Centrifuge
DAMASCUSRWA / Tokenization · Ethereum · $300M+ TVL · 15 contracts
Public risk assessment — scores are produced with the same methodology as monitored protocols
Security Profile
70
65
55
72
65
75
50
72
68
100
70
65
55
72
65
75
50
72
68
100
Audit History
Bug Bounty Program
Assessment
RWA tokenization protocol with 72-month Tinlake history. D3 low (55) due to off-chain oracle dependency for RWA valuations. D2 reflects inherent RWA illiquidity risk. Niche protocol with moderate security coverage.
Dimension Breakdown
How scores work →- Pool admin controls asset onboarding and configuration
- Epoch-based tranche investment/redemption model
- Restricted token transfers (compliance whitelist)
- Centralized asset originator trust dependency
- RWA collateral valuation depends on off-chain assets
- Senior/Junior tranche waterfall model
- NAV calculation relies on off-chain asset pricing
- Liquidity risk: RWA assets are illiquid by nature
- NAV oracle depends on off-chain asset valuations
- Asset originator self-reports collateral values
- Limited on-chain price verification for RWA
- Trust assumption: originator honest reporting
- Tinlake live since mid-2020 (72 months), new Centrifuge since 2023
- ~$250M TVL across pools
- No protocol-level exploit
- Z-factor: 0.923
- CFG token governance on Centrifuge Chain
- Council and democracy modules (Substrate-based)
- Pool-level governance by asset originators
- Limited on-chain governance maturity
- Maximum resilience under independent adversarial testing
- Comprehensive security coverage across all attack surfaces
- Active bounty program incentivizes continuous scrutiny
- No validated adversarial findings — score set to neutral baseline
- Small but professional team
- Dual-chain operational complexity
- RWA operations require off-chain processes
- Limited public incident response documentation
- Tinlake/Centrifuge Chain integration
- Limited DeFi composability (restricted tokens)
- MakerDAO integration for DAI lending against RWA
- Moderate external dependency footprint
- Member of 2 dependency cluster(s)
- No cross-protocol cascade exposure detected
- Score: 100/100 (higher = more isolated from systemic risk)
- Source: cross_protocol_composition.json dependency analysis
- Substrate-based chain (Centrifuge Chain)
- Solidity contracts on Ethereum (Tinlake)
- Moderate dependency complexity
- Mixed tech stack (Rust + Solidity)
Risk Drivers
Primary risk factors driving this score, ordered by severity.
Adversarial Risk Signals
Observable security posture indicators. These signals reflect publicly verifiable information and responsible disclosure outcomes. No specific vulnerability details are exposed.
Score History & Verification
Score provenance tracking begins with the next reassessment.
On-Chain Data
- Protocol Slug
- "centrifuge"
- Oracle
- BRORegistry (Base)
- Evidence
- IPFS (pinned)
- Staleness Threshold
- 24 hours
registry.getScore("centrifuge")Reduce exploitable risk
BlackHart Monitoring provides continuous adversarial analysis, vulnerability detection, remediation support, and verified reassessment when your risk posture improves.