Hot-patch deploys without timelock (last 30 days)
Superstate's assessment for RD-F-138 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
No timelock exists on any upgrade path. All upgrades execute as single-transaction ProxyAdmin calls with zero delay. The July 16, 2025 upgrade (to SuperstateTokenV5_1) was executed without a timelock at block 22933833. Assessment date is 2026-05-16; the Jul 2025 upgrade is outside the last 30 days but the structural absence of timelock on all upgrades persists. Scored yellow (structural gap) rather than red (no upgrade in last 30d identified).
Sources #
- EtherscanUSTB Hot-Upgrade Jul 2025 - No TimelockUSTB upgrade tx 0x3396a..., Jul 16 2025: single-tx, called directly by EOA on ProxyAdmin, no timelockretrieved 2026-05-16
Methodology #
Count upgrades executed in the last 30 days without going through the declared timelock path.
See the full factor methodology and distribution across all protocols →