[Polygon] Beefy Finance - Security Rating 3

Security Rating Level: 3
Evaluation Date: September 30th, 2021

1. History & Team (Weight 20%; Score 77)

1.1 Project age (8%; 80)
Launched on Polygon in 2021 June, alive for 4 months.
1.2 Past exploits (8%; 100)
Was attacked once
1.3 Team anonymity (2%; 30)
Team are anonymous
1.4 Team experience in programming (2%; 20)
Unknown

2. Exposure (Weight 25%; Score 57.1)

2.1 Historical TVL (17.5%; 63)
Average market share in the past 2Q: 2.4%, 2.1%
Data collected from Beefy-finance Protocol: TVL and stats - DefiLlama
2.2 Industry segment (5%; 40)
Beefy Finance is a yield aggregator
2.3 Infrastructure (2.5%; 50)
Out of business nature, heavy oracles are needed for price feed

3. Audit (Weight 35%; Score 95)

Audit report available on: GitHub - beefyfinance/beefy-audits
3.1 Transparency and scope (14%; 100)
Full scope audit done, and report is public
3.2 Audit firm trust score (10.5%; 70)
Audited by Certik, DefiField, Tier 2 audit firm
3.3 Audit findings (10.5%; 80)
No critical issues were found in audit
3.4 Other credits (up to additive 5.25%; 10)
Core smart contracts audited by multiple firms, audit done before deployment

4. Code quality (Weight 15%; Score 25)

Repository on github: GitHub - beefyfinance/beefy-protocol: Solidity smart contracts
4.1 Documentation
Top level documentation does not exist. Comments are fairly sufficient to explain the code
4.2 Test
No test suites

5. Developer community (Weight 5%; Score 71)

5.1 Bug bounty program (3.5%; 80)
Exists. Reward up to $75,000
5.2 Issues raised on Github (1.5%; 50)
2 issues raised on github repository

The N-SCOSS for Compound is 70.225, level 3