defirisk.co
rubric v1.7.0

Guardian/pause-keeper distinct from upgrader

Chainlink CCIP's assessment for RD-F-034 — scored green on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

RMN (Risk Management Network) via ARMProxy (0x411dE17f12D1A34ecC7F45f49844626267c75e81) provides an independent pause/curse capability entirely separate from CCIP admin. RMN can halt all CCIP lanes by issuing a curse transaction. RMN nodes are distinct from CCIP Commit/Execute DON nodes (different operator set, different programming language). Effective dual-layer: admin upgrader vs RMN curse.

Sources #

  • URL
    CCIP Risk Management Network | Chainlink BlogChainlink RMN blog — RMN issues curse transactions to all chains, halting all CCIP activity; implemented in Rust by separate teamretrieved 2026-05-16
  • Etherscan
    ARMProxy — EtherscanARMProxy at 0x411dE17f12D1A34ecC7F45f49844626267c75e81 — proxy for ARM implementation, confirmed on Etherscanretrieved 2026-05-16

Methodology #

Determine whether a pauser/guardian role exists and is held by an address distinct from the upgrader address.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol chainlink-ccip factor RD-F-034 score green collected_at 2026-05-16 01:55:09