Official MASTR logo MASTR Support the work
Contents
← Wiki home

Wallets & security

Upgrade authority and the limits of renounced ownership

Removing one permission may leave another route to changing the system.

Security guide · 1 min read

Research articles and reference entries are published in English. Navigation is available in seven languages.

In this article
  1. Build a control inventory

An upgradeable application can change its behaviour through an administrator or governance process. Other roles may control minting, fees, pausing, blacklists or withdrawals. A project announcing renounced ownership must identify the exact permission it removed.

Build a control inventory

For each power, record the controlling account or contract, the approval threshold and any delay. Follow the chain of authority far enough to understand whether one organisation can exercise several roles. A multisig requiring several signatures does not prove that several independent organisations control the keys.

Administrative powers can support maintenance and incident response. They also mean that a previous review may no longer describe the system after a change. The relevant question is how changes are authorised, disclosed and constrained.

Compare the advertised protections with the deployed configuration. Do not treat an ownership event as a universal removal of control. Read audit scope and governance for the related review questions.

Sources

  1. MASTR: Crypto Survival Guide, four original panels
  2. MASTR Research: From Decentralisation to Attention Capture, July 2026

Research checked 5 September 2026. Historical cases retain the date and legal status of the cited record.

Related reading

security

Proxy-upgrade rugs

A proxy delegates calls to implementation code replaceable by an administrator.

MASTR

Support independent research

The investigations, original evidence and guides here are free to read. Voluntary donations help fund the research and keep MASTR’s tools available.

Open wallet