defirisk.co
rubric v1.7.0

Admin = deployer EOA after 7 days

Jupiter Perpetual Exchange's assessment for RD-F-043 — scored green on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

Upgrade authority for PERPHjGBqRHArX4DySjwM6UJHiR3sWAatqfdBS2qQJu is 5myNNmEmPm3UAnJ2ggLEpnTFb9t9Gk8369wKw6n3uAKx, confirmed off-curve PDA (is_on_curve=FALSE) — Squads v4 vault PDA, not a deployer EOA. The rug-correlated condition (admin=deployer EOA with no multisig transfer) is falsified by on-chain derivation. Historical timing of the authority transfer at deploy (Nov 2023) cannot be confirmed from available sources, but the current governance posture (Squads v4 4-of-7) is the relevant state. Updated from not_assessed.

Sources #

  • Docs
    Squads Multisig — off-curve PDA methodologySOLANA_GOVERNANCE.md: off-curve PDA cannot be a single keypair EOA; ANTI-DRIFT CLAUDE.md item 12: the EVM owner-check intuition is WRONG on Solana; off-curve test is authoritativeretrieved 2026-05-16
  • Tx
    Squads v4 vault PDA 5myNNm on SolscanMainnet RPC on-chain derivation: upgrade_authority=5myNNmEmPm3UAnJ2ggLEpnTFb9t9Gk8369wKw6n3uAKx; is_on_curve=FALSE (not a deployer EOA); tx sig pmpDzKGTLC... confirms Squads v4 control; parent multisig AxkJ8oH5...retrieved 2026-05-16

Methodology #

Determine whether, at t = deploy+7d, the admin address still equals the deployer EOA with no evidence of transfer to a multisig.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol jupiter-perps factor RD-F-043 score green collected_at 2026-05-16 01:53:11