SELFDESTRUCT reachable from non-admin path
Lombard Finance's assessment for RD-F-011 — scored gray on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
No published Slither suicidal detector output available. Local tool run not performed per dry-run methodology. Factory directory exists in repo (CREATE3-based deployment) but factory source was not retrieved. Post-Cancun EIP-6780 limits SELFDESTRUCT to same-transaction deployments, reducing risk, but deployed contracts target Paris EVM version (pre-Cancun behavior applies to legacy deployments). No audit finding flags SELFDESTRUCT in non-admin paths. Marked gray — needs tool run.
Sources #
- Curator noteStatic analysis gap noteNo Slither output available; needs tool runretrieved 2026-05-05
- LBTC Implementation EtherscanLBTC implementation EVM target: Paris (per bytecode metadata)retrieved 2026-05-05
Methodology #
Determine whether any deployed contract contains the SELFDESTRUCT opcode in a code path reachable from a non-admin caller.
See the full factor methodology and distribution across all protocols →