Skip to content

Security Observation: Dormant upgrade authority for DLMM program #269

@contactn8n410-del

Description

@contactn8n410-del

Observation

On-chain analysis shows the upgrade authority for Meteora DLMM (LBUZKhRxPF3XUpBCjp4YzTKgLccjZhTSDM9YuVaPwxo) is JADaUV8k...CVLd, which has:

  • 0.23 SOL balance
  • 0 recent transactions

Context

A dormant authority could indicate cold storage (good) or inaccessible key (bad). If the key is lost, the team would be unable to patch critical vulnerabilities.

Recommendation

  1. Publicly document key management practices
  2. Consider timelock mechanisms
  3. Consider multisig upgrade authority

Methodology

Data from public blockchain state via solscan-cli --power-map.

Responsible disclosure of publicly observable state.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions