defirisk.co
rubric v1.7.0

Single admin EOA

Compound V3 (Comet)'s assessment for RD-F-027 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

Primary upgrade path routes through Timelock -> GovernorBravo -> COMP DAO. Not a single EOA for the standard path. Exception: Timelock.admin() = 0x8B8592E9570E96166336603a1b4bd1E8Db20fa20, confirmed EOA (no contract code, 152 transactions over 7+ years, personal wallet). Per Compound Timelock.sol, the admin can call queueTransaction() and executeTransaction() directly bypassing GovernorBravo. Whether this is an active bypass or legacy residual unresolved.

Sources #

Methodology #

Determine whether the effective upgrade/owner/rescue role is held by a single EOA (not a multisig) with no timelock on sensitive operations.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol compound-v3 factor RD-F-027 score yellow collected_at 2026-04-28 00:20:50