defirisk.co
rubric v1.7.0

Sudden admin-rescue/ACL change without discussion

Liquity V1 + V2 (LUSD / BOLD)'s assessment for RD-F-123 — scored green on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

GREEN by construction: Liquity v1 and v2 core contracts are fully immutable with no admin key, no proxy, no upgrade path, no pause function, and no rescue function. There is no on-chain mechanism for an admin-rescue or ACL change on any core borrowing, liquidation, or stability pool contract. The v2 Governance contract (0x807def5e7d057df05c796f4bc75c3fe82bd6eee1) controls PIL incentive direction only (25% of protocol revenue to external liquidity initiatives) via LQTY staking; all changes are public, epoch-based, and visible at voting.liquity.org. Review of GitHub liquity/bold and liquity/V2-gov confirms no undiscussed emergency admin-key changes in the past 180 days. ChainSecurity governance audit (January 2025) verified governance module scope is strictly limited to PIL direction. Zero admin-change surface exists by architectural construction.

Sources #

Methodology #

Determine whether any admin-rescue function or ACL change was committed to the repo or executed on-chain without corresponding public discussion in issues, PRs, or governance forum.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol liquity factor RD-F-123 score green collected_at 2026-05-16 10:35:50