★ Single admin EOA
Falcon Finance's assessment for RD-F-027 — scored green on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
Admin is the 4-of-6 Gnosis Safe, not a single EOA. Proxy admin role was set to the Safe at genesis (Jan 16, 2025). Deployer EOA is one of 6 signers but cannot act alone.
Detail #
USDf proxy constructor arg sets initialOwner=0x1E482B60bf19Cb1cc859389e0eA3DED153f16Bd7 (the Safe). sUSDf proxy constructor arg same. Safe created on 2025-01-16 by deployer EOA, immediately receiving admin rights. Deployer EOA 0x804016... is owner[0] in the Safe but cannot sign unilaterally. 4-of-6 coordination required for any privileged action.
Sources #
- EtherscanUSDf proxy — initialOwner constructor arg = Safe addresshttps://etherscan.io/token/0xFa2B947eEc368f42195f24F36d2aF29f7c24CeC2retrieved 2026-05-12
- Safe Transaction Service — Falcon Finance Admin Safehttps://api.safe.global/tx-service/eth/api/v1/safes/0x1E482B60bf19Cb1cc859389e0eA3DED153f16Bd7/retrieved 2026-05-12
Methodology #
Determine whether the effective upgrade/owner/rescue role is held by a single EOA (not a multisig) with no timelock on sensitive operations.
See the full factor methodology and distribution across all protocols →