Emergency-veto multisig present
Cap (cUSD / stcUSD)'s assessment for RD-F-040 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
No distinct emergency-veto multisig. CANCELLER_ROLE on TimelockController held by the dev multisig (same as PROPOSER_ROLE). Cancel authority is not independent from proposer.
Sources #
- EtherscanCap TimelockController — CANCELLER roleTimelockController constructor: admin=address(0), proposers=[0xb8FC...], executors=[0xb8FC..., 0xc1ab...]. No separate CANCELLER address specified.retrieved 2026-05-17
Methodology #
Determine whether an emergency-veto or guardian multisig exists with power to cancel malicious proposals before execution.
See the full factor methodology and distribution across all protocols →
rubric_version v1.7.0 protocol cap factor RD-F-040 score yellow collected_at 2026-05-17 10:56:24