Skip to main content
Stenion
Registry

Aquarius XLM/USDC

stellar·adapter AquariusAdapter

update failedScored 2026-10-09 07:00 UTC

Last run 2026-10-09 07:45 UTC · updated on every indexer cycle

This score has not refreshed — our last update attempt failed

The score shown is the last one Stenion computed successfully; our most recent attempt to refresh it failed, so the number may be out of date. This is a problem with our data collection, not a change in the protocol’s risk.

Last successful score 2026-10-09 07:00 UTC · last attempt 2026-10-09 07:45 UTC. The failure itself is in Recent runs below.

Verify this yourself

Protocol names, logos and trademarks belong to their respective owners and are shown for identification only. Their presence here and any link to a protocol's own site or documentation does not imply endorsement, partnership, or any relationship with Stenion, in either direction.

Factor breakdown

Why the score is what it is — each factor on a 0–100 scale, higher is safer.

Admin keyweight 55%10

role posture binds at 10 — pool: worst of 7 roles — PauseAdmin single-key GA6MA6… (1 signer(s), high-threshold 0), 44 op(s) in 30d; RewardsAdmin single-key GCXYKA… (1 signer(s), high-threshold 0), 200 op(s) in 30d; SystemFeeAdmin single-key GB57YD… (1 signer(s), high-threshold 0), 200 op(s) in 30d | router: worst of 7 roles — PauseAdmin single-key GA6MA6… (1 signer(s), high-threshold 0), 44 op(s) in 30d; RewardsAdmin single-key GCXYKA… (1 signer(s), high-threshold 0), 200 op(s) in 30d; SystemFeeAdmin single-key GB57YD… (1 signer(s), high-threshold 0), 200 op(s) in 30d

  • Privileged role posture10

    pool: worst of 7 roles — PauseAdmin single-key GA6MA6… (1 signer(s), high-threshold 0), 44 op(s) in 30d; RewardsAdmin single-key GCXYKA… (1 signer(s), high-threshold 0), 200 op(s) in 30d; SystemFeeAdmin single-key GB57YD… (1 signer(s), high-threshold 0), 200 op(s) in 30d | router: worst of 7 roles — PauseAdmin single-key GA6MA6… (1 signer(s), high-threshold 0), 44 op(s) in 30d; RewardsAdmin single-key GCXYKA… (1 signer(s), high-threshold 0), 200 op(s) in 30d; SystemFeeAdmin single-key GB57YD… (1 signer(s), high-threshold 0), 200 op(s) in 30d

  • Upgrade reaction window100

    pool UpgradeDeadline = 0 — no code change scheduled (FutureWASM d691135a… matches the running code) | router UpgradeDeadline = 0 — no code change scheduled (FutureWASM c99539b0… matches the running code)

  • Timelock durationnot scored

    ADMIN_ACTIONS_DELAY is a compile-time constant with no getter, confirmed absent from all four deployed wasms, so the LENGTH of the upgrade window is not readable from the contract. The deadline and the current time are, which is why the window is graded as a state and never as a fraction remaining.

  • Emergency Admin bypassnot scored

    Aquarius's own response to Certora H-01: "In the case of system vulnerability fixes, delay may be bypassed by the Emergency Admin role." So the reaction window is conditional on one single-signer key choosing not to skip it. Disclosed rather than folded in, because "a window exists" and "the window is unconditional" are different claims and only the first is true.

Asset controlweight 45%40

worst of 2 gradable reserve(s): USDC CCW67T…: issuer GA5ZSE… has auth_revocable — can freeze the pool's balance

  • XLM100

    XLM CAS3J7…: native XLM — a SAC with no issuer account to act from

  • USDC40

    USDC CCW67T…: issuer GA5ZSE… has auth_revocable — can freeze the pool's balance

Findings

What we found reading Aquarius XLM/USDC’s contracts that isn’t captured by a factor. These do not affect the score and cannot change the ranking.

This entry is one Aquarius market of 340, and the seven roles that control it control all of them

Aquarius is an AMM with many markets rather than one pool. Reading its router’s own get_pools_for_tokens_range across all 304 of its token sets on 2026-08-29, at ledger 64,182,824, returns 340 pools: 272 constant-product, 42 stableswap and 26 concentrated. This entry is one of the 272. It is not Aquarius, and a reader who takes the number above as a grade on the protocol has read it wrongly — what is scored is the pool at the contract address on this page.

Every one of those 340 pools runs one of exactly three contracts. Each pool’s running wasm hash equals one of ConstantPoolHash, StableSwapPoolHash or ConcentratedPoolHash as the router itself declares them, with no exceptions found — this pool runs ae0da5a8…de9852, the constant-product hash. So the code under this market is the same code under 271 others.

The admin surface is shared too, and that is the part that carries into the score. get_privileged_addrs() on this pool returns the same seven roles, held by the same seven accounts, as the router itself: an Admin held by a 3-of-n account with a high threshold of 2, and six single-signer accounts holding EmergencyAdmin, EmergencyPauseAdmin, PauseAdmin, OperationsAdmin, RewardsAdmin and SystemFeeAdmin. A per-pool set_privileged_addrs exists, so this is a current reading rather than an invariant — but as it stands, adminKeySafety is measuring something about Aquarius rather than about this market, and would read the same on any of the 340.

What that means for the two published factors: adminKeySafety does not distinguish this market from any other Aquarius market today, and assetControlSafety — which reads the issuers of the tokens this pool actually holds — is the factor that does. That is a property of Aquarius’s current setup, not of the rulebook, and the weights were deliberately not tuned around it.

What is not being claimed: sharing one codebase and one admin set across 340 markets is ordinary for an AMM and is not itself a finding. It is recorded because the entry names one pair, and a reader is entitled to know how much of the number is about that pair and how much is about the protocol underneath it.

Verify it yourself: Call get_tokens_sets_count() and get_pools_for_tokens_range(0, 304) on the Aquarius AMM router CBQDHNBFBZYE4MKPWBSJOPIYLW4SFSXAXUTSXJN76GNKYVYPCKWC6QUK via Soroban RPC to enumerate the pools. Read each pool contract’s instance entry for its executable wasm hash, and the router’s instance storage for ConstantPoolHash / StableSwapPoolHash / ConcentratedPoolHash to classify it. Call get_privileged_addrs() on this pool and on the router and compare the two maps.

Score history

Every indexer run, on a fixed 0–100 axis and a real time axis. The line breaks wherever the score is unknown — a failed run, an indexing gap, or a methodology change — rather than drawing through it.

ExportCSVJSON
034671008 Oct 21:009 Oct 00:0003:0006:00
24High risk
9 Oct 07:00 UTC · methodology v1
safety score failed run — no score, not a zero no data
Showing 50 runs · 8 Oct 19:30 → 9 Oct 07:45 UTC · 12h 15m · typically every 15m

Recent runs

The last 50 scoring runs, newest first. Open a scored run to see the factor breakdown it produced.

Aquarius XLM/USDC — safety 24 · Stenion