---
title: "Safety Scores Changelog"
canonical: "https://pharos.watch/methodology/scoring-changelog/"
description: "Safety Scores Changelog - Pharos methodology version history."
---

# Safety Scores Changelog

## v8.17 - Aggregate pool balances remain TVL evidence

**Effective:** 2026-07-13

Liquidity / Exit no longer labels balance-measured aggregate pool TVL as reserve-based AMM simulation when the retained row lacks an exact invariant, fee, output identity, and executable capacity curve.

- Balance measurement continues to improve DEX coverage and pool-quality inputs but does not by itself prove executable same-notional depth
- Aggregate measured rows use the existing generic-TVL-proxy ceiling of 60 instead of the reserve-based AMM simulation ceiling of 85
- The reserve-based AMM simulation class remains available only to exact route observations with modeled pool mechanics; P4b same-notional scoring remains inactive until its rollout gate passes
- The standalone public Liquidity Score is unchanged

## v8.16 - DEX exit scoring carries evidence quality

**Effective:** 2026-07-12

Liquidity / Exit now retains DEX coverage, measurement, effective-TVL, and deployment-access evidence and applies conservative ceilings when the published DEX score rests on reserve simulation, generic TVL proxies, synthetic fallback, or inaccessible-only coverage rather than measured executable depth.

- Report-card DEX snapshot reads preserve coverage class and confidence, evidence class, measured-balance and organic TVL, effective TVL, and aggregate deployment outcomes
- Rows without republished evidence fields and rows explicitly marked legacy remain score-neutral and parse through the existing optional raw-input contract
- Reserve-based AMM simulation is capped at 85, generic TVL proxy evidence at 60, and synthetic or fallback evidence at 55; a row with provider-inaccessible deployments and no observed deployment is capped at 45
- The standalone public Liquidity Score is unchanged; the evidence-adjusted DEX value is used only as the Safety Score effective-exit input and is exposed beside the observed score and binding evidence ceiling
- Fixed-input calibration changed 18 overall scores and 9 grades with no NR transitions; the largest moves were XSGD 80/A- to 72/B, IDRX 69/B- to 63/C+, and HOLLAR 53/C- to 48/D

## v8.15 - Dependency scoring is deterministic across cycles and unavailable upstreams

**Effective:** 2026-07-12

Dependency Risk now rejects unresolved graph cycles before publication, falls live-created cycles back to curated dependency sets, and scores fully unavailable upstreams through the same blend, weak-dependency penalty, and wrapper/mechanism ceilings used for partially unavailable exposure.

- Static self-links, duplicate edges, and unreviewed multi-asset cycles block report-card generation instead of relying on traversal order
- Live-created cycle members fall back to their current curated/manual dependency sets and are diagnosed again; an invalid fallback graph rejects snapshot publication and therefore prevents a grade-history write from that run
- Every unavailable upstream weight is scored at 70 inside the normal dependency blend, draws the existing 10-point weak-dependency penalty, and remains subject to wrapper or mechanism ceilings
- Dependency dimensions expose structured raw and normalized contributions, self-backed share, available/unavailable weights and IDs, the weak penalty, and the binding ceiling; contagion recomputation regenerates those diagnostics
- Fixed-input calibration changed two all-unavailable wrappers: Savings rUSD moved 39 to 36 without crossing a grade, and Zephyr Yield Share moved 51/C- to 47/D; 38 stale nonbinding ceiling labels were removed with no score effect, and no NR or dependency-edge changes occurred

## v8.14 - Dependency derivation rejects self-links and duplicate variant backing

**Effective:** 2026-07-12

Dependency Risk now suppresses self-referential reserve links at the adapter and canonical resolver boundaries, treats tracked variants as one serial wrapper claim on their parent instead of counting the parent's backing twice, and publishes typed dependency-source and fallback provenance.

- Frax balance-sheet mappings are subject-aware, so a coin's treasury-held own token remains visible as backing without creating an upstream self-edge
- The canonical resolver and graph builders defensively suppress self-links, while static metadata and live reserve write/read validation reject malformed, unknown, or self-referential dependency targets
- Tracked variants emit one weight-1 wrapper edge to the parent; reserve views can still show the parent's backing composition, but those slices no longer become parallel dependency weight
- Raw inputs expose dependency source, base source, mapped live weight, typed fallback reason, and score-grade live snapshot source/time while remaining backward-compatible with older cached cards
- Fixed-input all-card calibration moved FRAX from 58 to 59 and sUSDai from 59 to 57, removed two graph edges, and produced no grade crossing or NR change

## v8.13 - All-unmapped live reserve dependencies fall back to curated links

**Effective:** 2026-06-19

Dependency Risk now treats score-grade live reserve snapshots with no mapped tracked-asset links as insufficient dependency evidence when curated reserve or manual dependency links exist. Partial live mappings remain authoritative, and only the all-unmapped live case falls back to curated/manual dependency evidence.

- Live reserve slices with mapped `coinId` links still drive Dependency Risk, raw dependency inputs, topological ordering, and dependency graph edges
- Unmapped remainder inside a partially mapped live snapshot remains self-backed or non-stablecoin reserve share instead of reviving stale curated percentages
- When a score-grade live snapshot has zero mapped `coinId` links, Dependency Risk falls back to curated reserve links, then manual dependencies, before treating the asset as live-unmapped/self-backed
- The `dependencyFromLive` raw-input flag is false for fallback-derived dependencies and true only when the effective dependency set is live-derived or explicitly live-unmapped with no fallback evidence

## v8.12 - Bridge-route risk enters Decentralization

**Effective:** 2026-06-12

Reviewed bridge-route profiles now feed the Decentralization dimension through a penalty-only blend after CDP oracle scoring and before Mint Authority. L2BEAT Interop data is used as static review evidence and queue material, while live scoring consumes only curated Pharos bridgeRouteRisk metadata.

- bridgeRouteRisk metadata can now record reviewed route tier, summary, provenance, confidence, protocol evidence, and sources
- Penalty-only blend at weight 0.20: decentralization = min(current, 0.80 x current + 0.20 x bridge route score)
- Missing bridge-route reviews remain neutral and strong issuer-native or canonical routes never lift a score
- Weak external lock/mint, liquidity, intent, or opaque route reviews can drag Decentralization before the Mint Authority blend
- The L2BEAT Interop candidate queue proposes review targets, but report-card scoring has no live L2BEAT dependency
- Initial reviewed bridge-route profiles cover USDC, USDCx, USDB, and NUSD

## v8.11 - Oracle-risk profiles gain provenance and branch handling

**Effective:** 2026-06-12

Reviewed CDP oracle-risk profiles now carry review provenance, confidence, optional collateral-branch rows, and a report-card presentation object. When branch rows are present, the Decentralization oracle blend uses the weakest branch/profile score so multi-collateral CDPs cannot hide a weaker oracle path behind an aggregate label.

- oracleRisk metadata can now include reviewedAt, reviewer, confidence, and per-branch collateral/chains/source rows
- Branch-aware scoring is conservative: the lowest-scoring branch/profile tier drives the same penalty-only v8.1 oracle blend
- Report-card payloads expose a display-only oracleRisk object with summary, sources, selected branch, and inherited parent context for wrappers and variants
- A warning-only oracle-risk coverage check and an oracle-risk calibration report help finish the CDP backfill and review the 25% blend after coverage is complete
- BOLD now records WETH, wstETH, and rETH branch rows; USDS and BOLD profiles now carry review provenance

## v8.1 - CDP oracle setup enters Decentralization

**Effective:** 2026-06-12

Crypto-backed CDP stablecoins can now carry a reviewed oracle-risk profile. When present, the Decentralization dimension applies a penalty-only oracle setup blend for CDP liquidation and redemption price feeds: decentralization = min(current, 0.75 x current + 0.25 x oracle score). Robust oracle setups never lift the score, but weak, single-source, stale, or opaque feeds can drag it down.

- Oracle setup is scored only for crypto-backed CDP assets with an explicit reviewed oracleRisk profile; missing reviews and non-CDP assets remain unchanged
- The blend runs after governance and chain infrastructure, before the existing Mint Authority blend, and immutable-code CDPs are not exempt because liquidation oracles are an external dependency
- Oracle tiers score oracleless/internal setups at 100, redundant failover at 95, medianized delayed feeds at 85, standard external feeds at 75, single-source or laggy feeds at 45, and opaque/unknown setups at 20
- Report-card raw inputs now expose oracleRiskTier and oracleRiskScore for consumers that show report-card input details
- Initial reviewed metadata covers USDS (medianized-with-delay) and BOLD (redundant-with-failover); other CDP assets are unchanged until reviewed oracle profiles are curated

## v8.0 - Mint Authority Score enters Decentralization

**Effective:** 2026-06-11

The Decentralization dimension now applies a penalty-only Mint Authority blend: decentralization = min(current, 0.65 x current + 0.35 x Mint Authority Score). A weak privileged-mint path can drag the dimension down; a strong one never lifts it. Coins without a rated Mint Authority Score are unchanged.

- Penalty-only blend at weight 0.35, applied after the governance baseline, wrapper inheritance, and the chain-infrastructure penalty
- Mint Authority Score NR (missing or unresolved review) leaves the dimension untouched - a missing review never penalizes
- No separate confidence gate: the Mint Authority confidence caps (verified 100 / probable 90 / manual-review 85) already encode evidence quality inside the score
- 111 of 368 scoreable active coins move down, none up; biggest dimension drops are mint-incident and unbounded-mint protocols (DOLA 75 to 56, reUSD 55 to 39, MIM 45 to 33, USDe 45 to 38, crvUSD 85 to 77); USDT, USDC, LUSD, and BOLD are unchanged because their governance scores already reflect their mint topology
- Dimension weights, the peg multiplier, and the other four dimensions are unchanged; raw inputs now expose the standalone mintAuthorityScore input

## v7.291 - Degraded-input history guard

**Effective:** 2026-06-06

Safety Score scoring is unchanged, but degraded report-card inputs no longer create durable grade-history transitions and the compact score cache now exposes input-staleness metadata to dependent consumers.

- `snapshot-safety-grade-history` suppresses seed and transition writes when the report-card snapshot was built with stale DEX liquidity or redemption-backstop inputs
- The daily history cron records the degraded condition in cron metadata instead of persisting an `INSERT OR IGNORE` transition from stale upstream inputs
- The compact `report_card_cache` payload now carries `degradedInputs` metadata so Chain Health and other lightweight consumers can distinguish fresh scores from stale-input scores

## v7.29 - fxSAVE live redemption capacity

**Effective:** 2026-05-27

fxSAVE's Liquidity / Exit input can now consume fresh ERC-4626 live redemption capacity instead of the prior low-confidence heuristic strategy-buffer route.

- `fxsave-f-x-protocol` now uses the live reserve-sync redemption metadata emitted by its ERC-4626 adapter, reading idle fxSP capacity from the current on-chain snapshot
- Clean fresh snapshots resolve at medium model confidence, allowing the redemption backstop to contribute to effective exit liquidity and Safety Score liquidity when the standard route-status and severe-depeg gates pass
- If live fxSAVE capacity is unavailable or degraded, the route is left unrated rather than falling back to the old 20% heuristic buffer

## v7.28 - FreezeWatch curated upstream review audit

**Effective:** 2026-05-25

A full review of the active assets previously shown as FreezeWatch `No` corrects direct, possible, and upstream exposure classifications while keeping blacklist capability descriptive and unscored.

- M by M0, ISC, and USG now resolve as direct `Yes` based on Solana freeze authority or arbitrary holder-burn evidence
- DLLR, FXD, CJPY, USDQ, and USDK now resolve as `Possible` where mutable proxy, pause, manager-burn, or protocol-control paths exist without a confirmed active blacklist
- JUSD, SILK, NXUSD, LUAUSD, KRWO, and BNUSD now resolve as `Upstream` through stablecoin reserves, DAI collateral, Open Voucher redemption rails, or Stability Fund stablecoin collateral
- Curated `blacklistabilityReview.reviewedStatus: "inherited"` entries are now honored as upstream status when no direct `canBeBlacklisted` override exists, covering centralized assets whose freeze risk is backing/redemption-side rather than token-side

## v7.27 - FreezeWatch removes Dilutable admin-mint tier

**Effective:** 2026-05-24

FreezeWatch now uses a four-status freeze model: Yes, Upstream, Possible, and No. Admin mint authority is retained in the descriptive Mint Authority review instead of being mixed into freeze exposure.

- The `Dilutable` FreezeWatch/report-card status is retired; legacy snapshot reads map it into the current model for compatibility
- Former Dilutable assets are re-reviewed under freeze-only semantics: most now resolve as Upstream through collateral, custody, parent, or reserve exposure; USDN (SMARDEX) resolves as Possible; KRWO, LUAUSD, and vCRED resolve as No
- Mint Authority remains descriptive and unscored, but it is now the explicit home for privileged supply-control risk

## v7.26 - NAV wrapper peg scoring uses configured peg references first

**Effective:** 2026-05-21

NAV and savings wrappers with a configured peg reference now ignore their own appreciating share price for Safety Score peg and active-depeg caps, using the referenced base stablecoin's peg state instead.

- Yield-accruing wrapper prices above $1 no longer trigger active-depeg caps solely because the share price has appreciated
- Tracked wrappers such as fxSAVE inherit peg risk from the configured base asset, while pure NAV tokens without a valid peg reference remain neutral/NR for peg tracking
- Structural wrapper, dependency, collateral, and liquidity risks remain scored independently from the peg-reference correction

## v7.25 - Wrapper decentralization inherits from tracked parent assets

**Effective:** 2026-05-15

Tracked wrappers with a resolvable parent asset now derive Decentralization from the wrapped asset's Decentralization score, with the same wrapper-kind haircut used for dependency ceilings.

- Parent-linked wrappers such as yBOLD, sBOLD, and sfrxUSD no longer receive the old flat 10-point Decentralization score when their wrapped asset is already tracked
- Savings wrappers inherit parent Decentralization minus 3 points; strategy-vault and risk-absorption variants inherit parent minus 5; bond-maturity variants inherit parent minus 8
- Wrappers without a resolvable single tracked parent still fall back to the conservative 10-point wrapper score

## v7.24 - Capacity-aware redemption effective-exit blending

**Effective:** 2026-05-12

Liquidity / Exit now consumes Redemption Backstop v4 current-capacity semantics, scaling redemption uplift by executable capacity, model confidence, and independence from DEX liquidity.

- Eventual-only issuer or protocol routes remain visible as redemption coverage but no longer create redemption-only Safety liquidity uplift when current executable capacity is not modeled
- Redemption contribution to `effectiveExitScore` is discounted when current capacity is small relative to the modeled exit size or when route confidence is medium/low
- The diversification bonus is reserved for plausibly independent issuer rails; wrappers, same-protocol routes, same stablecoin-pool/backing paths, and unknown correlations receive no extra independence bonus

## v7.23 - sGHO and Reservoir reserve coverage refinements

**Effective:** 2026-05-12

Additional reserve-sync refinements promote clean independent snapshots for sGHO, Reservoir savings variants, USD.AI, and weekly NAV feeds without widening the score-grade evidence policy.

- sGHO now has a dedicated live reserve adapter that reads the legacy savings contract's `previewRedeem(totalSupply)` path instead of forcing the non-ERC-4626 contract through the generic wrapper adapter
- Reservoir reserve classification now maps AUSD and Steakhouse Prime USDC strategy rows from the live balance-sheet API, eliminating the prior unknown-exposure degradation for srUSD/wsrUSD when the source payload is otherwise clean
- USD.AI reserve freshness now stamps the latest scoped proof-row timestamp while retaining oldest/latest spread metadata, and mRe7YIELD allows a weekly Chainlink NAV update cadence

## v7.22 - Additional independent NAV and wrapper reserve feeds

**Effective:** 2026-05-12

More RWA NAV tokens and tracked savings wrappers now use direct independent reserve feeds instead of curated validation or weak liveness probes.

- WTGXX, VBILL, ACRED, USTBL, EUTBL, and JTRSY now use timestamped Chainlink NAV feeds for score-grade reserve freshness
- USDCV now uses the SG Forge CoinVertible reserve parser, aligning it with EURCV's independent attestation path
- sUSDD and sUSN now use ERC-4626 totalAssets()/asset() wrapper reads so their live reserve slices inherit the tracked USDD and USN parent links

## v7.21 - crvUSD direct on-chain LLAMMA reserve reads

**Effective:** 2026-05-12

crvUSD reserve scoring can now use direct Curve ControllerFactory and LLAMMA band reads with latest-state on-chain freshness instead of the timestampless Curve markets API.

- `crvusd-curve` reads LLAMMA `bands_y` collateral balances directly via Multicall3 and keeps Yield Basis exposure on the existing on-chain factory path
- `bands_x` crvUSD soft-liquidation inventory is retained in snapshot metadata instead of being counted as external collateral
- The adapter emits `freshnessMode: "not-applicable"`, allowing clean crvUSD snapshots to qualify as score-grade live reserve inputs

## v7.20 - Expanded Dilutable admin-mint classification with source provenance

**Effective:** 2026-05-11

A full tracked-universe follow-up to the Dilutable rollout expands the tier to strong uncapped admin-mint candidates and records a contract-source link for every Dilutable override.

- DAI, DOLA, FPI, PHT, USDD, USDe, USDN (SMARDEX), crvUSD, REUSD, USDU, and XAI now resolve as `Dilutable` after verified token-source review found explicit uncapped admin mint authority
- Every `canBeBlacklisted: "dilutable"` metadata override now carries `canBeBlacklistedSource`, and the asset schema rejects Dilutable entries without a source link
- The homepage table and stablecoin detail hero expose the Dilutable source link directly on the status label

## v7.19 - Dilutable freezability tier and upgradeable-proxy / admin-mint audit

**Effective:** 2026-05-11

A re-audit of 22 stablecoins marked `Freezable: No` introduces a new `Dilutable` tier for tokens whose admin can mint without bound, and reclassifies five coins to `Yes` after finding upgradeable proxies or active admin freeze surfaces.

- New `Dilutable` tier sits between `No` and direct `Yes`: the token has no transfer freeze or blacklist, but the issuer can mint unbounded supply and effectively seize value through dilution
- vCRED, LUAUSD, and srUSD now resolve as `Dilutable` because their token contracts expose `Ownable` mint or `AccessControl` minter-grant authority without supply caps
- HBD, mRe7YIELD, FEUSD (Felix), USDQ (Quill), and USDK (Orki) now resolve as direct `Freezable: Yes` after the audit confirmed transparent upgradeable proxies, `Blacklistable`/`Pausable` mixins, or chain-native witness-seizure precedent (HF23)
- BabelFish XUSD's explicit `canBeBlacklisted: false` override is removed so reserve-based inheritance from its bridged USDT/USDC basket now flows through to `Freezable: Upstream`
- DJED, IUSD (Indigo), HYUSD, FXD, FUSD (Zano), NXUSD, SILK, DLLR, USG, LUSD, BOLD, CJPY, and JUSD (Juicedollar) keep their defensible `Freezable: No` after token-contract or chain-level review

## v7.18 - Redemption freshness and daily-limit eligibility gates

**Effective:** 2026-05-10

Liquidity / Exit now consumes the stricter redemption-backstop live telemetry policy, so unverified nested redemption freshness is excluded unless route-specific lower-bound approval exists and live daily limits cap usable scoring capacity.

- Severe active-depeg survivability now requires direct live capacity kind evidence in addition to live-direct confidence, dynamic source mode, permissionless access, and atomic/immediate settlement
- Live reserve adapters can surface redemption constraints such as queue depth, settlement delay, daily limits, and minimum redemption size without those fields being mistaken for unconditional Safety eligibility
- Daily redemption limits reduce the capacity score used by redemption-backed Liquidity / Exit while leaving raw immediate capacity visible in the redemption API

## v7.17 - USD3 centralized-collateral dependency correction

**Effective:** 2026-05-07

USD3 / Web 3 Dollar is reclassified from DeFi to CeFi-dependent because its Reserve Protocol DTF basket is concentrated in centralized stablecoin-derived collateral.

- `usd3-reserve-protocol` now uses governance `centralized-dependent` instead of `decentralized`
- The correction reflects Savings USDS, Aave USDC, wrapped Compound USDCv3, and Steakhouse USDC strategy exposure in the curated and live reserve configuration
- Scoring weights, thresholds, reserve risks, and live reserve adapter behavior are unchanged

## v7.16 - Follow-up freezability classification audit

**Effective:** 2026-05-06

A follow-up review of six disputed `Freezable: No` classifications moves HomeCoin to `Possible` and leaves the other reviewed assets unchanged.

- HomeCoin now resolves as `Freezable: Possible` because the holder-facing HOME token is a transparent upgradeable proxy with an active proxy-admin upgrade surface
- HBD, vCRED, Freedom Dollar, LUAUSD, and NXUSD remain `Freezable: No` after reviewing their native protocol or verified contract surfaces for freeze, blacklist, pause, denylist, arbitrary burn, or upgrade controls
- Owner mint authority and user/allowance burn functions remain supply-control signals, not freeze signals, unless the contract also exposes holder-facing transfer gates, arbitrary burns, blacklist controls, or mutable holder-control surfaces

## v7.15 - Direct freezability metadata audit

**Effective:** 2026-05-05

The resolved `Freezable: No` cohort was reviewed against token-level freeze, denylist, blacklist, pause, and role-burn controls, moving confirmed direct-control assets out of the unfreezable bucket.

- JupUSD, eSui Dollar, MAI, JUSD, Alpha Partner USDA, Ring USDR, DOC, USDRIF, and Nest inALPHA now resolve as direct `Freezable: Yes` when their holder-facing token or vault exposes freeze, denylist, blacklist, or arbitrary role-burn controls
- sBOLD and Enosys CDP now resolve as `Freezable: Possible` because the audited contracts expose direct vault pause or mutable branch-control surfaces rather than a current address-level blacklist
- The remaining resolved `No` cohort was left unchanged where no direct holder-facing freeze, blacklist, pause, denylist, or arbitrary burn surface was confirmed

## v7.14 - Live reserve dependencies align with scoring

**Effective:** 2026-04-24

Score-grade live reserve slices with tracked `coinId` links now drive Dependency Risk, raw dependency inputs, topological ordering, and the public dependency graph together.

- Report-card Dependency Risk now uses the same fresh independent live reserve slices already eligible for collateral-quality scoring when those slices carry tracked stablecoin links
- Unmapped live reserve share remains implicit self-backed or non-stablecoin exposure, so live snapshots no longer fall back to stale curated dependency percentages for that remainder
- The public dependency graph now publishes the effective dependency edges used by the snapshot, while tracked variant parent wrapper edges remain synthetic and de-duplicated

## v7.13 - Reserve-driven blacklist risk moves to Upstream

**Effective:** 2026-04-22

`Possible` blacklist labeling is now reserved for curated direct token or vault freeze controls, while reserve- and custody-driven exposure resolves as `Upstream`.

- Shared blacklist resolution now classifies any reserve-side, backing-side, custody-side, or parent-asset freeze path as `inherited` / Upstream instead of keeping a separate sub-threshold `possible` bucket
- Curated direct-control overrides remain only on assets whose holder-facing token or vault still exposes a pause, freeze, or blacklist surface, including dormant controls that are currently disabled until governance or admin action
- This re-buckets reserve-driven cases such as strategy wrappers, PSM-backed assets, and custody-heavy tokens without changing the existing tracked-variant dependency ceilings or parent-overall cap behavior

## v7.12 - sBOLD joins tracked risk-absorption variants

**Effective:** 2026-04-22

The tracked parent-variant framework now includes K3 sBOLD as a `risk-absorption` child of BOLD because Liquity Stability Pool loss-absorption dominates the wrapper's extra risk surface.

- `sbold-k3-capital` now declares canonical `variantOf = bold-liquity` and `variantKind = risk-absorption`, so the relationship is visible across Safety Scores, detail pages, homepage variant filters, and the dependency graph
- sBOLD now joins the tracked risk-absorption cohort beside `stUSDS` and `stkGHO.v1`, inheriting the existing parent-minus-5 dependency ceiling and parent-overall cap
- This phase keeps the current parent-linked `pegReferenceId` path for sBOLD, so severe parent depegs still constrain the child until independent NAV/peg handling ships later

## v7.11 - Strategy-vault children join the tracked variant framework

**Effective:** 2026-04-22

The tracked parent-variant framework now covers the four highest-confidence strategy-vault children whose user expectation is still direct exposure to a tracked parent stablecoin.

- `sUSDai`, `msY`, `sAID`, and `stcUSD` now declare canonical `variantOf` / `variantKind` metadata as tracked `strategy-vault` children of their already-tracked parent stablecoins
- Dependency Risk now applies the same parent-minus-5 wrapper ceiling to tracked `strategy-vault` children that already applied to tracked risk-absorption wrappers, while the existing parent-overall cap still prevents the child from outscoring the parent card
- The homepage variant owner on `/` now exposes a `Strategy` filter state alongside the existing tracked, savings, risk-absorption, and bond cohorts
- This rollout keeps the current parent-linked `pegReferenceId` path for these four strategy-vault children, so severe parent depegs still constrain the child until independent NAV/peg handling ships in a later phase

## v7.10 - Bond-maturity variants join the parent-linked wrapper framework

**Effective:** 2026-04-22

The tracked variant framework now covers bond-maturity wrappers, starting with bUSD0 as a bond leg over USD0.

- `bUSD0` now declares canonical `variantOf` / `variantKind` metadata as a `bond-maturity` child of `USD0`, so the relationship is visible across Safety Scores, detail pages, the homepage filters, and the report-card dependency graph
- Dependency Risk applies a stricter wrapper ceiling of parent minus 8 points for `bond-maturity` variants, while the existing parent-overall cap still prevents the child from outscoring the parent card
- The homepage variant owner on `/` now exposes a `Bond` filter state alongside the existing tracked, savings, and risk-absorption cohorts, and detail pages link back into that owner instead of introducing a dedicated variant route family

## v7.09 - Tracked wrapper and staked variants become explicit parent-linked cards

**Effective:** 2026-04-22

Tracked savings and risk-absorption wrappers now carry an explicit parent relationship in Safety Scores, so dependency ceilings, parent caps, and stressed recomputation no longer depend on reserve-shape quirks.

- Nine tracked wrapped or staked stablecoins now declare canonical `variantOf` / `variantKind` metadata and contribute a synthetic `wrapper` edge from parent to child in dependency scoring, topological ordering, and the dependency graph
- Dependency Risk applies a wrapper ceiling of parent minus 3 points for tracked savings wrappers and parent minus 5 points for tracked risk-absorption wrappers, while legacy non-variant wrapper dependencies keep the existing parent minus 3 behavior
- Tracked variants cannot outscore their parent overall card: live cards and stressed recomputation both cap the child at the parent's overall score and expose `overallCapped`, `uncappedOverallScore`, `rawInputs.variantParentId`, and `rawInputs.variantKind` for transparency
- Active severe depeg caps now follow inherited `pegReferenceId` links for tracked wrappers, so a parent depeg continues to cap the child even when the wrapper has no direct open-event row of its own

## v7.08 - Strategy reserve tier clarification

**Effective:** 2026-04-21

Reserve-risk tiering now distinguishes transparent spot or wrapped market exposure from actively managed strategy books; externally managed market-neutral, basis, perp, LP, private-deal, or custody-dependent strategy reserves are high unless stronger granular evidence shows the slice is only an idle stablecoin or cash-equivalent buffer.

- Delta-neutral wording no longer implies a medium reserve-risk tier by itself
- Transparent spot or wrapped market exposure can remain medium when the slice is mainly asset exposure and custody/counterparty risk is handled by the custody dimension
- Externally managed market-neutral, basis, perp, LP, private-deal, or custody-dependent strategy reserves are high unless stronger granular evidence shows the slice is only an idle stablecoin or cash-equivalent buffer
- avUSD's 0xPartners-managed strategy and loss-absorption reserve slices move from medium to high, lowering its reserve-derived collateral quality while leaving its existing unregulated-custody penalty intact

## v7.07 - Stale DEX liquidity stays usable for Exit scoring

**Effective:** 2026-04-18

Liquidity / Exit and the redemption-backstop snapshot both now reuse the last-known DEX liquidity score when its freshness runway has elapsed, instead of suppressing it and cascading documented offchain-issuer routes (USDC, USDP, USDT, GUSD, …) to NR on routine sync-dex-liquidity cron lag.

- Reverses the v6.1 rule that stripped stale DEX liquidity out of `effectiveExitScore`; the score is now computed from the last-known DEX snapshot regardless of age, and staleness is surfaced only via `liquidityStale` and `inputFreshness.dexLiquidity.stale`
- `/api/redemption-backstops.effectiveExitScore` stays populated during stale windows under the same freshness policy as the report-card path, instead of diverging to `null`; the redemption-backstop cron still marks its run `degraded` and emits `metadata.liquidityStale = true` for operational visibility when upstream DEX input is stale. Note that the cron field remains a raw best-path blend and still differs numerically from the report-card `dimensions.liquidity.score`, which applies Safety Score eligibility gates on top
- Absent DEX snapshots (loader rejects or empty table) still produce `liquidityScore = null` and trigger the documented offchain-issuer primary-market-floor exclusion as before; the rule only distinguishes between 'present but old' and 'truly missing'

## v7.06 - GHO residual decomposition

**Effective:** 2026-04-16

The GHO reserve adapter now decomposes residual issuance across active facilitators and routes unmapped labels through the standard material-unknown-exposure validator, replacing the GHO-specific aggregated-residual warning.

- Aave V3 direct-minter facilitators contribute medium-risk residual slices; FlashMinter and unmapped facilitators contribute high-risk slices
- Unmapped residual share accumulates into metadata.unknownExposurePct so material unknown exposure can degrade the GHO sync consistently with other reserve adapters
- If the facilitator registry is unreadable in a run, the entire residual is treated as unknown so the fail-closed unknown-exposure policy still applies
- Direct GhoReserve / GhoDirectFacilitator / RemoteGSM reads remain a follow-up tracked in docs/trackers/reserve-coverage.md pending verified Aave deployment addresses

## v7.05 - Primary-market exit bonus

**Effective:** 2026-04-16

Liquidity / Exit now lets documented offchain issuer redemption add a DEX-gated primary-market exit bonus without treating eventual redemption as a standalone liquidity substitute.

- Documented-bound offchain issuer routes with eventual-only semantics can contribute only the diversification bonus when a DEX liquidity score is already present
- Issuer redemption can no longer replace missing DEX liquidity; no-DEX assets still remain unrated for Liquidity / Exit unless they have separate immediate-bounded redemption evidence
- Low-confidence, impaired, stale, route-limited, and severe-depeg-ineligible redemption rows remain excluded from Safety Score liquidity uplift

## v7.04 - Redemption freshness runway

**Effective:** 2026-04-15

Liquidity / Exit now keeps current redemption backstops through normal 4-hourly cron lag instead of self-suppressing immediately after one sync interval.

- Report-card redemption freshness now follows a 2x 4-hourly sync runway before suppressing redemption inputs
- Resolved medium- and high-confidence immediate-bounded redemption backstops can continue to improve Liquidity / Exit between normal 4-hourly syncs
- Missing, materially stale, low-confidence, impaired, eventual-only, and severe-depeg-ineligible routes remain excluded from Safety Score liquidity uplift

## v7.03 - USTB live liquidity capacity

**Effective:** 2026-04-15

Liquidity / Exit can now use USTB's current Superstate liquidity capacity while keeping NAV/AUM separate from immediate exit capacity.

- USTB now uses Superstate's current Circle USD and USDC RedemptionIdle liquidity as bounded redemption capacity
- USTB's on-chain NAV oracle remains reserve evidence and is not treated as immediate liquidity
- Malformed or unavailable Superstate liquidity telemetry fails closed to no redemption uplift rather than falling back to NAV/AUM

## v7.02 - frxUSD live redemption capacity

**Effective:** 2026-04-15

Liquidity / Exit can now use frxUSD's fresh Frax balance-sheet redemption capacity while preserving route-status and capacity-ratio fail-closed guards.

- frxUSD no longer relies on a static full-supply eventual redemption model for Safety Score liquidity uplift
- Live route-status telemetry from reserve adapters can suppress redemption uplift when a route is paused, degraded, or cohort-limited
- Live capacity rows with a nested capacity amount no longer reuse flat reserve-composition ratios as supply-relative capacity ratios

## v7.01 - Safety-eligible redemption tiers

**Effective:** 2026-04-15

Liquidity / Exit now distinguishes standalone redemption-route quality from Safety Score-eligible exit capacity.

- Eventual-only redemption routes remain visible on redemption surfaces but no longer uplift the Safety Score Liquidity / Exit dimension by themselves
- Queue-like redemption routes can still contribute when resolved and current, but their Safety Score contribution is capped before blending with DEX liquidity
- Immediate-bounded and live-direct or validated-live routes continue to improve Liquidity / Exit when they are resolved, fresh, non-low-confidence, and not impaired by route-availability evidence

## v7.0 - Independent NAV and bundle-oracle reserve feeds

**Effective:** 2026-04-15

Additional proof-style reserve feeds now use independent timestamped sources instead of weak single-asset liveness probes, including Chainlink-style NAV oracles, Frax's v2 balance sheet, and USD1's bundle oracle.

- USYC and TBILL now use Chainlink-style NAV oracles with verified oracle timestamps and 4-day business-day freshness windows
- FRAX now uses the Frax v2 balance-sheet API with verified as-of timestamps and explicit token risk mapping
- USD1 now uses its Chainlink bundle oracle for timestamped reserve size and live supply comparison
- AUSD and DGLD remain outside live collateral passthrough for now because their discovered feeds do not currently provide payload-native freshness inside the live gate

## v6.99 - Asymmetry USDaf live reserve freshness promotion

**Effective:** 2026-04-15

USDaf's Asymmetry reserve feed now preserves the protocol API timestamp and normalizes branch symbols before risk classification, allowing clean fresh snapshots to qualify for live collateral passthrough.

- The Asymmetry adapter now emits verified source freshness from the protocol API timestamp when available
- Branch-name normalization prevents casing-only symbols such as wBTC from degrading the feed as unknown exposure
- The global live collateral gate remains unchanged: only independent ok-status snapshots with scoring-eligible freshness can drive report-card collateral scoring

## v6.98 - Timestamp-backed reserve feeds restored to collateral passthrough

**Effective:** 2026-04-15

Several live reserve adapters now consume source timestamps already exposed by their upstream dashboards or disclosure pages, allowing clean fresh snapshots to qualify for collateral-quality passthrough without weakening the global freshness gate.

- Circle, M0, Mento, and USD.AI reserve adapters now emit verified freshness when their upstream source exposes a usable disclosure or update timestamp
- Yuzu and Re Protocol reserve feeds now have explicit mappings for newly observed buckets/tokens, preventing clean fresh feeds from being degraded as unknown exposure
- OpenEden reserve sync now sends browser-style origin hints to reduce upstream transport failures while preserving the existing verified timestamp validation
- Feeds that still lack trustworthy source freshness remain detail-visible only; the report-card live collateral gate still requires independent evidence, ok sync status, and verified or not-applicable freshness

## v6.97 - Active-depeg caps use event peak and stale redemption inputs are suppressed

**Effective:** 2026-04-15

Safety Score active-depeg handling now uses the open event's peak severity for final caps, removes the legacy peg-dimension cap, suppresses stale redemption rows, and makes dependency/stress behavior more conservative.

- Peg Stability now passes through computePegScore() directly during active depegs instead of applying an extra legacy 65-point cap before the multiplier
- RawDimensionInputs.activeDepegBps now uses the open depeg event peak, aligning final Safety Score caps with the severe-redemption impairment source
- Report-card Liquidity / Exit suppresses stale redemption-backstop snapshots instead of reusing old redemption uplift indefinitely
- Partially unavailable upstream dependency scores are scored at the existing 70-point unavailable fallback for their declared weights rather than being treated as self-backed
- The contagion stress test now propagates downstream dependency recomputations transitively instead of stopping at direct dependents

## v6.96 - Severe active depegs disable weak redemption uplift

**Effective:** 2026-04-14

Liquidity / Exit no longer accepts static or non-live-direct redemption uplift during severe active depegs unless current live-open redemption evidence exists.

- Redemption backstop uplift now requires a resolved non-low-confidence route that is not impaired by route availability or severe active-depeg contradiction
- Active depegs at or above 2500 bps disable static, documented-bound, live-proxy, issuer/API, queue, and estimated redemption uplift until live-open evidence returns
- Live-direct, dynamic, permissionless, atomic or immediate redemption routes can still contribute to Liquidity / Exit during a severe depeg because they provide current direct exercisability evidence

## v6.95 - Direct inherited freeze risk now counts custodied BTC wrappers and issuer-seizable collateral

**Effective:** 2026-04-07

Blacklistability attribution now treats centralized-custody BTC wrappers, tokenized gold, and issuer-seizable tokenized collateral as direct reserve-side freeze exposure when they dominate a stablecoin's backing mix.

- Shared isBlacklistable() logic now counts centralized-custody BTC wrappers such as WBTC and cbBTC as direct reserve-side freeze exposure instead of only possible exposure
- Issuer-seizable tokenized collateral such as tokenized gold and reviewed tokenized share symbols now also counts as direct inherited freeze risk when present in reserve labels
- Coins with these reviewed collateral assets gained inherited-freeze treatment in this phase; v7.13 later superseded the reserve-weight gate with the current any-reserve Upstream policy

## v6.94 - NAV wrappers can inherit peg risk from a referenced base stablecoin

**Effective:** 2026-04-06

NAV tokens that are explicit wrappers over a stablecoin can now inherit peg stability from a configured base asset instead of receiving an automatic neutral peg multiplier.

- Configured NAV wrappers can now use a referenced base stablecoin's pegScore in report-card scoring when their own NAV share price is not the right peg-tracking surface
- Pure NAV fund-share tokens with no configured peg reference still remain pegScore = NR and keep the neutral multiplier treatment
- sUSDai now inherits USDAI peg risk, preventing the stronger v6.93 peg multiplier from becoming a free pass for wrapped stablecoin NAV structures

## v6.93 - Steeper peg multiplier + active depeg grade cap

**Effective:** 2026-04-05

Peg multiplier exponent raised from 0.2 to 0.4 so peg stability impacts grades more meaningfully. Active depegs above 1000 bps now cap the overall score at D; above 2500 bps caps at F.

- PEG_MULTIPLIER_EXPONENT changed from 0.2 to 0.4 — coins with pegScore 80+ see ~1-5% more reduction; coins with pegScore < 30 see 19-34% more reduction
- New graduated active depeg cap: >= 2500 bps (25%) caps overall at 39 (F), >= 1000 bps (10%) caps overall at 49 (D)
- Active depeg severity (activeDepegBps) added to RawDimensionInputs for reproducibility in stressed grades and frontend

## v6.92 - Direct Liquity v1 reserve observation for LUSD

**Effective:** 2026-04-04

LUSD now uses direct on-chain Liquity v1 system-collateral telemetry instead of the generic proof-style liveness probe, so fresh clean snapshots qualify as independent live reserve evidence.

- LUSD live reserve sync now reads TroveManager getEntireSystemColl() and getEntireSystemDebt() directly from Ethereum
- The reserve detail badge for clean authoritative LUSD snapshots now resolves to live instead of proof because the adapter is classified as independent single-bucket evidence
- Weak single-asset probes remain excluded from collateral-quality passthrough; this is a targeted Liquity v1 adapter upgrade rather than a reclassification of the generic family

## v6.91 - Reserve-side blacklist exposure heuristics

**Effective:** 2026-03-30

Blacklistability attribution began scanning curated and live reserve labels plus reserve-rail text for stablecoin, wrapper, and CEX custody clues; v7.13 later promoted any matched reserve path to Upstream.

- Shared isBlacklistable() logic started surfacing reserve-side blacklist and custodial-freeze clues instead of falling through to no
- Curated and live reserve names started sharing the same direct blacklist clue detection instead of relying only on coinId or explicit blacklistable flags; v7.13 later removed the reserve-weight gate
- Only coins with no explicit blacklist function, no reserve-side blacklist clues, and no CEX custody signal remain in the no bucket unless an explicit false override applies

## v6.9 - Explicit inherited blacklistability

**Effective:** 2026-03-30

Blacklistability attribution now separates mutable-contract risk from inherited collateral freeze risk, and no longer treats centralized-dependent governance as enough evidence on its own.

- Shared isBlacklistable() logic no longer defaults centralized-dependent governance to possible
- Reserve-heavy downstream freeze exposure now resolves to inherited instead of possible-inherited
- Inherited detection became an explicit upstream-freeze category using curated reserve-slice blacklistable markers and upstream stablecoin coinId links; v7.13 later removed the reserve-weight gate

## v6.8 - On-chain reserve freshness alignment

**Effective:** 2026-03-25

Direct latest-state reserve adapters now explicitly mark on-chain freshness as not-applicable, allowing clean independent branch-balance snapshots to participate in collateral-quality passthrough again.

- evm-branch-balances snapshots now carry freshnessMode=not-applicable instead of remaining timestamp-less and implicitly ineligible
- Clean branch-balance reserve feeds can override curated collateral quality again when their latest reserve sync status is ok
- This is an implementation-alignment change to the existing v6.6 freshness policy, not a new scoring rule family

## v6.7 - CeFi-dependent blacklistability fallback

**Effective:** 2026-03-25

Blacklistability attribution now defaults centralized-dependent stablecoins to possible unless an explicit override or inherited-reserve classification is more specific.

- Shared isBlacklistable() logic now resolves centralized-dependent governance to possible instead of false
- Inherited reserve exposure still takes precedence, preserving possible-inherited for reserve-heavy dependency cases
- Explicit canBeBlacklisted overrides remain authoritative, including explicit false exceptions

## v6.6 - Timestamp-backed live reserve scoring gate

**Effective:** 2026-03-24

Collateral-quality passthrough now excludes timestamp-less or explicitly unverified live reserve feeds unless the feed carries verified freshness or is intrinsically on-chain.

- Independent live reserve feeds now need scoring-eligible freshness evidence in addition to fresh authoritative ok-status snapshots
- Snapshots with freshnessMode=unverified no longer override curated collateral quality in report-card scoring
- Direct on-chain reserve adapters can still qualify when freshness is marked not-applicable

## v6.5 - Clean independent live reserve passthrough

**Effective:** 2026-03-22

Collateral-quality passthrough now requires clean independent live reserve evidence, excluding weak probes and warning-bearing snapshots from Safety Score scoring.

- Live collateral passthrough now requires a fresh authoritative snapshot whose latest reserve sync status is ok
- The live reserve adapter registry now separates reserve shape (sourceModel) from evidence strength (evidenceClass)
- single-asset and tether style feeds now remain detail/status-visible only; they no longer override curated collateral scoring
- Source-age and material unknown-exposure warnings now automatically keep affected snapshots out of collateral passthrough

## v6.4 - Live Liquity redemption fee telemetry

**Effective:** 2026-03-22

The liquidity dimension keeps the same structure, but Liquity-style formula routes can now use current on-chain redemption fees when live reserve telemetry is available.

- LUSD and BOLD now reuse live reserve sync metadata for current redemption fee bps instead of always sitting in the generic formula-fee bucket
- These routes remain labeled as formula-based and eventual-only; Pharos still does not present them as having an immediate redeemable buffer
- If live fee telemetry is unavailable, Safety Score liquidity falls back to the prior reviewed-formula treatment

## v6.3 - Documented-bound Liquity redemption confidence

**Effective:** 2026-03-22

Fully on-chain Liquity redemption routes with documented full-system redeemability now qualify as stronger exit-liquidity evidence without being presented as immediate buffer capacity.

- LUSD and BOLD now use documented-bound eventual redemption capacity instead of heuristic supply-full modeling
- These routes remain eventual-only on detail surfaces, but they can now uplift the Safety Score liquidity dimension
- Liquity-style base-rate fee formulas remain reviewed formula inputs rather than fixed-fee assumptions

## v6.2 - Independent live reserve contract tightening

**Effective:** 2026-03-22

Collateral-quality passthrough now only uses fresh authoritative independent live reserve feeds, preventing validated-static probes from overriding curated scoring and allowing single-bucket live feeds to count.

- Live collateral passthrough now requires a fresh authoritative snapshot matched to reserve_sync_state, not just a fresh reserve_composition row
- Only dynamic-mix and single-bucket live feeds can override curated collateral quality; validated-static feeds stay reserve-detail/status only
- Single-bucket live feeds now contribute to collateral drift and curated-fallback tracking instead of being excluded by an implicit >=2-slice gate

## v6.1 - Redemption confidence gating and capacity semantics

**Effective:** 2026-03-22

Liquidity scoring now distinguishes strong redemption evidence from heuristic routes and stops presenting eventual issuer redemption as immediate buffer capacity.

- Low-confidence redemption backstops no longer uplift the Safety Score liquidity dimension
- Stale DEX liquidity no longer produces blended effective-exit inputs in report-card scoring
- Redemption detail output now separates eventual redeemability from immediate redeemable capacity

## v6.0 - Custody model tiers, mature-alt-l1, 2-factor Resilience

**Effective:** 2026-03-21

Four structural changes: 6-tier custody model replaces 3-tier, new mature-alt-l1 chain tier for Solana/BNB, Resilience becomes 2-factor (blacklist descriptive only), 5-band chain penalty with wrapper exemption.

- Custody model split: onchain/institutional-top/institutional-regulated/institutional-unregulated/institutional-sanctioned/cex (was onchain/institutional/cex)
- USDC, BUIDL, EURC, frxUSD, DAI, USDS classified as institutional-top (80); sanctioned custodians score 5
- Mature-alt-l1 tier (score 45) for Solana and BNB Chain; JupUSD, USX, hyUSD, lisUSD, CASH reclassified
- Resilience is now (collateral + custody) / 2; blacklist reported but no longer affects score
- 5-band chain penalty: ≥80→0, ≥60→-10, ≥40→-25, ≥20→-40, <20→-60; wrappers exempted
- Deployment multipliers: canonical-bridge 0.85→0.90, native-multichain 0.40→0.75

## v5.9 - Classification corrections: centralized-custody DeFi coins

**Effective:** 2026-03-20

Three DeFi-classified coins with >50% centralized custody exposure reclassified to centralized-dependent based on live reserve data.

- meUSD, ALUSD, BtcUSD reclassified from decentralized to centralized-dependent
- ALUSD correction: 65% USDC+USDT direct exposure (reverts erroneous v4.1 reclassification)
- meUSD and BtcUSD: live reserves confirm 100% custodial BTC variants (WBTC, BTCB, cbBTC, SolvBTC)

## v5.8 - Live reserve passthrough for collateral quality

**Effective:** 2026-03-14

Collateral quality scoring now consumes live reserve snapshots when available, using hourly data from reserve_composition instead of curated metadata.

- Coins with liveReservesConfig use fresh (<48h) live snapshots for collateral quality instead of curated metadata
- Delta alert fires when live-derived score diverges from curated by >15 points
- Dependency inference remains on curated data (live slices lack coinId links)

## v5.7 - Canonical ETH wrapper reserve alignment

**Effective:** 2026-03-13

Reserve-derived collateral quality now treats direct ETH and canonical wrapped ETH as the same very-low-risk asset class.

- Canonical WETH no longer falls into the generic wrapped-asset bucket in the reserve-asset risk map
- Curated reserve metadata and live reserve-adapter overrides aligned for coins exposing ETH/WETH slices

## v5.6 - Exit-liquidity integration

**Effective:** 2026-03-12

Safety Score liquidity now evaluates modeled exit quality via redemption backstops, not just raw DEX depth.

- Liquidity dimension uses effectiveExitScore, preserving DEX liquidity as floor while redemption quality can improve it
- Route-family caps prevent queue-based and offchain issuer systems from appearing unrealistically liquid

## v5.5 - Peg score fairness for young coins

**Effective:** 2026-03-01

Three peg-scoring fixes prevent young coins with repeated brief depegs from being over-scored.

- Tracking window capped to coin age via coinTrackingStart()
- Severity magnitude floor ensures each depeg contributes a minimum penalty
- Steeper active-depeg penalty: max(5, absBps/50), capped at 50

## v5.4 - No-liquidity penalty

**Effective:** 2026-02-28

When Liquidity is NR (no DEX data), overall score receives a 10% penalty instead of redistributing weight.

- NR liquidity now applies final *= 0.9 after peg multiplier instead of inflating other dimensions

Commits: `14131fa`

## v5.3 - Remove chain infra from Resilience

**Effective:** 2026-02-28

Chain infra double-counting fixed: removed from Resilience sub-factors, now exclusively in Decentralization.

- Resilience becomes a 3-factor model (collateral quality, custody model, blacklist capability)

Commits: `8c060b3`

## v5.2 - Immutable-code governance tier

**Effective:** 2026-02-28

Added immutable-code as highest GovernanceQuality tier (score 100) for protocols with no admin keys or upgrade path.

- LUSD, BOLD now score 100 in governance quality; exempt from chain infra penalty

Commits: `c6c0b77`

## v5.1 - Regulated-entity tier + blacklist softening

**Effective:** 2026-02-28

Blacklist scores softened (blacklistable 0->33) and regulated-entity governance tier added for licensed issuers.

- Blacklist scoring: blacklistable 0->33, possible 50->66, not-blacklistable stays 100
- Regulated-entity tier (score 40) auto-promoted from single-entity when regulator+license+independent audit
- Grade thresholds lowered another 5 points (A+ >= 87)

Commits: `38cbe20`, `86b8ce1`, `01ed304`, `fc6cd6c`

## v5.0 - GovernanceQuality + universal dependency scoring

**Effective:** 2026-02-28

Decentralization moved from 3-tier to 6-tier GovernanceQuality. Dependency scoring became universal (not CeFi-only).

- GovernanceQuality tiers: dao-governance=85, multisig=55, single-entity=20, wrapper=10
- All coins with upstream dependencies now scored, not just centralized-dependent
- Chain infra scored as ChainTier x DeploymentModel multiplier in Resilience

Commits: `e915623`, `e516bbf`, `d4dd044`, `0b603d2`, `83a540a`

## v4.1 - Liquidity weight increase + reclassifications

**Effective:** 2026-02-27

Liquidity weight raised to 30% as the most defining stablecoin attribute. Five coins reclassified to decentralized.

- Weights: Liquidity 25->30%, Resilience 25->20%
- crvUSD, FRXUSD, USR, GYD, ALUSD reclassified from centralized-dependent to decentralized

Commits: `122733d`

## v4.0 - Peg stability becomes a multiplier

**Effective:** 2026-02-27

Biggest structural change: peg stability removed from weighted dimensions and applied as a post-hoc power-curve multiplier.

- Peg applied as final *= (pegScore/100)^0.20 instead of 25% dimension weight
- Grade thresholds lowered 5 points to compensate for structural deflation

Commits: `6ed2ec9`

## v3.3 - Reserve-derived collateral quality

**Effective:** 2026-02-27

For coins with curated reserves arrays, collateral quality is now a weighted average of reserve risk tiers instead of an enum fallback.

- Reserve risk tiers: very-low=100, low=75, medium=50, high=25, very-high=5
- Decentralization weight raised 10->15%

Commits: `25602d1`, `1cd1bb9`

## v3.2 - Dependency type ceilings

**Effective:** 2026-02-27

New DependencyType field (wrapper/mechanism/collateral) with ceilings preventing wrappers from scoring above upstream.

- Wrapper ceiling = upstream_score - 3, mechanism ceiling = upstream_score, collateral = no ceiling

Commits: `fa1d992`

## v3.0 - Resilience 4-factor model

**Effective:** 2026-02-26

Complete Resilience redesign from 2 factors to 4 equal sub-factors: chain risk, collateral quality, custody model, blacklist capability.

- Chain risk, collateral quality, custody model, and blacklist each weighted 25%
- New types: ChainRisk, CollateralQuality, CustodyModel with tier-based scoring

Commits: `ff9d589`, `46fe511`, `c45f007`

## v2.0 - Remove Safety dimension

**Effective:** 2026-02-26

Safety dimension removed due to sparse Bluechip rating coverage (~20/142 coins). Bluechip display kept for informational use.

- Safety dimension dropped; weight redistributed to remaining 5 dimensions

Commits: `a272ca8`

## v1.0 - Initial implementation

**Effective:** 2026-02-25

First release with six weighted dimensions: Peg Stability, Liquidity, Safety, Resilience, Decentralization, and Dependency Risk.

- Six dimensions with grade thresholds from A+ (>=97) to F (>=0)
- Minimum 3 rated dimensions required for overall grade

Commits: `66ec5c4`, `9c7ccc9`, `c11e37c`
