defirisk.co
rubric v1.7.0

Sudden admin-rescue/ACL change without discussion

Circle USYC's assessment for RD-F-123 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

9 EIP-1967 proxy upgrades confirmed on the Ethereum USYC token contract (0x136471a34f6ef19fE571EFFC1CA711fdb8E49f2b) since May 2023, most recent 2025-12-09. Similar upgrades on RolesAuthorityProxy (last upgrade 2025-11-20). No public governance forum, Snapshot, DAO, or GitHub issue/PR exists for USYC. All upgrades executed by deployer EOA without observable public preceding discussion. Per PD-042 RWA context: absence of public discussion is structurally expected for a corporate-governed regulated issuer, not an anomaly. No insider-implant signal pattern observed (no suspicious rapid-change/reverse, no malicious ACL narrowing). Scored yellow not red because: (1) Circle is NYSE-listed regulated entity with BMA oversight and fiduciary duties; (2) no suspicious timing/pattern visible; (3) RWA corporate governance model makes DAO-norm comparison inappropriate per PD-042.

Sources #

Methodology #

Determine whether any admin-rescue function or ACL change was committed to the repo or executed on-chain without corresponding public discussion in issues, PRs, or governance forum.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol circle-usyc factor RD-F-123 score yellow collected_at 2026-05-15 21:56:43