docs: Metronome Synths risk assessment (2.6 — Medium Risk)#42
docs: Metronome Synths risk assessment (2.6 — Medium Risk)#42
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
PR #42 Verification Report — Metronome Synths Risk AssessmentVerification Date: February 17, 2026 (PR report date: ~February 13, 2026) 1. Contract Address Verification ✅All contract addresses confirmed to have deployed code on Ethereum mainnet (block 24478185):
2. Liquidity Figures vs DeFiLlama ✅Protocol TVL (DeFiLlama API):
Token Prices (CoinGecko):
DEX Pool TVL (DeFiLlama Yields):
3. Governance Structure ✅Ethereum Governor (on-chain verified):
Timelock Delay:
Quorum: L2 Governance (Base & Optimism Safe:
4. Risk Scoring Methodology ✅Math verified: Score justifications are consistent with evidence presented and scoring rubrics. Category scores are reasonable given the findings. 5. ProxyAdmin Safe Signers & Threshold ✅Ethereum ProxyAdmin Safe (
ProxyAdmin Ownership:
Summary
All 5 test plan items are verified. The report is accurate and ready for merge. |
…n data - Update to new template (add Contract Architecture appendix) - Refresh all on-chain data as of 2026-03-28: TVL $24.55M→$21.04M, msUSD supply 24.2M→18.7M, msETH 15.6K→17.3K Treasury USDC 364K→205K, DEX liquidity $75.9M→$93.4M Yield wrappers $87.4M→$170M - Fix signer overlap: 4/5→5/5 (all signers identical across all chains) - Note governance inactivity: no proposals since Feb 2025 (1+ year) - Note no new audits since Feb 2023 (3+ years) - Governance score 4.0→4.5, Centralization 3.2→3.3 - Final score 2.5→2.6/5.0 (still Medium Risk) Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2f8741c to
05f6121
Compare
Re-evaluation Update (2026-03-28)Report has been re-evaluated with fresh on-chain data and updated to follow the new template. Data Changes
Key Findings in Re-evaluation
Score Changes
Template Changes
|
|
Review findings after verifying the report against live on-chain state and public APIs on 2026-03-28.
Items I spot-checked that do look correct:
|
Fix three findings from spalen0's review: 1. High: Pool.governor() and PoolRegistry.governor() both return the 3/5 Safe, not the Timelock. Parameter changes (collateral factors, deposit caps, fees) are also directly controlled by the multisig. The on-chain Governor/Timelock is entirely unused, not just bypassed for upgrades. Updated framing throughout the report. 2. Medium: MIP-30 started March 10, 2025, not February 2025. Fixed all date references. 3. Low: Collateral is held in Treasury contracts, not Pool contracts. Fixed "Pool contracts" → "Treasury contracts" in provability and critical gates sections. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
|
Thanks @spalen0 — all three findings are valid and have been fixed in aaf3b29. 1. High: Pool.governor() returns the Safe, not the Timelock ✅Verified on-chain: This is worse than the original framing. The Governor/Timelock is entirely unused — not just bypassed for upgrades, but also bypassed for parameter governance (collateral factors, deposit caps, fees). Updated all affected sections:
2. Medium: Snapshot date off by one month ✅
3. Low: Collateral in Treasury, not Pool ✅
|
Summary
Comprehensive risk assessment for Metronome Synths (msUSD / msETH / msBTC), a multi-collateral multi-synthetic CDP protocol built by Bloq Inc.
Key Findings
Score Breakdown
Research Includes
Changes in re-evaluation (2026-03-28)
Test plan
🤖 Generated with Claude Code