Liquity BOLD
DAMASCUSStablecoin · Ethereum · $500M+ TVL · 15 contracts
Public risk assessment — scores are produced with the same methodology as monitored protocols
Security Profile
82
72
78
65
90
42
50
85
88
100
82
72
78
65
90
42
50
85
88
100
Audit History
Bug Bounty Program
Assessment
Governance-minimized stablecoin from proven Liquity team. Immutability gives top scores in D1/D5/D8/D11 but very low maturity (Z=0.374, D6=42) is the critical drag. Novel interest rate mechanism untested. Score will rise rapidly if no exploit in first 18 months.
Dimension Breakdown
How scores work →- Immutable contracts (no admin keys, no upgradability)
- Permissionless borrowing and liquidation
- No governance control over protocol parameters
- User-set interest rates (novel mechanism)
- BOLD stablecoin with user-set interest rates (novel)
- Multi-collateral (ETH, wstETH, rETH) with independent markets
- Interest rate mechanism untested at scale
- Redemption mechanism redesigned from Liquity V1
- No governance = economic parameters must be self-regulating
- Chainlink oracles with fallback to Uniswap TWAP
- Dual oracle design provides redundancy
- LST exchange rate handling adds complexity
- Oracle failure modes well-considered in design
- Mainnet since October 2025 (~7 months)
- Very new protocol, limited battle testing
- V1 (LUSD) ran 4+ years without exploit (team has track record)
- Multiple audits (Dedaub, ChainSecurity, Certora formal verification)
- Z-factor: 0.374
- Fully immutable, no governance attack surface
- No admin keys, no multisig risk
- Parameter changes impossible (governance-minimized by design)
- Highest possible governance score for DeFi
- No validated adversarial findings — score set to neutral baseline
- Immutable contracts = no operational key risk
- No admin operations needed post-deployment
- Protocol is self-operating by design
- Operational risk transferred entirely to users
- LST collateral inherits staking protocol risk (Lido, RocketPool)
- BOLD composed in DeFi lending and DEXes
- Cross-collateral type risks bounded by independent markets
- Stability pool composition is well-scoped
- Appears in 1 cross-protocol cascade chain(s)
- Member of 2 dependency cluster(s)
- Score: 100/100 (higher = more isolated from systemic risk)
- Source: cross_protocol_composition.json dependency analysis
- Minimal dependencies (immutable = no proxy libraries)
- Clean Solidity with no upgradeable patterns
- Standard OpenZeppelin for token interfaces
- Immutability means no supply chain update risk post-deploy
Risk Drivers
Primary risk factors driving this score, ordered by severity.
Adversarial Risk Signals
Observable security posture indicators. These signals reflect publicly verifiable information and responsible disclosure outcomes. No specific vulnerability details are exposed.
Score History & Verification
Score provenance tracking begins with the next reassessment.
On-Chain Data
- Protocol Slug
- "liquity-bold"
- Oracle
- BRORegistry (Base)
- Evidence
- IPFS (pinned)
- Staleness Threshold
- 24 hours
registry.getScore("liquity-bold")Reduce exploitable risk
BlackHart Monitoring provides continuous adversarial analysis, vulnerability detection, remediation support, and verified reassessment when your risk posture improves.