
      }
    },
    {
      "id": "usdc",
      "name": "USDC",
      "kind": "asset",
      "proposedTier": 9,
      "scope": "Ethereum mainnet deployment; asset-level dependencies assessed separately.",
      "reason": "Circle controls token blocking and the offchain reserves needed for redemption.",
      "controls": [
        "Issuer blocklisting.",
        "Offchain reserve custody and issuer redemption."
      ],
      "evidenceUrls": [
        "https://www.circle.com/legal/usdc-risk-factors",
        "https://www.circle.com/legal/usdc-terms"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "USDC"
      ],
      "dependencies": [],
      "canonicalAddresses": {
        "1": "0xa0b86991c6218b36c1d19d4a2e9eb0ce3606eb48"
      },
      "limits": [
        "Native and bridged USDC must be distinguished; additional bridge controls compose upward."
      ],
      "assessment": "assessed",
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ],
      "sourceProof": {
        "checkedAt": "2026-10-01",
        "chainId": 1,
        "address": "0xa0b86991c6218b36c1d19d4a2e9eb0ce3606eb48",
        "provider": "sourcify-v2",
        "runtimeSha256": "c1bcd4dc4f30c4dcf6c9fe462abeaf2efefc065dcb4dec74996e471f1ce219b4",
        "sourcesSha256": "a119c20eede6dd674efc8cbae690e22482077778322a5822105934da69b21400",
        "contractName": "FiatTokenProxy",
        "proxyDetected": true,
        "onchainCodeMatchedAt": "2026-10-01"
      }
    },
    {
      "id": "usde",
      "name": "USDe",
      "kind": "asset",
      "proposedTier": 9,
      "scope": "Ethereum mainnet deployment; asset-level dependencies assessed separately.",
      "reason": "Backing depends on custodial and exchange operations with permissioned direct redemption.",
      "controls": [
        "Whitelisted mint/redeem access.",
        "Custodial collateral routing.",
        "Exchange hedge and settlement dependencies."
      ],
      "evidenceUrls": [
        "https://docs.ethena.fi/solution-design/key-trust-assumptions",
        "https://docs.ethena.fi/solution-overview/usde-overview"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "USDE",
        "USDe"
      ],
      "dependencies": [],
      "assessment": "assessed",
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "usdg",
      "name": "USDG",
      "kind": "asset",
      "proposedTier": 9,
      "scope": "Ethereum mainnet deployment; asset-level dependencies assessed separately.",
      "reason": "Paxos controls reserve redemption and can freeze or wipe token balances.",
      "controls": [
        "Issuer reserve custody.",
        "Asset-protection role can freeze and wipe balances."
      ],
      "evidenceUrls": [
        "https://www.paxos.com/usdg",
        "https://github.com/paxosglobal/usdg-contract/blob/master/README.md"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "USDG"
      ],
      "dependencies": [],
      "assessment": "assessed",
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "usdp",
      "name": "USDP",
      "kind": "asset",
      "proposedTier": 9,
      "scope": "Ethereum mainnet deployment; asset-level dependencies assessed separately.",
      "reason": "Paxos issuer custody and asset-protection controls remain part of the asset.",
      "controls": [
        "Offchain backing.",
        "Issuer freeze and balance-wipe powers."
      ],
      "evidenceUrls": [
        "https://github.com/paxosglobal/paxos-token-contracts"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "USDP"
      ],
      "dependencies": [],
      "assessment": "assessed",
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "usds",
      "name": "USDS",
      "kind": "asset",
      "proposedTier": 3,
      "scope": "Ethereum mainnet deployment; asset-level dependencies assessed separately.",
      "reason": "Upgradeable issuance inherits Sky governance and the collateral backing used by the system.",
      "controls": [
        "UUPS-upgradeable token.",
        "Governance-authorized issuance."
      ],
      "evidenceUrls": [
        "https://github.com/sky-ecosystem/usds",
        "https://developers.skyeco.com/protocol/tokens/usds/"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "USDS"
      ],
      "dependencies": [
        "sky"
      ],
      "ownComponentTier": 3,
      "knownFloor": 3,
      "proposedRange": [
        3,
        5
      ],
      "limits": [
        "Upgradeability is not evidence that an account-freeze feature is currently enabled."
      ],
      "assessment": "lower-bound",
      "tierBound": true,
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "usdt",
      "name": "USDT",
      "kind": "asset",
      "proposedTier": 9,
      "scope": "Ethereum mainnet deployment; asset-level dependencies assessed separately.",
      "reason": "Tether can freeze and destroy balances and controls redemption of the backing.",
      "controls": [
        "Owner-controlled blacklist and destruction of blacklisted funds.",
        "Issuer reserve custody and redemption."
      ],
      "evidenceUrls": [
        "https://github.com/tethercoin/USDT/blob/main/TetherToken.sol",
        "https://tether.to/en/faqs/"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "USDT"
      ],
      "dependencies": [],
      "canonicalAddresses": {
        "1": "0xdac17f958d2ee523a2206206994597c13d831ec7"
      },
      "assessment": "assessed",
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ],
      "sourceProof": {
        "checkedAt": "2026-10-01",
        "chainId": 1,
        "address": "0xdac17f958d2ee523a2206206994597c13d831ec7",
        "provider": "sourcify-v2",
        "runtimeSha256": "6d967f98f2f3843065688dc2065248e3686b56fc0b6ddfa82007df016148becb",
        "sourcesSha256": "d83ee8ecc891a9255291a31f61f1c9bb1adae7ea60344d36ac911c2d027791d3",
        "contractName": "TetherToken",
        "proxyDetected": false,
        "onchainCodeMatchedAt": "2026-10-01"
      }
    },
    {
      "id": "usdy",
      "name": "USDY",
      "kind": "asset",
      "proposedTier": 9,
      "scope": "Canonical token mechanism; deployment-specific custody adds inherited bounds.",
      "reason": "A permissioned issuer claim backed by Treasury assets and bank deposits; redemption depends on Ondo and its custodians.",
      "controls": [
        "A permissioned issuer claim backed by Treasury assets and bank deposits; redemption depends on Ondo and its custodians."
      ],
      "evidenceUrls": [
        "https://docs.ondo.finance/general-access-products/usdy/basics",
        "https://docs.ondo.finance/general-access-products/usdy/important-notes"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "USDY"
      ],
      "dependencies": [],
      "assessment": "assessed",
      "tierBound": false,
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "usyc",
      "name": "USYC",
      "kind": "asset",
      "proposedTier": 9,
      "scope": "Canonical token mechanism; deployment-specific custody adds inherited bounds.",
      "reason": "Tokenized fund shares depend on the fund manager, custody, investor eligibility and redemption rules.",
      "controls": [
        "Tokenized fund shares depend on the fund manager, custody, investor eligibility and redemption rules."
      ],
      "evidenceUrls": [
        "https://www.circle.com/usyc"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "USYC"
      ],
      "dependencies": [],
      "assessment": "assessed",
      "tierBound": false,
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "wbeth",
      "name": "WBETH",
      "kind": "asset",
      "proposedTier": 9,
      "scope": "Canonical deployed product; additional asset and chain dependencies compose separately.",
      "reason": "The token represents ETH staked through Binance and inherits its custodial service.",
      "controls": [],
      "evidenceUrls": [
        "https://www.binance.com/en-IN/support/announcement/detail/a1197f34d832445db41654ad01f56b4d"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "WBETH",
        "wbETH"
      ],
      "dependencies": [
        "binance-staked-eth"
      ],
      "assessment": "assessed",
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "wbtc",
      "name": "WBTC",
      "kind": "asset",
      "proposedTier": 9,
      "scope": "Ethereum mainnet deployment; asset-level dependencies assessed separately.",
      "reason": "BTC backing is held by institutional custodians and redeemed through authorized merchants.",
      "controls": [
        "Custodian-controlled BTC reserves.",
        "Permissioned mint and redemption channels."
      ],
      "evidenceUrls": [
        "https://wbtc.network/whitepaper",
        "https://wbtc.network/faq"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "WBTC"
      ],
      "dependencies": [],
      "canonicalAddresses": {
        "1": "0x2260fac5e5542a773aa44fbcfedf7c193bc2c599"
      },
      "assessment": "assessed",
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ],
      "sourceProof": {
        "checkedAt": "2026-10-01",
        "chainId": 1,
        "address": "0x2260fac5e5542a773aa44fbcfedf7c193bc2c599",
        "provider": "sourcify-v2",
        "runtimeSha256": "1377b93c57d7373bf87a742b4783deff88599e7a1bcca58f0a5d6a93e8a2973b",
        "sourcesSha256": "559942d4e8c5aac2d1edb8d1cf2fa0c085d4cac6ef088371ec56bb2a8b44f86a",
        "contractName": "WBTC",
        "proxyDetected": false,
        "onchainCodeMatchedAt": "2026-10-01"
      }
    },
    {
      "id": "weeth",
      "name": "weETH",
      "kind": "asset",
      "proposedTier": 0,
      "scope": "Ethereum mainnet deployment; asset-level dependencies assessed separately.",
      "reason": "The wrapper preserves eETH staking and restaking dependencies.",
      "controls": [],
      "evidenceUrls": [
        "https://etherfi.gitbook.io/etherfi/contracts-and-integrations/deployed-contracts"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "WEETH",
        "weETH"
      ],
      "dependencies": [
        "eeth"
      ],
      "knownFloor": 3,
      "proposedRange": [
        3,
        4
      ],
      "assessment": "assessed",
      "tierBound": false,
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "weth9",
      "name": "WETH",
      "kind": "asset",
      "proposedTier": 0,
      "scope": "Canonical Ethereum WETH9 only; same ticker on another chain or contract is not covered.",
      "reason": "The canonical WETH9 wrapper has fixed deposit and withdrawal rules and no privileged owner.",
      "controls": [
        "Immutable wrapper; holders redeem their own balance for ETH."
      ],
      "evidenceUrls": [
        "https://github.com/dapphub/ds-weth/blob/master/src/weth9.sol"
      ],
      "reviewedAt": "2026-09-08",
      "aliases": [
        "WETH"
      ],
      "dependencies": [
        "native-eth"
      ],
      "canonicalAddresses": {
        "1": "0xc02aaa39b223fe8d0a0e5c4f27ead9083c756cc2"
      },
      "assessment": "assessed",
      "reviewCadence": "permanent-D0",
      "nextReviewAt": null,
      "immutableIdentity": "Ethereum mainnet WETH9 0xc02aaa39b223fe8d0a0e5c4f27ead9083c756cc2; fixed native-ETH deposit and withdrawal code.",
      "sourceProof": {
        "checkedAt": "2026-09-29",
        "chainId": 1,
        "address": "0xc02aaa39b223fe8d0a0e5c4f27ead9083c756cc2",
        "provider": "sourcify-v2",
        "runtimeSha256": "5566bf50796faf93c9b6f6adacd3b32c70bfe16b48ffc59db6cd144cbdc89739",
        "sourcesSha256": "991e959fe30a34f1545e19953a72e091e55a4c6660691bc1a5a65e594b1e3941",
        "contractName": "WETH9",
        "proxyDetected": false,
        "onchainCodeMatchedAt": "2026-09-29"
      }
    },
    {
      "id": "world",
      "name": "World Chain",
      "kind": "chain",
      "proposedTier": 8,
      "scope": "World Chain mainnet, chain ID 480; chain protocol, not World ID biometric privacy.",
      "reason": "Permissioned dispute participation and immediate upgrades leave ordinary settlement and exits dependent on privileged actors.",
      "controls": [
        "Permissioned fault-proof games; one entity may propose and challenge in the reviewed deployment.",
        "Immediate proxy upgrades and guardian powers remain.",
        "No permissionless participation is inferred from OP Stack or Superchain membership.",
        "L1 inclusion exists, but designated proposers are still needed to advance withdrawal state."
      ],
      "evidenceUrls": [
        "https://l2beat.com/layer2s/projects/world"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [
        "ethereum"
      ],
      "assessment": "assessed",
      "tierBound": false,
      "dimensions": {
        "Validation": "Permissioned fault-proof games; one entity may propose and challenge in the reviewed deployment.",
        "Upgrades": "Immediate proxy upgrades and guardian powers remain.",
        "Accountability": "No permissionless participation is inferred from OP Stack or Superchain membership.",
        "Exits": "L1 inclusion exists, but designated proposers are still needed to advance withdrawal state."
      },
      "uncertainty": "The upstream review flags ongoing changes. This is a chain-authority review, not an assessment of identity products.",
      "reviewBasis": "Editorial mapping from linked first-party governance records and L2BEAT contract-discovery research to this map’s D0–D9 rubric; not a conversion of L2BEAT stages.",
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "wsteth",
      "name": "wstETH",
      "kind": "asset",
      "proposedTier": 0,
      "scope": "Ethereum mainnet deployment; asset-level dependencies assessed separately.",
      "reason": "The fixed wrapper preserves the stETH and Lido dependencies underneath it.",
      "controls": [
        "Non-rebasing representation of stETH."
      ],
      "evidenceUrls": [
        "https://docs.lido.fi/guides/lido-tokens-integration-guide/",
        "https://docs.lido.fi/deployed-contracts/"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "WSTETH",
        "wstETH"
      ],
      "dependencies": [
        "steth"
      ],
      "knownFloor": 3,
      "proposedRange": [
        3,
        4
      ],
      "canonicalAddresses": {
        "1": "0x7f39c581f595b53c5cb19bd0b3f8da6c935e2ca0"
      },
      "assessment": "assessed",
      "tierBound": false,
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ],
      "sourceProof": {
        "checkedAt": "2026-10-01",
        "chainId": 1,
        "address": "0x7f39c581f595b53c5cb19bd0b3f8da6c935e2ca0",
        "provider": "sourcify-v2",
        "runtimeSha256": "5719e354e2cf1a08674d0034c090fdc03e25162d8f1d99830a2d95aba54fbd97",
        "sourcesSha256": "f41d0bd268c2616bb5c2e441201e4b0f49e5f3291dd39626eec50d8bb8cc7bdb",
        "contractName": "WstETH",
        "proxyDetected": false,
        "onchainCodeMatchedAt": "2026-10-01"
      }
    },
    {
      "id": "xaut",
      "name": "XAUT",
      "kind": "asset",
      "proposedTier": 9,
      "scope": "Canonical token mechanism; deployment-specific custody adds inherited bounds.",
      "reason": "Tether controls issuance and redemption of claims on physical gold held in custody.",
      "controls": [
        "Tether controls issuance and redemption of claims on physical gold held in custody."
      ],
      "evidenceUrls": [
        "https://gold.tether.to/"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [
        "XAUT"
      ],
      "dependencies": [],
      "assessment": "assessed",
      "tierBound": false,
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "yearn-v3",
      "name": "Yearn V3",
      "kind": "protocol",
      "proposedTier": 2,
      "tierBound": true,
      "scope": "Ethereum L1 protocol mechanism; assets and integrations are separate dependencies.",
      "reason": "Allocator vault managers select strategies, debt allocations, accountants and withdrawal-limit modules. The fixed vault code alone does not make the managed position D0; at least D2 until each deployment and strategy is resolved.",
      "controls": [
        "Allocator vault managers select strategies, debt allocations, accountants and withdrawal-limit modules. The fixed vault code alone does not make the managed position D0; at least D2 until each deployment and strategy is resolved."
      ],
      "evidenceUrls": [
        "https://docs.yearn.fi/developers/v3/overview",
        "https://docs.yearn.fi/developers/v3/vault_management"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [],
      "assessment": "lower-bound",
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    },
    {
      "id": "zksync",
      "name": "ZKsync Era",
      "kind": "chain",
      "proposedTier": 8,
      "scope": "ZKsync Era, chain ID 324; includes shared Gateway and operator filtering dependencies.",
      "reason": "Delayed governance and a joint emergency board coexist with operator filtering and permissioned proposals that can block ordinary exits.",
      "controls": [
        "Validity proofs constrain state; batch proposal and approval remain permissioned.",
        "Normal DAO path has delays; Council, Guardians and Foundation can jointly execute an immediate emergency upgrade.",
        "Multiple governance bodies constrain upgrades, without removing operator-level censorship powers.",
        "L1 queue cannot compel processing. An operator-installed transaction filter can censor withdrawals without delay."
      ],
      "evidenceUrls": [
        "https://l2beat.com/layer2s/projects/zksync-era"
      ],
      "reviewedAt": "2026-10-01",
      "aliases": [],
      "dependencies": [
        "ethereum"
      ],
      "assessment": "assessed",
      "tierBound": false,
      "dimensions": {
        "Validation": "Validity proofs constrain state; batch proposal and approval remain permissioned.",
        "Upgrades": "Normal DAO path has delays; Council, Guardians and Foundation can jointly execute an immediate emergency upgrade.",
        "Accountability": "Multiple governance bodies constrain upgrades, without removing operator-level censorship powers.",
        "Exits": "L1 queue cannot compel processing. An operator-installed transaction filter can censor withdrawals without delay."
      },
      "uncertainty": "The stronger upgrade process is recorded, but the controlling exit dimension is D8.",
      "reviewBasis": "Editorial mapping from linked first-party governance records and L2BEAT contract-discovery research to this map’s D0–D9 rubric; not a conversion of L2BEAT stages.",
      "reviewCadence": "monthly",
      "nextReviewAt": "2026-11-01",
      "reviewChecks": [
        "identity",
        "implementation",
        "authorities",
        "timing",
        "exits",
        "dependencies"
      ]
    }
  ],
  "rubricVersion": "2.0",
  "scope": "An ordinal assessment of additional authority over assets and applications built on Ethereum. Scores are editorial approximations, not L2BEAT stages. An at-least score preserves known restrictions when an additional dependency remains unreviewed.",
  "aggregation": {
    "rule": "effectiveTier = max(asset or wrapper tier, containing protocol tier, every security-relevant ancestor and dependency tier)",
    "unknown": "If any material dependency is unreviewed, effectiveTier is null. knownFloor is the largest established tier, not a replacement for unknown.",
    "order": "Larger D means additional control. A child cannot have a numerically smaller effective D than an ancestor.",
    "composition": "Record dependencies by the actual capital path. Do not attach every product of a brand to every other product. Parallel independent exits can remove a dependency only after a specific review.",
    "nonCardinal": "Ordinal categories, not equal intervals: D4 is not twice as centralized as D2. Multiple controls at one tier remain visible in details."
  },
  "tiers": [
    {
      "tier": 0,
      "label": "Maximum decentralization",
      "definition": "As decentralized as Ethereum L1 itself within the reviewed mechanism; no additional administrator can rewrite its principal or exit rules.",
      "id": "D0",
      "color": "#8bffff"
    },
    {
      "tier": 1,
      "label": "Limited administration",
      "definition": "Bounded settings can change, while the reviewed asset custody and exit mechanism remains fixed.",
      "id": "D1",
      "color": "#32ff81"
    },
    {
      "tier": 2,
      "label": "External operation",
      "definition": "An oracle, allocation role, pause or other external operation materially affects the position without arbitrary replacement of its core.",
      "id": "D2",
      "color": "#a8ff00"
    },
    {
      "tier": 3,
      "label": "Delayed governance",
      "definition": "Governance can change the system through a documented delay; user vetoes and exit protections are assessed explicitly.",
      "id": "D3",
      "color": "#e5ff00"
    },
    {
      "tier": 4,
      "label": "Independent emergency council",
      "definition": "An elected, accountable and diverse council can act immediately, alongside a delayed normal governance route.",
      "id": "D4",
      "color": "#fff000"
    },
    {
      "tier": 5,
      "label": "Council and foundation",
      "definition": "A formally governed council shares immediate authority with a foundation, with additional foundation or fallback powers.",
      "id": "D5",
      "color": "#ffbf00"
    },
    {
      "tier": 6,
      "label": "Council and operator",
      "definition": "An operator shares immediate authority with an appointed council, with limited public governance or removal rights.",
      "id": "D6",
      "color": "#ff8a24"
    },
    {
      "tier": 7,
      "label": "Administrator upgrade",
      "definition": "A concentrated administrator or committee can replace core rules without a verified protective delay and independent veto.",
      "id": "D7",
      "color": "#ff5c44"
    },
    {
      "tier": 8,
      "label": "Operator-governed validation",
      "definition": "The operator also restricts who may validate or challenge state, or can defeat ordinary inclusion or exit mechanisms.",
      "id": "D8",
      "color": "#ff405d"
    },
    {
      "tier": 9,
      "label": "Issuer-controlled backing",
      "definition": "An issuer or custodian controls the backing, redemption or seizure of the asset. This dimension is additional to the chain it uses.",
      "id": "D9",
      "color": "#ff3152"
    }
  ]
}
