New ERC-20 approval to unverified contract from whale
Sushi (SushiSwap) — v2 + v3 + Trident + BentoBox/Kashi + SushiXSwap's assessment for RD-F-096 — scored green on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
No high-TVL user granting a new ERC-20 approval to an unverified contract interacting with Sushi core contracts detected as of 2026-05-17. Given the RouteProcessor2 approval-drain history (2023), this signal is particularly relevant. No current anomalous approval pattern from known whale addresses. T-09 v2-deferred signal.
Sources #
- URLRouteProcessor2 Post Mortem — SushiRouteProcessor2 post-mortem — approval-drain attack vector contextretrieved 2026-05-17
Methodology #
Detect whether a top-TVL depositor grants a new token approval to an unverified contract that interacts with this protocol.
See the full factor methodology and distribution across all protocols →
rubric_version v1.7.0 protocol sushi factor RD-F-096 score green collected_at 2026-05-16 19:50:37