Timelock on sensitive actions
Frax Finance's assessment for RD-F-033 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
Alpha path: yes, 1-day OZ TimelockController gates high-impact changes. Omega path (day-to-day): 2-day veto window only — no mandatory post-veto timelock. frxUSD mint/pause/upgrade/addMinter: explicitly NO timelock per LlamaRisk. The operative day-to-day path and the stablecoin's sensitive actions lack timelock gating. Only Alpha-governed (rare) changes have timelock.
Sources #
- URLPegkeeper Onboarding Review: Frax frxUSD | Llama RiskLlamaRisk: no timelocks implemented in frxUSD contracts; admin multisigs have full control to upgrade contracts, change parameters, or pause functionalityretrieved 2026-05-17
- Advanced Concepts | Frax FinanceFrax docs: Omega uses 2-day veto window; Alpha uses OZ TimelockControllerretrieved 2026-05-17
Methodology #
For each sensitive action category (mint / pause / rescue / setOracle / upgrade), determine whether execution requires going through the declared timelock.
See the full factor methodology and distribution across all protocols →