defirisk.co
rubric v1.7.0

Admin key custody type

crvUSD (Curve Stablecoin)'s assessment for RD-F-025 — scored red on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

ControllerFactory admin() returns 0xbabe61887f1de2713c6f97e567623453d3c79f67 (Curve Deployer 2 EOA). Custody type = single EOA. Emergency DAO is 5-of-9 Safe but only has emergency powers. Aragon DAO (veCRV) is the intended governance path but does NOT currently hold ControllerFactory admin.

Sources #

  • Etherscan
    ControllerFactory readContract admin()ControllerFactory admin() read returns 0xbabe61887f1de2713c6f97e567623453d3c79f67retrieved 2026-05-16
  • Docs
    crvUSD Protocol Profile §6Profile §6 governance topology confirms Deployer 2 as ControllerFactory adminretrieved 2026-05-16

Methodology #

Read the effective admin/owner/upgrader role on deployed contracts and classify as: EOA / multisig / multisig+timelock / full DAO+timelock / immutable.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol crvusd factor RD-F-025 score red collected_at 2026-05-16 19:09:40