defirisk.co
rubric v1.7.0

Single admin EOA

Meteora's assessment for RD-F-027 — scored green on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

DLMM upgrade authority JADaUV8kvDpDbJr55wxXJHVaBS3VCj8thZZHjfeuCVLd is off-curve (is_on_curve = FALSE per SOLANA_GOVERNANCE.md methodology). This is a Squads v3 vault PDA, not a single private-key EOA. Controlled by Squads v3 multisig CoEsykatDegLB7pcMJia79JSriDdi71nPnjgeSfw623k. Not a single admin EOA scenario. Anti-drift item-12 applied: do not score red based on upgrade authority address alone without curve classification.

Sources #

  • Internal
    Solana Governance Verification Methodology — off-curve discriminatorSOLANA_GOVERNANCE.md — off-curve test + Squads v3 vault PDA explanationretrieved 2026-05-16
  • Docs
    Meteora on Solana: Project Review, Programs, Token, MetricsSolanaCompass Meteora governance — protocol uses Squads multisig for adminretrieved 2026-05-16
  • Internal
    Orchestrator DLMM upgrade authority on-curve classificationOrchestrator on-chain derivation: is_on_curve(JADaUV8kvDpDbJr55wxXJHVaBS3VCj8thZZHjfeuCVLd) = FALSE; SOLANA_GOVERNANCE.md off-curve discriminatorretrieved 2026-05-16

Methodology #

Determine whether the effective upgrade/owner/rescue role is held by a single EOA (not a multisig) with no timelock on sensitive operations.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol meteora factor RD-F-027 score green collected_at 2026-05-16 10:03:05