★ Single admin EOA
Sushi (SushiSwap) — v2 + v3 + Trident + BentoBox/Kashi + SushiXSwap's assessment for RD-F-027 — scored green on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
No single EOA holds live admin authority over core protocol. Ops Multisig (3-of-5) controls operations. Deployer EOA (0xf942dba4159cb61f8ad88ca4a83f5204e8f4a6bd) transferred control historically. SUSHI token owner = MasterChef contract (not bare EOA). V3 factory owner not fully resolved via on-chain read [?] but Etherscan page shows no EOA label. Scored green — effective centralization is multisig-based.
Sources #
- DocsSushi Governance DocsSushi docs governance: operations multisig requires minimum 3 signatures for core team changesretrieved 2026-05-17
- SushiSwap: Operation Multisig — EtherscanSushiSwap Operation Multisig — active Safe contract, not EOAretrieved 2026-05-17
- SushiToken (SUSHI) — EtherscanSUSHI Token — owner is MasterChef contract 0xc2EdaD668740f1aA35E4D8f227fB8E17dcA888Cd (contract, not EOA)retrieved 2026-05-17
Methodology #
Determine whether the effective upgrade/owner/rescue role is held by a single EOA (not a multisig) with no timelock on sensitive operations.
See the full factor methodology and distribution across all protocols →