★ Single admin EOA
BENQI's assessment for RD-F-027 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
Admin is not a single EOA — confirmed multisig governance by multiple sources. Deployer 0x5423819B3b5bb38b0E9E9e59F22f9034e2d8819b deployed Comptroller ~5 years ago; current admin is a team multisig, not the deployer. Not red (multisig confirmed). Not green (threshold and signers undisclosed; effective centralization cannot be ruled out). Undisclosed multisig with unknown composition at $277M TVL warrants yellow.
Sources #
- EtherscanBenqi Finance: Comptroller | SnowTraceComptroller contract on Snowtrace; deployer 0x5423819B3b5bb38b0E9E9e59F22f9034e2d8819b deployed ~5yr ago; current admin address not readable via Snowtrace read interfaceretrieved 2026-05-16
- BENQI Security: Audits, Risk Architecture — DEV CommunityBENQI multisig framework confirmation — all parameter changes require multi-party approvalretrieved 2026-05-16
Methodology #
Determine whether the effective upgrade/owner/rescue role is held by a single EOA (not a multisig) with no timelock on sensitive operations.
See the full factor methodology and distribution across all protocols →