Hyperlane
DAMASCUSCross-Chain Messaging · Multi-chain · N/A (infra) TVL · 10 contracts
Public risk assessment — scores are produced with the same methodology as monitored protocols
Security Profile
78
75
72
62
55
58
71
78
65
68
100
78
75
72
62
55
58
71
78
65
68
100
Audit History
Bug Bounty Program
Assessment
Newer cross-chain messaging protocol with modular ISM design. D5 low (55) due to pre-token governance centralization. D6 low (58) for 24-month maturity. Innovative architecture but limited stress history.
Dimension Breakdown
How scores work →- Modular ISM (Interchain Security Module) architecture
- Configurable security per route (multisig, optimistic, etc.)
- Permissionless deployment of mailboxes
- Default ISM configurable by mailbox owner
- Relayer/validator fee model (gas-based)
- No direct DeFi economics to exploit
- Interchain gas paymaster handles cross-chain fees
- Limited economic stress testing
- Validators attest to cross-chain merkle roots
- ISM modularity allows custom oracle configurations
- No external price oracle dependency
- Trust assumption varies by ISM configuration
- Mainnet since mid-2023 (~24 months)
- Relatively newer cross-chain protocol
- Growing adoption but limited stress history
- Z-factor: 0.8
- Score derived from continuous adversarial security research
- Cross-chain message passing = high compositional risk
- Warp Routes for token bridging compose with DeFi
- ISM modularity means varied security per deployment
- Permissionless deployment increases composition surface
- Newer governance structure, still centralizing
- Foundation-controlled upgrades on core contracts
- No token-based governance yet (pre-token)
- Upgradeable proxy pattern on mailbox contracts
- Cross-chain messaging is core product
- Modular ISM is innovative but adds configuration risk
- Permissionless deployment means varied security levels
- Growing chain support, each adds surface area
- Active development team (ex-Celo)
- Monitoring infrastructure maturing
- Permissionless model shifts some ops burden to deployers
- Limited incident response track record
- Appears in 1 cross-protocol cascade chain(s)
- Member of 3 dependency cluster(s)
- Score: 100/100 (higher = more isolated from systemic risk)
- Source: cross_protocol_composition.json dependency analysis
- Modern Solidity (0.8.x)
- OpenZeppelin dependencies
- Rust components for off-chain validators
- Well-structured monorepo
Risk Drivers
Primary risk factors driving this score, ordered by severity.
Adversarial Risk Signals
Observable security posture indicators. These signals reflect publicly verifiable information and responsible disclosure outcomes. No specific vulnerability details are exposed.
Score History & Verification
Score provenance tracking begins with the next reassessment.
On-Chain Data
- Protocol Slug
- "hyperlane"
- Oracle
- BRORegistry (Base)
- Evidence
- IPFS (pinned)
- Staleness Threshold
- 24 hours
registry.getScore("hyperlane")Reduce exploitable risk
BlackHart Monitoring provides continuous adversarial analysis, vulnerability detection, remediation support, and verified reassessment when your risk posture improves.