Admin key custody type
Axelar Network's assessment for RD-F-025 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
EVM gateway governance routes through validator-set quorum (AxelarGatewayProxyMultisig) and the InterchainGovernance contract (7-day minimum timelock). Operator/mintLimiter role held by custom 3-of-6 Multisig contract. ITS proxy upgrade authority held by bare EOA 0x6f24A47Fc8AE5441Eb47EFfC3665e70e69Ac3F05 (confirmed no contract code). Two distinct trust domains: gateway (strong) and ITS (bare EOA). Updated yellow from green to reflect split architecture.
Sources #
- EtherscanITS proxy admin — Etherscan (EOA confirmed)ITS proxy admin 0x6f24A47Fc8AE5441Eb47EFfC3665e70e69Ac3F05 — bare EOA (no contract code confirmed)retrieved 2026-05-17
- AxelarGateway Proxy — EtherscanAxelarGatewayProxyMultisig 0x4F4495243837681061C4743b74B3eEdf548D56A5retrieved 2026-05-17
- InterchainGovernance — EtherscanInterchainGovernance 0xfDF36A30070ea0241d69052ea85ff44Ad0476a66 minimumTimeLockDelay=604800retrieved 2026-05-17
Methodology #
Read the effective admin/owner/upgrader role on deployed contracts and classify as: EOA / multisig / multisig+timelock / full DAO+timelock / immutable.
See the full factor methodology and distribution across all protocols →