defirisk.co
rubric v1.7.0

UUPS _authorizeUpgrade correctly permissioned

Ethena's assessment for RD-F-021 — scored not_applicable on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

None of the core Ethena contracts use UUPS or any proxy pattern. USDe, EthenaMinting V2, StakedUSDeV2 are all direct non-upgradeable implementations. UUPS _authorizeUpgrade gate factor is not applicable. USDtb (sub-product) uses upgradeable pattern but is out of core scope.

Sources #

Methodology #

Determine whether the UUPS implementation defines `_authorizeUpgrade(address)` restricted to owner/admin/timelock (not open to arbitrary callers).

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol ethena factor RD-F-021 score not_applicable collected_at 2026-04-28 13:58:51