★ Single admin EOA
Chainlink CCIP's assessment for RD-F-027 — scored green on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
Not a single EOA. Admin is the ManyChainMultiSig contract at 0xE53289F32c8E690b7173aA33affE9B6B0CB0012F — a verified multi-party signing contract requiring group-based quorums. No single EOA holds effective admin over CCIP.
Sources #
- DocsOnchain Architecture - Upgradability (EVM) | Chainlink DocumentationChainlink CCIP upgradability docs confirming MCMS is the admin proposer with node operator co-signersretrieved 2026-05-16
- CCIP ManyChainMultiSig — Etherscan0xE53289F32c8E690b7173aA33affE9B6B0CB0012F verified as ManyChainMultiSig contractretrieved 2026-05-16
Methodology #
Determine whether the effective upgrade/owner/rescue role is held by a single EOA (not a multisig) with no timelock on sensitive operations.
See the full factor methodology and distribution across all protocols →
rubric_version v1.7.0 protocol chainlink-ccip factor RD-F-027 score green collected_at 2026-05-16 01:55:09