CoW Protocol
MITHRILDEX Aggregator · Ethereum + Gnosis · $500M+ TVL · 10 contracts
Public risk assessment — scores are produced with the same methodology as monitored protocols
Security Profile
85
88
82
75
80
82
50
85
82
100
85
88
82
75
80
82
50
85
82
100
Audit History
Bug Bounty Program
Assessment
Innovative batch auction DEX with native MEV protection. D4 penalized for deep multi-DEX dependency for settlement. Clean track record (36+ months, Gnosis heritage). Solver competition model is novel but less battle-tested.
Dimension Breakdown
How scores work →- Solver competition with bonding requirements
- Settlement contract with allow-listed solvers
- Order signing via EIP-712 (user intent)
- Pre-hooks and post-hooks add execution flexibility
- Batch auction model provides MEV protection
- Surplus from CoW (Coincidence of Wants) returned to users
- CoW AMM adds protocol-owned liquidity
- Solver competition creates price improvement incentive
- No external oracle in core - solver provides price discovery
- Settlement must match or exceed user's limit price
- Reference prices from DEX liquidity (indirect oracle)
- Price quality enforced by solver competition
- GPv2 live since 2021, CoW Protocol since 2022 (36+ months)
- Gnosis team heritage (ex-Gnosis Protocol)
- No protocol-level exploit
- Growing but still mid-maturity
- Z-factor: 0.854
- CowDAO governance via vCOW token
- Snapshot voting with on-chain execution
- Solver whitelist managed by governance
- Emerging governance maturity
- Maximum resilience under independent adversarial testing
- Comprehensive security coverage across all attack surfaces
- Active bounty program incentivizes continuous scrutiny
- No validated adversarial findings — score set to neutral baseline
- Professional team with Gnosis heritage
- Solver monitoring and competition oversight
- Order book infrastructure management
- Active development and deployment cadence
- Aggregates across Uniswap, Balancer, Curve, etc.
- Deep external DEX dependency for settlement
- Solver strategies compose across multiple protocols
- Hook system adds new composition vectors
- Member of 1 dependency cluster(s)
- No cross-protocol cascade exposure detected
- Score: 100/100 (higher = more isolated from systemic risk)
- Source: cross_protocol_composition.json dependency analysis
- Standard Solidity settlement contracts
- Rust-based solver infrastructure
- Well-maintained dependency set
- Verified on Ethereum mainnet
Risk Drivers
Primary risk factors driving this score, ordered by severity.
Adversarial Risk Signals
Observable security posture indicators. These signals reflect publicly verifiable information and responsible disclosure outcomes. No specific vulnerability details are exposed.
Score History & Verification
Score provenance tracking begins with the next reassessment.
On-Chain Data
- Protocol Slug
- "cow-protocol"
- Oracle
- BRORegistry (Base)
- Evidence
- IPFS (pinned)
- Staleness Threshold
- 24 hours
registry.getScore("cow-protocol")Reduce exploitable risk
BlackHart Monitoring provides continuous adversarial analysis, vulnerability detection, remediation support, and verified reassessment when your risk posture improves.