Deprecated contract paused but pause reversible by live admin
Beefy Finance's assessment for RD-F-167 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
Dev multisig retains ownership of deprecated strategy contracts that are paused after vault migrations. Strategy deprecation via retireStrat() is irreversible once called (transfers want tokens to vault). Allowance tool (allowance.beefy.finance) exists to help users revoke stale approvals from deprecated routers — its existence implies acknowledged stale-approval surface on deprecated contracts. Old BIFI token on BSC (0xCa3F508B8e4Dd382eE878A314789373D80A5190A) is deprecated but still on-chain.
Sources #
- URLhttps://app.beefy.com/revokeretrieved 2026-05-16
Methodology #
Determine whether a deprecated-and-paused contract's pause state is revertible by a currently-live admin role.
See the full factor methodology and distribution across all protocols →