D1
Access Control
Permission models, admin surface, reentrancy protection, and authorization boundaries. #1 exploit vector by dollar loss in DeFi history.
Weight 18%70% confidence
62
Moderate
info
How This Score Is Built
Permission models, admin surface, reentrancy protection, and authorization boundaries. #1 exploit vector by dollar loss in DeFi history.
+23Strong positive
+12Positive
+5Slight positive
−15Strong negative
−8Negative
−3Slight negative
Score Composition
+16
DegenBox masterContractApproved pattern provides adequate access control
+16
cook() is permissionless but deferred solvency check provides post-hoc guard
+16
MIM mint is operator-only (single address)
+16
Strategy management is owner-only with timelock
Evidence Chain (2 files)
GitHub APIMay 17, 2026, 06:58 PM
open_in_newGitHub (/)sha256:3fcdf4e47b4b...
BlackHart AnalysisMay 4, 2026, 11:30 PM
open_in_newAccess Control — Source Codesha256:5bb15efa66c1...
Score History
—
Automated pipeline dimension update