New ERC-20 approval to unverified contract from whale
Liquid Collective (LsETH)'s assessment for RD-F-096 — scored gray on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
T-09 v2 deferred. LsETH deposits are permissioned via the Allowlist contract (0xebc83Bb472b2816Ec5B5de8D34F0eFc9088BB2ce); institutional KYC/AML screening gates all depositor addresses. New ERC-20 approvals to unverified contracts from high-TVL depositors are harder to associate with this protocol given the permissioned access model. Requires on-chain approval-scan infrastructure not yet in production.
Sources #
- DocsDeployment Addresses - Liquid Collective ETHAllowlist contract gates all LsETH deposits; institutional-grade access model reduces ERC-20 approval attack surfaceretrieved 2026-05-17
Methodology #
Detect whether a top-TVL depositor grants a new token approval to an unverified contract that interacts with this protocol.
See the full factor methodology and distribution across all protocols →