defirisk.co
rubric v1.7.0

Reinitializable implementation (no _disableInitializers)

Stake DAO's assessment for RD-F-143 — scored gray on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

vlSDT is non-proxy (verified non-proxy source) — RD-F-143 N/A for vlSDT. veSDT is TransparentUpgradeableProxy; implementation is 0xe4c978731617096d04ea271a2499cf48b99cdc3e. Cannot confirm _disableInitializers() in implementation constructor from proxy contract page alone. Static analysis required. Gray pending code-security-analyst inspection of implementation source.

Sources #

  • Etherscan
    vlSDT ContractvlSDT: non-proxy verified source (Ownable2Step, not UUPS/transparent); RD-F-143 not applicable for vlSDTretrieved 2026-05-16
  • Etherscan
    veSDT Proxy — ImplementationveSDT proxy impl: 0xe4c978731617096d04ea271a2499cf48b99cdc3e; _disableInitializers() not confirmable from proxy pageretrieved 2026-05-16

Methodology #

Determine whether the implementation contract does not call `_disableInitializers()` in its constructor, leaving re-initialization possible.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol stake-dao factor RD-F-143 score gray collected_at 2026-05-16 12:29:20