defirisk.co
rubric v1.7.0

Guardian/pause-keeper distinct from upgrader

StakeWise v3's assessment for RD-F-034 — scored red on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

No separate guardian/pauser role distinct from the upgrader. The DAO Treasury Safe is simultaneously the upgrader, the emergency responder (Nov 2025), and holds the SafeSnap veto capability. The SafeSnap veto (documented: DAO can reject malicious proposals) is held by the same Safe that executes them — no independence between cancel role and execute role.

Sources #

  • URL
    Balancer hacker loses $20M — DL NewsDL News: seven-member DAO multi-signature wallet executed transactions granting controller privileges — same entity as governance executorretrieved 2026-05-16
  • Internal
    StakeWise profile §6 — governance topology00-profile.md §6: SafeSnap veto held by same Safe; Nov 2025 emergency action showed Safe is the emergency actorretrieved 2026-05-16

Methodology #

Determine whether a pauser/guardian role exists and is held by an address distinct from the upgrader address.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol stakewise factor RD-F-034 score red collected_at 2026-05-16 01:03:28