官方的 MASTR 标志 MASTR 支持这项工作
目录
← 知识库首页

Wallets & security

Upgrade authority and the limits of renounced ownership

Removing one permission may leave another route to changing the system.

Security guide · 1 min read

研究文章和参考条目以英语发布。导航提供七种语言。

本文目录
  1. Build a control inventory

An upgradeable application can change its behaviour through an administrator or governance process. Other roles may control minting, fees, pausing, blacklists or withdrawals. A project announcing renounced ownership must identify the exact permission it removed.

Build a control inventory

For each power, record the controlling account or contract, the approval threshold and any delay. Follow the chain of authority far enough to understand whether one organisation can exercise several roles. A multisig requiring several signatures does not prove that several independent organisations control the keys.

Administrative powers can support maintenance and incident response. They also mean that a previous review may no longer describe the system after a change. The relevant question is how changes are authorised, disclosed and constrained.

Compare the advertised protections with the deployed configuration. Do not treat an ownership event as a universal removal of control. Read audit scope and governance for the related review questions.

来源

  1. MASTR: Crypto Survival Guide, four original panels
  2. MASTR Research: From Decentralisation to Attention Capture, July 2026

资料核对日期:2026年9月5日. Historical cases retain the date and legal status of the cited record.

相关阅读

钱包与安全

Delegatecall authority

Delegatecall runs another contract's code in the caller's storage context.

钱包与安全

Proxy-upgrade rugs

A proxy delegates calls to implementation code replaceable by an administrator.

MASTR

支持独立研究

这里的调查、原始证据和指南均可免费阅读。自愿捐赠帮助支付研究成本,让 MASTR 能够继续提供工具。

打开钱包