Smart Contract Risk
The exploit risk of the token's own contracts, assessed on three inputs: audit quality, quantity, bug bounty, and contract maturity. Contract complexity weights the whole metric: a simple, permissioned share-representation token (mint, burn, whitelist-gated transfer) has a far smaller attack surface than complex on-chain DeFi logic, and for a tokenized asset whose reserve sits off-chain even a successful contract exploit cannot reach the underlying assets, only disrupt the on-chain record.
Asset quality: reserves and backing
Asset quality covers the reserves, underlying assets, and strategies backing a token's value, assessed across three risk dimensions.
Contract maturity and exploit risk
Deployed contract age and performance history as an indicator of exploit risk and protocol stability, and how Credora weighs both.