BlackHartBlackHart
Scores/Immutable

Immutable

DAMASCUS

Gaming / NFT L2 · Ethereum + zkEVM · $500M+ TVL · 20 contracts

Confidence 75%Z-Factor 0.80Updated 2026-05-06Public Score

Public risk assessment — scores are produced with the same methodology as monitored protocols

842
BRI Score
3004756508251000

Security Profile

Access Ctrl
75
Economic
80
Oracle
85
Compos.
78
Govern.
50
Maturity
78
Resilience
97
Supply Ch.
78
OpSec
75
Cascade
100
Min
50
Avg
80
Max
100

Audit History

Trail of Bits
2022-09
NCC Group
2023-03

Bug Bounty Program

$1,000,000
Max payout on Immunefi
View Program →

Assessment

Gaming L2 built on StarkEx with 49-month track record. D5 very low (50) due to fully centralized governance. D3 high (85) thanks to cryptographic validity proofs. Lower risk profile than DeFi but centralization concerns.

Dimension Breakdown

How scores work →
Access Control
Weight 18%72% conf
75
Good
  • StarkEx operator controls sequencing and data availability
  • Centralized sequencer with escape hatch mechanism
  • NFT minting requires operator approval
  • Withdrawal delay provides user protection window
Economic Soundness
Weight 13%75% conf
80
Strong
  • NFT marketplace economics (not DeFi lending/trading)
  • IMX token for protocol fees (limited economic attack surface)
  • No flash loan or price manipulation vectors in core
  • Lower economic complexity than DeFi protocols
Oracle Integrity
Weight 13%80% conf
85
Strong
  • StarkEx validity proofs (cryptographic, not oracle-based)
  • No external price oracle dependency for core NFT operations
  • L1 settlement provides price finality
  • Minimal oracle surface compared to DeFi protocols
Battle-Tested Maturity
Weight 12%78% conf
78
Good
  • Live since April 2021 (49 months)
  • Processed millions of NFT transactions
  • StarkEx technology well-tested (shared with dYdX)
  • Z-factor: 0.891
Governance & Upgradeability
Weight 10%70% conf
50
Concerning
  • Centralized operator (Immutable X team)
  • No on-chain governance mechanism
  • Protocol upgrades controlled by team multisig
  • Escape hatch is user protection, not governance
Adversarial Resilience
Weight 10%95% conf
97
Excellent
  • Score derived from continuous adversarial security research
Operational Security
Weight 10%72% conf
75
Good
  • Professional operations team (VC-backed)
  • StarkEx operator infrastructure
  • Centralized but professionally managed
  • Incident response through central team
Compositional Risk
Weight 5%75% conf
78
Good
  • Limited DeFi composability (gaming/NFT focus)
  • StarkEx provides isolated execution environment
  • Bridge to Ethereum L1 for deposits/withdrawals
  • Lower composition risk than general-purpose L2
Cascade Exposure
Weight 5%50% conf
100
Excellent
  • Member of 1 dependency cluster(s)
  • No cross-protocol cascade exposure detected
  • Score: 100/100 (higher = more isolated from systemic risk)
  • Source: cross_protocol_composition.json dependency analysis
Supply Chain
Weight 4%75% conf
78
Good
  • StarkEx prover (proprietary StarkWare tech)
  • Solidity contracts for L1 bridge
  • Cairo programs for L2 logic
  • Dependency on StarkWare infrastructure

Risk Drivers

Primary risk factors driving this score, ordered by severity.

Governance & Upgradeability50
Access Control75
Operational Security75

Adversarial Risk Signals

Observable security posture indicators. These signals reflect publicly verifiable information and responsible disclosure outcomes. No specific vulnerability details are exposed.

Disclosure HistoryNot Assessed
Remediation VelocityNot Assessed
Bug Bounty ProgramNot Assessed
Audit CoverageNot Assessed
Incident HistoryNot Assessed
Deployed 2021-04-01Z-Factor 0.80010 active dimensions

Score History & Verification

Score provenance tracking begins with the next reassessment.

On-Chain Data

Protocol Slug
"immutable"
Oracle
BRORegistry (Base)
Evidence
IPFS (pinned)
Staleness Threshold
24 hours
Read Score
registry.getScore("immutable")

Reduce exploitable risk

BlackHart Monitoring provides continuous adversarial analysis, vulnerability detection, remediation support, and verified reassessment when your risk posture improves.