Portal
Best for audited protocol with published methodology
How it rates
- Audit report linked from a public dataset
- Accounting methodology published
- $1,437m recorded independently
- Several indicators could not be verified from public sources at this check
Each indicator scores 2, 1 or 0. A pillar is the points earned over the points available; the overall score is the weighted sum. Every source below is public — check any of them yourself.
- MetIndependent audit report linked publicly
Audit report linked from the public protocol dataset.
github.com/certusone/wormhole/blob/dev.v2/SECURITY.md - Met
- MetTracked by an independent analytics platform
Listed with published value and history.
defillama.com/protocol/portal - Met
- MetApplication reachable at a public address
Reachable without an account at this check.
portalbridge.com
- Met
- MetProtocol economics published independently
Value and change history published.
defillama.com/protocol/portal - Met
- PartialFee or reward model documented publicly
Application reachable for review; specific rates not captured at this check.
portalbridge.com - MetNo account required to reach the application
Reachable without an account at this check.
portalbridge.com
- Met
- Met
- Not met
- Met
- Met
- Met
- Met
- Met
- Met
- Met
- Met
- Met
- Met
- Met
- Met
A cross-chain bridge holding $1.44bn across 24 chains with published audits, operating since a major 2022 exploit that was fully covered.
Our assessment
Portal holds $1.44bn across 24 chains with two audits and reports linked — the strongest evidence profile of any bridge in this comparison. Its history includes one of the largest exploits in DeFi.
February 2022, and what followed
An attacker exploited a signature verification flaw and minted roughly $325m of wrapped ETH without depositing anything. The hole was covered in full by the parent company within days, so users lost nothing. That response — immediate, complete, and funded by the operator rather than socialised — is rarer than the exploit itself.
Why bridges are the most dangerous thing in DeFi
A bridge holds real assets on one chain and issues claims on another. Break the issuance logic and you can mint claims without deposits, draining everything. More value has been lost to bridge exploits than to any other category of DeFi failure, which is why counterparty risk carries 45% of the score here — the highest weight we apply anywhere.
What the evidence shows now
Two audits with linked reports, documented mechanics, and a rebuilt system with a security programme following the incident. A protocol that was exploited, disclosed it, covered the loss and published the remediation is demonstrating something a never-tested protocol cannot.
Who it suits
Portal fits users moving assets across many chains who want the best-documented bridge available. Users who can avoid bridging — by buying the asset natively on the destination chain — should do that instead, whatever the bridge scores.
Frequently asked
Does this score mean Portal is safe?
No. It measures what an outsider can verify: linked audits, published methodology and independently recorded data. Contract and custody risk are not tested by us.
Where do these figures come from?
A public analytics dataset queried at the verification date, plus the audit reports it links. Anyone can re-run the query.
Why do some protocols score zero on audits?
Because no audit report is linked in the public record. It records what a user can reach, not a claim that no audit exists.