defirisk.co
rubric v1.7.0

Admin = deployer EOA after 7 days

Yearn Finance's assessment for RD-F-043 — scored green on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

Admin role held by ychad 6-of-9 multisig. Not a deployer EOA. V3 vault factory deploys vaults with role_manager set at initialization (ychad-controlled Role Manager). Cache deployer address is null (unresolved) but historical Yearn deployer (Banteg/Andre Cronje) transferred admin long ago. Protocol has operated under multisig governance since YFI launch (2020).

Sources #

Methodology #

Determine whether, at t = deploy+7d, the admin address still equals the deployer EOA with no evidence of transfer to a multisig.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol yearn-finance factor RD-F-043 score green collected_at 2026-05-16 08:34:32