Contract Maturity
Assesses the duration and performance history of deployed smart contracts as an indicator of exploit risk and protocol stability.
Time deployed without material modification is the primary input. Maturity scoring tapers as a function of deployment age. Material upgrades reset the maturity clock: a long-deployed contract that undergoes an unaudited core upgrade is assessed against the upgrade date, not the original deployment.
| Tier | Reasoning | Evidence |
|---|---|---|
| 60+ months | Bytecode has been continuously scrutinized across multiple complete market cycles by users, integrators, competitors, white-hats, and adversarial actors. Surviving this exposure window is the strongest available evidence that obvious and many subtle vulnerability classes have been surfaced and patched. | MakerDAO core (deployed November 2017), Uniswap V2 (May 2020), Compound v2 (May 2019), and Lido stETH (December 2020) have all survived multiple cycles without core protocol exploit. Lindy effect is supported by survival analysis across the documented hack record. |
| 36 to 60 months | Has weathered at least one complete market cycle, including expansion, contraction, and macro stress regimes, providing meaningful but not exhaustive evidence of resilience. | Aave V3 (deployed March 2022), Compound III (August 2022), and GMX v2 (August 2023) sit within this band as of mid-2026. Each has weathered the 2022–2023 bear market and the 2023 banking crisis without core protocol exploit. |
| 18 to 36 months | Track record exists across multiple stress regimes but has not been tested through a full cycle, leaving residual uncertainty about behavior under conditions not yet observed. | Newer LST protocols (Renzo, Kelp, Puffer) and curator-backed lending markets (Morpho Blue) sit here, with track record across the 2024 DeFi summer and 2025 rate-cycle stress but not full bear-market exposure. |
| 6 to 18 months | Past the infant-mortality period but not deeply battle-tested; the post-deployment window during which initial vulnerabilities and integration assumptions are most likely to be exploited remains partially open. | Recently launched LRTs, active-strategy stablecoins in their first year, and newer L2 deployments. Beanstalk's exploit at month 8 ($182M), Wormhole's at month 7–8 ($326M), and Euler's roughly 8 months after a critical function was added all illustrate residual risk in this window. |
| 0 to 6 months | Highest-risk deployment period: real liquidity, integrations, and adversarial attention are not yet fully priced into the bytecode. | Concentration of the documented loss record sits here. Wormhole (~7–8 months from launch), Ronin (~5–6 months), Beanstalk (~8 months), Nomad (~4–6 months), and Cashio (~3 months) all fall within or just past this window. |