BlackHartBlackHart
D1

Access Control

Permission models, admin surface, reentrancy protection, and authorization boundaries. #1 exploit vector by dollar loss in DeFi history.

Weight 18%90% confidence
82
Strong
info

How This Score Is Built

Permission models, admin surface, reentrancy protection, and authorization boundaries. #1 exploit vector by dollar loss in DeFi history.

+23Strong positive
+12Positive
+5Slight positive
−15Strong negative
−8Negative
−3Slight negative

Score Composition

+14

Kernel-Module architecture with permissioned modifier on all Module functions

Strong positiveopen_in_newSource CodeMay 4, 2026
+14

Kernel.modulePermissions cross-contract AC lookup gates every value-affecting function

+14

Emergency policy has 8 distinct bypass guards (all cost=1.0): onlyKernel, permissioned, onlyExecutor, onlyGovernor, onlyGuardian, onlyPermitted, onlyVault, onlyRole

+14

TRSRY authority_tau_star=0.75, MINTR/Staking/Clearinghouse/Emergency all tau_star=1.0

Strong positiveopen_in_newSource CodeMay 4, 2026
+14

Kernel.executeAction blast_radius=0.613 (highest) but onlyExecutor-gated

+14

Graph analysis: 7 contracts, 1633 functions, only 50 genuinely restricted at graph level (rest gated by cross-contract Kernel check)

Strong positiveopen_in_newSource CodeMay 4, 2026

Evidence Chain (2 files)

GitHub APIMay 17, 2026, 06:58 PM
open_in_newGitHub (/)
sha256:9ca826618ed9...
BlackHart AnalysisMay 4, 2026, 09:00 PM
open_in_newAccess Control — Source Code
sha256:44f198d3e8bd...

Score History

Automated pipeline dimension update