defirisk.co
rubric v1.7.0

Audit scope mismatch

Rocket Pool's assessment for RD-F-001 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

Six+ audit engagements confirmed across all major upgrades. Saturn One (2026-02-18) covered by three firms: Sigma Prime, Cantina/Spearbit, Bailsec. Cantina and Bailsec reports confirmed published by Feb 16, 2026; Sigma Prime Saturn final report pending sign-off at that date (expected early February per governance forum). Both Cantina and Bailsec identified substantial findings requiring code changes that were addressed pre-launch. Audit PDFs inaccessible via WebFetch — commit SHA matching against deployed bytecode not achievable. Not red because three-firm pre-deploy audit with documented issue resolution is affirmatively confirmed; not green because commit SHA verification is not possible.

Sources #

Methodology #

Check whether the commit SHA cited in the audit report matches the bytecode deployed at the production proxy/implementation address.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol rocket-pool factor RD-F-001 score yellow collected_at 2026-05-04 15:40:28