defirisk.co
rubric v1.7.0

Role separation: upgrade ≠ fee ≠ oracle

PancakeSwap's assessment for RD-F-035 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

Core V2/V3 AMM contracts are immutable — no upgrade role exists. Fee management and oracle config (for Predictions) are separate. However, at the governance layer, the team multisig appears to control all admin functions without documented role separation. Treasury, upgrade, and oracle config roles appear to converge in the undifferentiated team admin.

Sources #

Methodology #

Determine whether the upgrade role, fee-collection role, and oracle-config role are assigned to distinct addresses.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol pancakeswap factor RD-F-035 score yellow collected_at 2026-04-28 19:10:57