SELFDESTRUCT reachable from non-admin path
Sky Lending (formerly MakerDAO)'s assessment for RD-F-011 — scored green on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
No SELFDESTRUCT in MCD core contracts per ToB/PeckShield 2019 audits. USDS uses OZ UUPS pattern without SELFDESTRUCT. ESM cage() function is admin-only, governance-gated, and performs controlled shutdown (not SELFDESTRUCT).
Sources #
- URLhttps://github.com/makerdao/mcd-security/blob/master/Audit%20Reports/TOB_MakerDAO_Final_Report.pdfretrieved 2026-04-27
- https://docs.makerdao.com/smart-contract-modules/shutdown/emergency-shutdown-moduleretrieved 2026-04-27
Methodology #
Determine whether any deployed contract contains the SELFDESTRUCT opcode in a code path reachable from a non-admin caller.
See the full factor methodology and distribution across all protocols →
rubric_version v1.7.0 protocol sky-lending factor RD-F-011 score green collected_at 2026-04-28 00:43:18