defirisk.co
rubric v1.7.0

Upgrade multisig signer configuration (M/N)

Meteora's assessment for RD-F-026 — scored gray on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

Squads v3 multisig CoEsykatDegLB7pcMJia79JSriDdi71nPnjgeSfw623k threshold and member count not decoded. Borsh decode requires direct RPC getAccountInfo not feasible in agent environment. No public disclosure of threshold found in documentation, governance forum, or search results. Per-program upgrade authority enumeration for other programs also incomplete.

Sources #

  • Internal
    Meteora Protocol Profile — squads_v3_threshold not decoded.research/protocols/meteora/00-profile.md §6 — squads_v3_threshold: nullretrieved 2026-05-16
  • Internal
    Solana Governance Verification MethodologySOLANA_GOVERNANCE.md Step 4 — Squads v3 borsh layout decode procedureretrieved 2026-05-16

Methodology #

Read `threshold` and `getOwners()` on the multisig controlling upgrade / sensitive ops. Store as `required` (M) and `total` (N); render as "M/N". For EOA admins record `required=1, total=1` (display "1/1"). Null when admin is immutable or full DAO with no fixed signer set.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol meteora factor RD-F-026 score gray collected_at 2026-05-16 10:03:05