defirisk.co
rubric v1.7.0

Admin wallet interacts with flagged addresses

A governance & admin factor in the v1.7.0 rubric. Measured per protocol on a e cadence.

Methodology how we score#

What this measures
This factor checks whether the protocol's admin address has sent or received transactions involving addresses on a curator-maintained watchlist — including known dust-attack targets, mixer deposit addresses, sanctioned clusters, and addresses linked to prior exploits or exit scams. The check is performed via on-chain transaction history analysis and cross-referenced against the watchlist.

Why it matters
Admin address interactions with flagged addresses are a soft signal of potential insider risk or compromised key custodian relationships. A protocol whose admin wallet has received funds from a mixer, sent funds to a OFAC-sanctioned address, or interacted with a known exit-scam contract presents an elevated risk of insider-motivated drain. This factor is not individually sufficient to alter a grade, but it contributes to the overall governance risk picture and can corroborate other signals in the dev identity category (Cat 7).

Green / Yellow / Red
Green is assigned when the admin address has no interactions with flagged addresses in the watchlist. Yellow covers cases where interactions are present but explainable (e.g., dust-attack receipt with no active response) or where the watchlist confidence is low. Red is assigned when the admin address has sent funds to or actively interacted with mixer addresses, sanctioned clusters, or known exit-scam deployers.

Common gray cases
This factor is grayed when the admin address cannot be identified from on-chain data, or when the watchlist coverage for the relevant chain is sparse.

Notable historical examples
No cross-hacked incidents currently linked in database for this factor.

Measurement what to look for#

Determine whether the admin/upgrader address has sent or received transactions with addresses on the curator watchlist (mixer deposits, dust-attack targets, OFAC-listed).

Data & output #

Data source
Chainalysis/TRM API cluster feed + Etherscan tx history of admin address
Output format
Green / Yellow / Red
Evidence artifact
Admin address + cluster-feed hit list + most recent flagged interaction tx hash
Confidence signal
green = no flagged interactions; yellow = distant interaction (3+ hops) with flagged cluster; red = direct send/receive with OFAC-listed or known-rug address; gray = cluster feed unavailable

Scored protocols 0 carry this factor#

No protocols have been scored for this factor yet.

Linked hacks no historical incidents linked#

No historical incidents are linked to this factor.
rubric_version v1.7.0factor RD-F-044category 2carried 0critical no