defirisk.co
rubric v1.7.0

Single admin EOA

Jupiter's assessment for RD-F-027 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

Program upgrade authority held via Squads multisig (not a single EOA). JUP token admin is 4-of-7 multisig with named external signers. However: (1) governance voluntarily paused since June 2025, reverting effective protocol control to founding team (Meow/Ming Ng, Siong Ong) with no on-chain constraint; (2) exact program upgrade authority multisig address not publicly confirmed. No single admin EOA holds formal authority, but de facto centralization during pause is material.

Sources #

Methodology #

Determine whether the effective upgrade/owner/rescue role is held by a single EOA (not a multisig) with no timelock on sensitive operations.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol jupiter factor RD-F-027 score yellow collected_at 2026-04-29 11:51:25