Back to Leaderboard
G

Goldfinch

EthereumSubmitted March 13, 2026
45/100
Protocol Security Score
CWeak
Protocol Security Rating45%

Protocol Security — Category Scores

Smart Contract Security
55/100
Oracle & Data Integrity
48/100
Custody & Asset Backing
30/100
Redemption & Liquidity
35/100
Governance & Admin Control
42/100
Regulatory Compliance
68/100
Operational Security
36/100
Transparency & Reporting
47/100

Smart Contract Security

55/100

Completed Audits

3+ audits

100

Auditor Reputation

Reputable firms

75

Critical Vulnerabilities Found

Some resolved

50

Upgradeability Risk

Admin-controlled

40

Admin Privilege Controls

Multisig owner

60

Test Coverage

50 - 80%

65

Formal Verification

None

0

Fuzzing

Basic fuzzing

40

ERC Standard Compliance

Fully compliant

80

Audit Recurrence

Ad-hoc

40

Spell Review / Governance Review

Internal security review

60

Oracle & Data Integrity

48/100

Oracle Decentralization

2 providers

50

Price Deviation Protection

Basic threshold checks

50

Fallback Oracle System

Manual fallback

40

Manipulation Resistance

Moderate safeguards

50

Custody & Asset Backing

30/100

Custody Provider

Third-party (non-regulated)

35

Proof of Reserves

Self-reported

25

Redemption Guarantee

Best effort

30

Insurance Coverage

No insurance

0

Redemption & Liquidity Safety

35/100

Redemption Mechanism

Manual / ad-hoc

25

Liquidity Buffer

Below 5%

30

Governance Risk

42/100

Emergency Shutdown Controls

Admin-only pause

45

Timelock Delay

Under 24 hours

30

Compliance & Transfer Restrictions

68/100

KYC Gating

Required KYC for all

80

Whitelist Enforcement

On-chain enforced

85

Jurisdiction Restrictions

Basic geo-blocking

40

Operational Security

36/100

Bug Bounty Program

Structured program

70

Incident Response Plan

Informal process

35

Monitoring Systems

Basic alerting

40

Third-Party Dependency Risk

Some dependencies reviewed

35

Operational Audit (SOC 2 / ISO 27001)

None

0

Learn More

GOLDFINCH SECURITY FAQ

Goldfinch has an RWA Protocol Security Score of 45/100 with a grade of C. This protocol-level score is evaluated across 8 risk categories: smart contract security, oracle integrity, custody, redemption safety, governance, compliance, operational security, and transparency.

Goldfinch's protocol security score of 45 is a weighted average across 8 protocol risk categories: • Smart Contract Security (20%) • Oracle & Data Integrity (15%) • Custody & Asset Backing (15%) • Redemption & Liquidity Safety (10%) • Governance Risk (10%) • Compliance & Transfer Restrictions (10%) • Operational Security (10%) • Transparency & Proof Systems (10%) Each protocol category is scored 0–100 and multiplied by its weight to produce the overall score.

A protocol security grade of C means Goldfinch has notable areas requiring protocol security improvements. Review the detailed category breakdown to identify which protocol risk categories need the most attention.

The RWA Protocol Security Score of 45 (C) indicates Goldfinch's security posture relative to other RWA protocols on the leaderboard. This protocol security score should be one factor in your due diligence — also review the detailed category breakdown, consider regulatory compliance in your jurisdiction, and consult security professionals for high-value decisions. A higher protocol security score reflects stronger controls but does not constitute a guarantee of security.

Each RWA protocol is assessed across 8 risk categories: 1. Smart Contract Security — Protocol audit history, vulnerability resolution, upgradeability, admin privileges, test coverage. 2. Oracle & Data Integrity — Oracle decentralization, price manipulation protections, protocol fallback mechanisms. 3. Custody & Asset Backing — Protocol custody provider quality, multisig controls, proof of reserves, insurance coverage. 4. Redemption & Liquidity Safety — Protocol redemption mechanisms, liquidity buffers, bank-run protections. 5. Governance Risk — Protocol admin key management, token distribution, emergency controls, timelock delays. 6. Compliance & Transfer Restrictions — Protocol KYC gating, whitelist enforcement, jurisdiction restrictions. 7. Operational Security — Protocol bug bounty programs, incident response, monitoring, operational audits. 8. Transparency & Proof Systems — Protocol public financial disclosures, audit reports, on-chain asset verification.

cta-bg

WE SECURE EVERYTHING YOU BUILD.

From day-zero risk mapping to exchange-ready audits — QuillAudits helps projects grow with confidence. Smart contracts, dApps, infrastructure, compliance — secured end-to-end.

QuillAudits Logo


DeFi SecurityplumeUniswap FoundationAethiropt-collectivePolygon SPNBNB Chain Kickstart

All Rights Reserved. © 2026. QuillAudits - LLC