★ Single admin EOA
Fluid's assessment for RD-F-027 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
0x4F6F977 is an Avocado smart account (not plain EOA) but _requiredSigners defaults to 1 and specific multi-party configuration is not publicly verifiable. No timelock between Avocado admin action and FluidLiquidityProxy upgrade. Cannot confirm multi-party protection.
Sources #
- GitHubInfinite Proxy onlyAdmin: msg.sender == _getAdmin(), no delay — admin = 0x4F6F977fluid-contracts-public/contracts/infiniteProxy/proxy.sol onlyAdmin modifierretrieved 2026-04-29
- AvocadoMultisig impl: signers(), requiredSigners(), signersCount() in ABI but values unreadable statically0x4F6F977aCDD1177DCD81aB83074855EcB9C2D49e Avocado implementation 0xaa282C8aretrieved 2026-04-29
Methodology #
Determine whether the effective upgrade/owner/rescue role is held by a single EOA (not a multisig) with no timelock on sensitive operations.
See the full factor methodology and distribution across all protocols →
rubric_version v1.7.0 protocol fluid factor RD-F-027 score yellow collected_at 2026-04-29 10:35:01