Static-analyzer high-severity count
Orca's assessment for RD-F-010 — scored gray on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
Slither/Mythril/Semgrep are EVM-specific static analysis tools and cannot be run on Rust/BPF bytecode. Orca Whirlpools is an Anchor/Rust Solana program; no Etherscan-verified source exists (non-EVM substrate). Sec3's X-ray tool was used in the 2025 audits but findings are not publicly summarized. Structurally not assessable via the taxonomy-specified toolchain on this substrate.
Sources #
- GitHubWhirlpool program lib.rs (Anchor/Rust — confirms non-EVM substrate)https://github.com/orca-so/whirlpools/blob/main/programs/whirlpool/src/lib.rsretrieved 2026-05-16
Methodology #
Count the number of unique high-severity detector findings from Slither + Mythril + Semgrep run against the deployed verified source (after deduplication across tools).
See the full factor methodology and distribution across all protocols →