D1
Access Control
Permission models, admin surface, reentrancy protection, and authorization boundaries. #1 exploit vector by dollar loss in DeFi history.
Weight 18%82% confidence
85
Strong
info
How This Score Is Built
Permission models, admin surface, reentrancy protection, and authorization boundaries. #1 exploit vector by dollar loss in DeFi history.
+23Strong positive
+12Positive
+5Slight positive
−15Strong negative
−8Negative
−3Slight negative
Score Composition
-8
Minimalist Morpho Blue core: ~650 lines, immutable, no admin keys
-8
No emergency pause on base layer (by design)
+42
Authorization model via callbacks (well-scoped)
+42
MetaMorpho vaults add curator layer with controlled permissions
Evidence Chain (2 files)
GitHub APIMay 17, 2026, 06:58 PM
open_in_newGitHub (/)sha256:c4cdd25ed7b5...
BlackHart AnalysisMay 4, 2026, 08:00 PM
open_in_newAccess Control — Source Codesha256:839cd8516924...
Score History
—
Automated pipeline dimension update