Contract Upgradability Permissions
Evaluates who holds the authority to change deployed contract code. Upgrade authority is the protocol's root authority, so the concentration and transparency of upgrade rights is the primary input.
| Tier | Reasoning | Evidence |
|---|---|---|
| Single signer or undisclosed proxy admin | Upgrade authority is the protocol's root authority — anyone with upgrade rights can rewrite contracts to grant themselves any other privilege. A single signer or undisclosed proxy admin is worst-case because every other control can be bypassed through it. | Radiant Capital (October 2024, $53M) was drained via a malicious ownership transfer through an upgrade path with no timelock. Ankr's deployer EOA (December 2022) pushed a malicious mint implementation through unchecked upgrade authority. |
| Multisig with modest threshold and limited transparency | A multisig distributes the compromise surface across multiple keys, so no single holder can unilaterally rewrite the protocol. Modest thresholds and limited transparency leave residual concentration risk and impede external verification of true signer independence. | Modal configuration across mid-tier DeFi protocols. Compound v3 and Aave V3 operate at this tier with multisig-controlled upgrade authority and 24–48h timelock, providing meaningful but not maximal protection. |
| High-quorum multisig with verified signers and tightly scoped upgrade path, or immutable contracts | A high-quorum multisig with verified, independent signers and a tightly-scoped upgrade path narrows the compromise surface to a level requiring broad collusion; immutable contracts eliminate the attack surface entirely. | Arbitrum's Security Council 9-of-12 multisig with a 13-day timelock anchors the top multisig tier; immutable contracts (Liquity, Uniswap V2) remove the upgrade attack surface entirely. |