defirisk.co
rubric v1.7.0

Bridge uses same key custody for >30% validators

Frax Finance's assessment for RD-F-156 — scored red on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

FraxFerry: all three bridge roles (Captain, Crew, First Officer) are Frax-team-controlled — 100% same custodian (far exceeds >30% threshold). Fraxtal: single proposer EOA and single sequencer EOA both controlled by Frax team — same custodian. LayerZero OFT bridge: multiple independent DVN operators (Horizen, Blockdaemon-Animoca, Polyhedra, LZ Labs, Frax DVN) — distributed custody. However scoring against highest-risk bridge surface (FraxFerry and Fraxtal both exceed >30% single-custodian threshold), so red. The frxUSD LZ OFT path has better custody distribution but does not override the centralized control of FraxFerry and Fraxtal.

Sources #

  • URL
    L2BEAT FraxtalL2BEAT Fraxtal — sequencer and proposer both single EOA addresses controlled by Frax teamretrieved 2026-05-17
  • Docs
    Frax FraxFerry Bridge DocsFraxFerry docs — Captain, Crew, First Officer: all Frax team roles (single custodian for all bridge validation roles)retrieved 2026-05-17

Methodology #

Determine whether >30% of bridge validators share a single key custodian.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol frax factor RD-F-156 score red collected_at 2026-05-16 20:44:31