defirisk.co
rubric v1.7.0

Upgrade multisig signer configuration (M/N)

Pendle Finance's assessment for RD-F-026 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

Dev Multisig: 2-of-5. Governance Safe: 3-of-5. Treasury: 2-of-6. ProxyAdmin is EOA (1-of-1 for upgrades). All confirmed via Safe Transaction Service API.

Sources #

  • URL
    Safe API TreasuryTreasury 0x8270400d528c34e1596EF367eeDEc99080A1b592 — threshold 2, owners 6retrieved 2026-04-29
  • URL
    Safe API Dev MultisigDev Multisig 0xE6F0489ED91dc27f40f9dbe8f81fccbFC16b9cb1 — threshold 2, owners 5retrieved 2026-04-29

Methodology #

Read `threshold` and `getOwners()` on the multisig controlling upgrade / sensitive ops. Store as `required` (M) and `total` (N); render as "M/N". For EOA admins record `required=1, total=1` (display "1/1"). Null when admin is immutable or full DAO with no fixed signer set.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol pendle factor RD-F-026 score yellow collected_at 2026-04-28 21:09:40