defirisk.co
rubric v1.7.0

Timelock duration on upgrades

Falcon Finance's assessment for RD-F-032 — scored red on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

ZERO timelock delay. No TimelockController deployed. All proxy upgrades and admin actions execute immediately upon Safe threshold confirmation. At $1.618B TVL this is a critical infrastructure gap.

Detail #

Profile: timelock_address=null, timelock_delay_seconds=null. No TimelockController address found in: (1) official docs pages, (2) audit reports (Pashov and Zellic both scoped USDf/sUSDf without mentioning a timelock), (3) Etherscan searches for associated addresses. The Safe's 16 transactions are all direct 'Exec Transaction' calls with no timelock-queued operations.

Sources #

Methodology #

Read the timelock delay (in hours) between a queued upgrade proposal and its executable state.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol falcon-finance factor RD-F-032 score red collected_at 2026-05-12 04:06:37