Spark Protocol
DAMASCUSLending / Borrowing · Ethereum · $4B+ TVL · 15 contracts
Public risk assessment — scores are produced with the same methodology as monitored protocols
Security Profile
82
80
82
72
75
80
61
85
82
71
82
80
82
72
75
80
61
85
82
71
Audit History
Bug Bounty Program
Assessment
Strong score driven by MakerDAO org maturity (D6=80), Aave V3 base code, and dual oracle infrastructure. Compositional risk (D4=72) from deep Maker integration is the main drag.
Dimension Breakdown
How scores work →- Aave V3 fork with proven access control model
- MakerDAO integration adds admin surface complexity
- Emergency admin via MakerDAO governance
- Pool configurator and bridge executor from Aave
- Inherits Aave V3 economic model (well-tested)
- DAI-first design with Maker PSM providing stability anchor
- SparkVault/PSM3 for stablecoin operations
- DSR integration provides floor yield
- Chainlink primary + Chronicle oracles (Maker oracle infra)
- Dual oracle infrastructure provides redundancy
- Inherited Aave V3 oracle validation
- Maker oracle security team provides additional oversight
- SparkLend live since mid-2023 (~2 years)
- MakerDAO org maturity 5+ years (battle-tested through multiple crises)
- Aave V3 base code is extensively battle-tested
- Audited via Maker pipeline (ChainSecurity, ABDK)
- Z-factor: 0.802
- MakerDAO governance (MKR holders) provides oversight
- SubDAO structure with SPK token governance maturing
- Timelocks via Maker governance (GSM delay)
- Some centralization in SubDAO executive decisions
- Score derived from continuous adversarial security research
- Inherits MakerDAO mature monitoring infrastructure
- Keeper network for liquidations
- Incident response backed by Maker experience
- Active bug bounty program
- Deep integration with MakerDAO (D3M, PSM, DSR)
- MakerDAO failure would cascade to Spark
- Correlated risk with DAI/USDS stability
- Growing integration surface (Morpho vaults, etc.)
- Appears in 5 cross-protocol cascade chain(s)
- Member of 3 dependency cluster(s)
- Score: 71/100 (higher = more isolated from systemic risk)
- Source: cross_protocol_composition.json dependency analysis
- Aave V3 codebase is extensively audited base
- Standard OpenZeppelin libraries
- Maker integration libraries add some dependency
- Proxy patterns inherited from Aave V3
Risk Drivers
Primary risk factors driving this score, ordered by severity.
Adversarial Risk Signals
Observable security posture indicators. These signals reflect publicly verifiable information and responsible disclosure outcomes. No specific vulnerability details are exposed.
Score History & Verification
Score provenance tracking begins with the next reassessment.
On-Chain Data
- Protocol Slug
- "spark"
- Oracle
- BRORegistry (Base)
- Evidence
- IPFS (pinned)
- Staleness Threshold
- 24 hours
registry.getScore("spark")Reduce exploitable risk
BlackHart Monitoring provides continuous adversarial analysis, vulnerability detection, remediation support, and verified reassessment when your risk posture improves.