ANALYTICAL STANDARD

Methodology

Every report is built from primary, externally verifiable evidence: on-chain traces, contract bytecode and storage, protocol post-mortems, and the cryptographic record of the event. Where a claim cannot be reconstructed from observable data, it is not made.

The chain proceeds in four stages. Observation — the incident is reconstructed transaction by transaction, block heights and call traces preserved as the evidentiary spine. Classification — each incident is assigned to the Forensic Capital Vulnerability Class Taxonomy, by failure mechanism, not by headline. An event reported as one class of failure often resolves, on inspection, into another — and the distinction changes who is exposed. Scoring — severity, defensibility, recovery probability, and blast radius, assessed against fixed anchors, so two analysts reach comparable figures. Corroboration — findings cross-checked against independent sources before release.

Frameworks are grounded in external standards: CVSS for severity, MITRE where failure mechanisms map, recognized industry baselines for loss and recovery context.

The defensibility score is central. It measures how completely a finding can be reproduced from public and forensic data alone — no privileged access, no unverifiable testimony. A high-tier report is one a reasonable reviewer could reconstruct independently and reach the same conclusion.

We do not disclose private methods, proprietary tooling, or sources. We disclose the standard every report is held to: evidence that is observable, classification that is consistent, conclusions defensible on their own terms.

FC-CLASS-001
Cross-Chain State Validation Failure
Failure to validate cross-chain state, allowing an attacker to forge proofs or bypass relay node consensus mechanisms. CVSS 9.0–10.0.
CRITICAL
FC-CLASS-002
Privileged Key Compromise
Compromise of admin or governance private keys, enabling full protocol control without significant exploit cost. CVSS 8.5–10.0.
CRITICAL
FC-CLASS-003
Oracle Price Manipulation
Manipulation of price oracles enabling forced liquidations or undercollateralized borrowing. CVSS 7.0–8.9.
HIGH
FC-CLASS-004
Reentrancy
Recursive calls exploiting execution order before state updates to drain funds. CVSS 8.0–10.0.
CRITICAL
FC-CLASS-005
Access Control
Insufficient access controls on critical functions permitting unauthorized calls. CVSS 7.0–10.0.
CRITICAL
FC-CLASS-006
Economic Design Failure
Flaws in protocol economic mechanics (tokenomics, incentives) enabling governance attacks or destructive arbitrage. CVSS 7.0–9.5.
HIGH
FC-CLASS-007
Flash Loan Attack
Use of flash loans to manipulate protocol state within a single atomic transaction. CVSS 8.0–10.0.
CRITICAL