Signer rotation recency
Multipli's assessment for RD-F-031 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
No multisig signer rotation to measure. MultipliBridger owner has not changed since deploy (January 2025, 16+ months). No threshold-reduction event applicable. Assessed yellow: static EOA control means no rotation — which is neither the positive (routine key hygiene) nor the DPRK precursor pattern. The 16-month stale single-EOA pattern is a separate concern captured by F043.
Sources #
- EtherscanMultipliBridger — no owner rotation since January 2025 deployMultipliBridger no OwnershipTransferred event after deploy tx 0x894a7fcretrieved 2026-05-17
Methodology #
Measure the number of months since the most recent signer-set change (add/remove signer) on the admin multisig; flag if threshold was reduced within 14 days of a timelock removal or new-signer addition.
See the full factor methodology and distribution across all protocols →