defirisk.co
rubric v1.7.0

Timelock duration on upgrades

crvUSD (Curve Stablecoin)'s assessment for RD-F-032 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

No standalone TimelockController. Aragon vote duration = 7 days (168h) for Ownership votes — this is the functional delay on the DAO path. However, the Deployer 2 EOA admin on ControllerFactory can act immediately (0h delay). The dual-path reality: DAO-routed actions have 168h delay; EOA-direct actions have 0h delay. Graded yellow (not red) because the intended governance path has an adequate delay; red on F033 captures the EOA bypass.

Sources #

Methodology #

Read the timelock delay (in hours) between a queued upgrade proposal and its executable state.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol crvusd factor RD-F-032 score yellow collected_at 2026-05-16 19:09:40