★ Single admin EOA
Compound V3 (Comet)'s assessment for RD-F-027 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
Primary upgrade path routes through Timelock -> GovernorBravo -> COMP DAO. Not a single EOA for the standard path. Exception: Timelock.admin() = 0x8B8592E9570E96166336603a1b4bd1E8Db20fa20, confirmed EOA (no contract code, 152 transactions over 7+ years, personal wallet). Per Compound Timelock.sol, the admin can call queueTransaction() and executeTransaction() directly bypassing GovernorBravo. Whether this is an active bypass or legacy residual unresolved.
Sources #
- GitHub
- https://etherscan.io/address/0x6d903f6003cca6255D85CcA4D3B5E5146dC33925retrieved 2026-04-28
- https://etherscan.io/address/0x8B8592E9570E96166336603a1b4bd1E8Db20fa20retrieved 2026-04-28
Methodology #
Determine whether the effective upgrade/owner/rescue role is held by a single EOA (not a multisig) with no timelock on sensitive operations.
See the full factor methodology and distribution across all protocols →