defirisk.co
rubric v1.7.0

New contract with similar bytecode to exploit template

Cap (cUSD / stcUSD)'s assessment for RD-F-094 — scored gray on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

T-09 v2-deferred signal. No live new-deploy sweep with bytecode similarity check against Cap's contracts. Cap uses UUPS proxy pattern + AccessControl — bytecode-similar exploit-template contracts are a plausible class. No specific exploit-template deployment targeting Cap found via OSINT web searches.

Sources #

  • Internal
    T-09 — F104 (new contract similar bytecode) deferred rationaleresearch/outputs/09-realtime-signals.md §3.3 v2/deferred table (F104 entry)retrieved 2026-05-17

Methodology #

Detect whether a freshly deployed contract has high bytecode similarity to a known exploit template targeting this protocol class.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol cap factor RD-F-094 score gray collected_at 2026-05-17 10:56:24