defirisk.co
rubric v1.7.0

delegatecall/call in proposal execution without allowlist

Meteora's assessment for RD-F-039 — scored not_applicable on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

Solana BPF has no delegatecall opcode. No EVM-style governor with delegatecall execution path exists. Solana uses CPI (Cross-Program Invocation) which is architecturally distinct and not subject to the same attack vector. Factor is structurally inapplicable to Solana non-EVM substrate.

Sources #

  • Internal
    Meteora Protocol Profile — Substrate flag.research/protocols/meteora/00-profile.md §11 — non_evm_substrate: trueretrieved 2026-05-16
  • Internal
    Solana Governance Verification MethodologySOLANA_GOVERNANCE.md — Solana substrate methodology; no delegatecall equivalentretrieved 2026-05-16

Methodology #

Determine whether the governance executor contract uses `delegatecall` or `call` with proposal-supplied target, without enforcing an allowlist of permitted targets.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol meteora factor RD-F-039 score not_applicable collected_at 2026-05-16 10:03:05