defirisk.co
rubric v1.7.0

Single admin EOA

Marinade Finance's assessment for RD-F-027 — scored green on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

Upgrade authority 551FBXSXdhcRDDkdcb3ThDRg84Mwe5Zs6YjJ1EEoyzBp is off-curve PDA (is_on_curve=FALSE confirmed by orchestrator). Cannot be a single EOA — no private key exists for an off-curve address. Controlled by Coral Multisig program msigmtwzgXJHj2ext4XJjCDmpbcMuufFb5cHuwg6Xdt (6/13). Solana on-curve/off-curve discriminator correctly applied per SOLANA_GOVERNANCE.md.

Sources #

  • URL
    Solana upgrade authorities — NeodymeNeodyme blog on Solana upgrade authorities — explains off-curve PDA vs single-key discriminatorretrieved 2026-05-16
  • Internal
    Marinade profile — off-curve PDA confirmation.research/protocols/marinade/00-profile.md §3 and §11 — orchestrator-derived is_on_curve=FALSE for 551FBXSXdhcRDDkdcb3ThDRg84Mwe5Zs6YjJ1EEoyzBpretrieved 2026-05-16
  • URL
    Solscan — MarBmsSgKXdrN1egZf5sqe1TMai9K1rChYNDJgjq7aDSolscan — Marinade Liquid Staking Program account showing BPFLoaderUpgradeableretrieved 2026-05-16

Methodology #

Determine whether the effective upgrade/owner/rescue role is held by a single EOA (not a multisig) with no timelock on sensitive operations.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol marinade factor RD-F-027 score green collected_at 2026-05-16 08:48:35