defirisk.co
rubric v1.7.0

Sudden admin-rescue/ACL change without discussion

Jupiter's assessment for RD-F-123 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

The June 2025 DAO governance pause and ASR structure change were made unilaterally by the Jupiter Foundation without a DAO vote. Community participants explicitly noted the decision was 'made behind closed doors, instead of through a DAO vote' (discuss.jup.ag). However, this is a governance-process centralization event, NOT a smart-contract ACL change. No covert on-chain program upgrade authority change is documented. Jupiter's protocol programs have a 12-hour timelock on admin actions (Drift hack post-mortem reference). The $140M CWG allocation (March 2025) followed proper DAO vote + prior forum discussion. YELLOW: governance process concern below the threshold of covert on-chain ACL change (the insider-implant signal class).

Sources #

Methodology #

Determine whether any admin-rescue function or ACL change was committed to the repo or executed on-chain without corresponding public discussion in issues, PRs, or governance forum.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol jupiter factor RD-F-123 score yellow collected_at 2026-04-29 11:51:25