defirisk.co
rubric v1.7.0

Single admin EOA

Sushi (SushiSwap) — v2 + v3 + Trident + BentoBox/Kashi + SushiXSwap's assessment for RD-F-027 — scored green on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

No single EOA holds live admin authority over core protocol. Ops Multisig (3-of-5) controls operations. Deployer EOA (0xf942dba4159cb61f8ad88ca4a83f5204e8f4a6bd) transferred control historically. SUSHI token owner = MasterChef contract (not bare EOA). V3 factory owner not fully resolved via on-chain read [?] but Etherscan page shows no EOA label. Scored green — effective centralization is multisig-based.

Sources #

Methodology #

Determine whether the effective upgrade/owner/rescue role is held by a single EOA (not a multisig) with no timelock on sensitive operations.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol sushi factor RD-F-027 score green collected_at 2026-05-16 19:50:37