defirisk.co
rubric v1.7.0

Admin/upgrade transaction in mempool

mETH Protocol's assessment for RD-F-102 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

Admin/upgrade transaction appearing in mempool. T-09 v1, Phase 2, Tier B. Applicable: yes — Staking contract (0xe3cBd06D7dadB3F4e6557bAb7EdD924CD1489E8f, TransparentUpgradeableProxy) and L1cmETHAdapter (0x4aFA9620D0B79137383A7A9AB3477837d475e948) are upgradeable proxies. CRITICAL POSTURE FINDING: TimelockController minDelay=0 means any admin upgrade tx submitted by the multisig has no enforced delay window. T-09 suppression rule (a) — tx originates from a timelock that fed by a queued+ripe governance proposal — cannot suppress here because any queued operation is immediately ripe (minDelay=0). The Tier-B 48h hysteresis window is also compressed: by the time an alert fires, the tx may already be mined. No active admin tx in mempool at assessment time (last confirmed upgrade: Staking contract 2025-10-30). Score yellow: the zero-delay posture means this signal would fire with no warning window — structurally elevated even without an active fire.

Sources #

  • Internal
    mETH Protocol profile — governance section, TimelockController anomaly note00-profile.md §6 — TimelockController minDelay=0 confirmed from constructor args on Etherscan: Arg [0]: minDelay (uint256): 0retrieved 2026-05-16
  • Etherscan
    mETH Staking Contract — EtherscanStaking contract 0xe3cBd06D7dadB3F4e6557bAb7EdD924CD1489E8f — TransparentUpgradeableProxy, last upgrade 2025-10-30; TimelockController 0xc26016f1166bE7b6c5611AAB104122E0f6c2aCE2 minDelay=0retrieved 2026-05-16

Methodology #

Detect an admin-role or upgrade transaction appearing in the mempool before confirmation.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol meth-protocol factor RD-F-102 score yellow collected_at 2026-05-16 02:17:50