Redemption Risk
Evaluates the blast radius of a single privileged-key compromise. The breadth of powers attached to privileged roles, and whether they include custodial reach over user funds, is the primary input.
| Tier | Reasoning | Evidence |
|---|---|---|
| Full centralized control | The damage from any single key compromise is bounded by what that key's scope permits. Combined pause, mint, freeze, seize, redirect, and upgrade authority means the blast radius of a single compromise is total. | 80.5% of stolen DeFi funds in 2024 came from compromised accounts and off-chain attacks. USDC's five privileged roles (pauser, blacklister, masterMinter, owner, proxyOwner) combine pause + freeze/seize + mint + upgrade authority and anchor the worst tier. |
| Broad operational controls without seizure | Separating operational from custodial powers materially lowers the loss profile: a compromise of broad operational authority can disrupt the protocol but cannot directly seize or redirect user assets. | The StablR exploit (May 2026, $10.4M in unbacked EURR and USDR minting) illustrates the residual exposure — broad mint scope turned a single contract compromise into an asset-wide depeg even without direct seizure authority. |
| Narrow, non-custodial powers | Narrow, non-custodial powers mean that full compromise of every privileged role cannot directly impair user funds. | GMX V2's isolated-market design, where privileged powers are scoped away from custody of user assets, anchors the best tier. |