Ownership
This page maps every privileged account on the Ethereum mainnet deployment to the contracts it controls: the Safes and their signers, the operational accounts, who can upgrade what, and who holds each role on each contract. For what each role allows, see Roles. For why ownership is split this way, see Verification Council. Contract addresses are listed on the Deployments overview and the integration pages.
Accounts
Section titled “Accounts”Every Safe below runs Safe v1.4.1 with no transaction guard set. Two of them also have a Zodiac Roles Modifier enabled as a module, which lets specific accounts run a narrow set of calls without collecting the threshold.
| Name | Address | Threshold | Signers | Modules |
|---|---|---|---|---|
3F_ADMIN_PROTECTED |
0xA9F5262c1aa97C6E519D6f8837658C8f9979bA24 |
2 of 3 | 3F_OWNER, CHAINSECURITY, ARAGON |
None |
3F_PM_OWNER |
0xA0f6CbC8dBa8B106473E5F70fe04a3ea6c3bFD26 |
2 of 3 | 3F_OWNER, ARAGON, STEAKHOUSE |
None |
FAC_FUND |
0xf1C632965888ABA4612EbcD00AB6d2898Cae147b |
2 of 3 | 3F_OWNER, CHAINSECURITY, ARAGON |
Roles Modifier 0x0fDE5755D4f36bb321ED93C22aC0857398FB78CD |
REPAYER |
0xe1dD48D8797D83bB98AdA9b4cf8A1c39554d0cb5 |
2 of 3 | 3F_LABS, 3F_FOUNDATION, ARAGON_REPAYER |
None |
3F_OWNER |
0xC82003FC812F8eFE93cdA63d9f8Ee8c0A3EF5d60 |
4 of 7 | 3F signers 1 to 6, 3F_FOUNDATION |
Roles Modifier 0xEb4F957AC16A51feeE7A12f6610ad75874F8433c |
3F_LABS |
0x9e2f211E5e8cAaD07F2E2210928Aa274b458042D |
2 of 5 | 3F signers 1 to 5 | None |
3F_DEV |
0xb7794058B48CF9d0DD55a2f4A5379B3610Da34eC |
2 of 3 | 3F signers 1 to 3 | None |
3F_LEAD |
0xea643d989d7373236Dc2684b7d2BDc6f6bBC1e14 |
1 of 2 | 3F signers 4 and 5 | None |
3F_FOUNDATION |
0xdb15A55bCBb05d2bF64bB5F8D8fD79FBb850b982 |
1 of 2 | Foundation signers 1 and 2 | None |
The first four are the Verification Council Safes. 3F_LEAD holds no role on any protocol contract.
Signers
Section titled “Signers”| Name | Address | Type | Signs for |
|---|---|---|---|
| 3F signer 1 | 0x118D6a9Dc45c0A4C6d68090eF59fB818Baa802b3 |
EOA | 3F_OWNER, 3F_LABS, 3F_DEV |
| 3F signer 2 | 0x9E7237C460e0a7F3fD69B0928751FeeB54331f86 |
EOA | 3F_OWNER, 3F_LABS, 3F_DEV |
| 3F signer 3 | 0xD993e26f736Ec1fb54aDBFE69CeD4973Bf32CFc0 |
EOA | 3F_OWNER, 3F_LABS, 3F_DEV |
| 3F signer 4 | 0xa44481Cd8fa3936F847bd3f6Ed0dfEFBa857C54f |
EOA | 3F_OWNER, 3F_LABS, 3F_LEAD |
| 3F signer 5 | 0xc3AC7bCd42c0f33F286e5B24591851e7b9132A2e |
EOA | 3F_OWNER, 3F_LABS, 3F_LEAD |
| 3F signer 6 | 0x0129c2CE87b9DF9955ca3144a5B6F6D7Cf829b86 |
EOA | 3F_OWNER |
| Foundation signer 1 | 0xAE278997e11c9C595f11EDc5F99783f3811ef42C |
EOA | 3F_FOUNDATION |
| Foundation signer 2 | 0x710780A22edbFaf2fdb095006429088F41CF4489 |
EOA | 3F_FOUNDATION |
ARAGON |
0xe8B545678da773d2E865dc28e40566b07445C14e |
Smart account | 3F_ADMIN_PROTECTED, 3F_PM_OWNER, FAC_FUND |
ARAGON_REPAYER |
0x6FfF2908C25030Bf21112EC8E545c650A5792996 |
Smart account | REPAYER |
CHAINSECURITY |
0xe9DB188CdeE033a2837b1964B00082695fB7eCe2 |
EOA | 3F_ADMIN_PROTECTED, FAC_FUND |
STEAKHOUSE |
0x827e86072B06674a077f592A531dcE4590aDeCdB |
Safe (2 of 7) | 3F_PM_OWNER |
ARAGON_REPAYER runs the same smart-account implementation as ARAGON and is the Aragon seat on the Repayer Safe described on the Verification Council page.
Operational Accounts
Section titled “Operational Accounts”Hot accounts run by 3F services or partners. None of them owns a contract except REBALANCER, which owns the MorphoRebalancer.
| Name | Address | Operator | Holds |
|---|---|---|---|
FACILITATOR |
0x95026A338084241E739250f4F9d2F5745dE81bDd |
3F back-end | Facility facilitator; executor on MorphoFlashLoanRequest, CommitDeposit and MorphoAllocator |
GUARDIAN_A |
0x296b6A2946F47a1BB8913A6f4338eF963a95ACC4 |
3F guardian | Facility guardian; RequestWhitelist validator |
GUARDIAN_B |
0x961b27Db4a9AE0C4dF73b34e08f01362f44F8bef |
Second guardian | Facility guardian; RequestWhitelist validator |
PAUSER_A |
0x457a7882D63a2185CA3cC2F814C64e51a6750388 |
Hypernative | Facility compliance (pause); pauser on both TransferGuards |
COMPLIANCE |
0x8A58B8EadD9Ce5599bc4D8A0111D2DEC2501c07C |
3F back-end | Compliance on both TransferGuards; RequestWhitelist compliance officer |
CURATOR |
0x6F97fD89DFA931683C8c6ffD7c7bA2D37B9873C6 |
3F back-end | Curator on every PositionManager |
REBALANCER |
0x029b9AaCD5496A27b877f6433468B082b9e4cEEe |
3F back-end | Owner of MorphoRebalancer; rebalancer and consumer on every Retargetter |
CONSUMER |
0x2ADaC155B8Decc03D4F5f003d4A02af05Dc74398 |
3F back-end | Consumer on every Facility-bound and early Request |
REQUEST_CREATOR |
0x2C47E654116ccFc27a4beE06Dd9D8610Df840f83 |
3F back-end | Owner of eight early Requests, all repaid (see below) |
MIDAS_PAYMENT |
0xFD6EBf2e5801dfd26B66770a479683FC04f0F405 |
Payment operator | PAYMENT_ROLE on every MidasFund |
GUARDIAN_B and MIDAS_PAYMENT have never sent a transaction: they only sign off-chain or hold a role for later use.
Upgrades
Section titled “Upgrades”Implementation upgrades go through the Upgrade Timelock, except for the two facilitator helper proxies, which 3F_ADMIN_PROTECTED administers directly.
Upgrade Timelock
Section titled “Upgrade Timelock”0xC1abf27242829D4c8a4dE2704Fa1bC3D29836fA5, a Solady Timelock with a minimum delay of 24 hours (86,400 seconds).
| Role | Index | Holders |
|---|---|---|
ADMIN_ROLE |
0 | 3F_ADMIN_PROTECTED |
PROPOSER_ROLE |
1 | 3F_ADMIN_PROTECTED |
EXECUTOR_ROLE |
2 | 3F_ADMIN_PROTECTED, 3F_OWNER |
CANCELLER_ROLE |
3 | 3F_ADMIN_PROTECTED |
Beacons
Section titled “Beacons”The timelock owns all 12 beacons listed on the Deployments overview: CentrifugeFund, USCCFund, ParetoFund, MidasFund, PositionManager, BorrowPosition, TransferGuard, Request, PT Token, YT Token, MorphoFlashLoanRequest and Retargetter.
ERC-1967 Proxies
Section titled “ERC-1967 Proxies”Admins are stored in the factory that deployed the proxy and read with adminOf(proxy).
| Proxy | Address | Factory | Admin |
|---|---|---|---|
| Facility | 0x4e013ca8fF612a58F53C822904cDD0eC538a4A4F |
Grunt ERC1967Factory |
TIMELOCK |
| wJAAA | 0x86b495e4Cb00AB18Ad94BFD7920479cC79E8eBFE |
Grunt ERC1967Factory |
TIMELOCK |
| wUSCC | 0xF458Ad24B1dE7c653e8471efB0b87710b316b7D9 |
Grunt ERC1967Factory |
TIMELOCK |
| wFalconX | 0x4614F7A56A3Eb83b2Ff9fA4B4b9575B28Fb68644 |
Grunt ERC1967Factory |
TIMELOCK |
| wmGLO | 0xB8d692e46D624b3c650282Ed3011Bf6d7B1dB5e8 |
Grunt ERC1967Factory |
TIMELOCK |
| BorrowOffersRegistry | 0x07ab1Ac9cBA9d0CAf5dEF80a463B15e72d9b50c3 |
Grunt ERC1967Factory |
TIMELOCK |
| RequestWhitelist | 0x3FcD87948cBF46605D6ded0ed56d3daCcd9daf9e |
Solady canonical ERC1967Factory |
TIMELOCK |
| CommitDeposit | 0x19189B5c136c25BD2615D369661fc131419e37f6 |
Grunt ERC1967Factory |
3F_ADMIN_PROTECTED |
| MorphoAllocator | 0x9BDcb584a2304e394705932c8b67114E3908241f |
Grunt ERC1967Factory |
3F_ADMIN_PROTECTED |
The Grunt factory is 0x54F862fa0612A8709F6Dec4A7B39AF015CD4E82E and the Solady canonical factory is 0x0000000000006396FF2a80c067f99B3d2Ab4Df24.
Contract Roles
Section titled “Contract Roles”Role values are the on-chain bitmask (1 << index) passed to grantRoles. The owner of an OwnableRoles contract can call every owner-or-role function directly, and is the only account that can grant roles.
Facility
Section titled “Facility”Owner: FAC_FUND.
| Role | Value | Holders |
|---|---|---|
FACILITATOR_ROLE |
1 | FACILITATOR, MorphoFlashLoanRequest 0x9cCe1Ec365A9822A257C09cdeF9D0642dfF36108, CommitDeposit, MorphoAllocator |
GUARDIAN_ROLE |
2 | GUARDIAN_A, GUARDIAN_B |
COMPLIANCE_ROLE |
4 | PAUSER_A, 3F_OWNER |
COMPLIANCE_ROLE gates pauseFor and revertDeposit. The guardian quorum is set per intent at creation.
PositionManager
Section titled “PositionManager”Owner: 3F_PM_OWNER, on all 42 PositionManagers (wJAAA, wUSCC, wFalconX, wmGLO and Fission).
| Role | Value | Holders |
|---|---|---|
MINTER_ROLE |
1 | Facility |
CURATOR_ROLE |
2 | CURATOR |
REBALANCER_ROLE |
4 | MorphoRebalancer 0x882fFC4d28A52Cbd6940dfdb03a93FfCCbE6E096, plus the tier’s own Retargetter on every tier from 2x up |
The wJAAA PositionManagers also carry direct grants to 3F_PM_OWNER: curator and rebalancer on 2x, 3x, 4x, 5x, 6x, 8x and 10x, rebalancer on 7x, and curator on 1x. The 9x tier has none.
MorphoBorrowPosition
Section titled “MorphoBorrowPosition”Ownable. Each borrow position is owned by the PositionManager it belongs to. Offer proposals and revocations are authorized through the BorrowOffersRegistry.
BorrowOffersRegistry
Section titled “BorrowOffersRegistry”Owner: 3F_PM_OWNER. No account holds PROPOSER_ROLE (1) or GUARDIAN_ROLE (2), so today only 3F_PM_OWNER can post or revoke offers on borrow positions.
Retargetter
Section titled “Retargetter”Owner: FAC_FUND, on all 38 Retargetters.
| Role | Value | Holders |
|---|---|---|
REBALANCER_ROLE |
1 | REBALANCER |
CONSUMER_ROLE |
2 | REBALANCER |
MorphoRebalancer
Section titled “MorphoRebalancer”0x882fFC4d28A52Cbd6940dfdb03a93FfCCbE6E096. Ownable, owned by the REBALANCER account. Not upgradeable.
Owner: FAC_FUND, on every fund. DEPOSITOR_ROLE is held by the Facility and by every Retargetter of the same collateral, including the Fission Retargetter of that collateral.
| Fund | Count | OPERATOR_ROLE (1) |
DEPOSITOR_ROLE (2) |
Other |
|---|---|---|---|---|
| CentrifugeFund (wJAAA) | 10 | 3F_OWNER |
Facility, 10 Retargetters; 3F_PM_OWNER on Funds 1 to 7 |
— |
| USCCFund (wUSCC) | 17 | 3F_OWNER |
Facility, 17 Retargetters | — |
| ParetoFund (wFalconX) | 14 | 3F_OWNER |
Facility, 6 Retargetters | — |
| MidasFund (wmGLO) | 12 | FAC_FUND |
Facility, 5 Retargetters | PAYMENT_ROLE (4): MIDAS_PAYMENT. VAULT_MANAGER_ROLE (8): none |
On the MidasFunds the operator role is granted to the owner Safe itself, so there is no separate operator account.
TransferGuard
Section titled “TransferGuard”Owner: FAC_FUND, on both guards.
| Guard | COMPLIANCE_ROLE (1) |
PAUSER_ROLE (2) |
|---|---|---|
Shared 0x809649b3Af57E0AE8c53342e628F367EaA464622 |
COMPLIANCE |
PAUSER_A, 3F_OWNER |
Fission 0xE1544f832B3317f32368d0CA5ba7ea053E1112aB |
COMPLIANCE |
PAUSER_A |
Wrapped Assets
Section titled “Wrapped Assets”Owner: 3F_PM_OWNER, on wJAAA, wUSCC, wFalconX and wmGLO.
| Role | Value | Holders |
|---|---|---|
ISSUER_ROLE |
1 | Every fund of the same collateral |
SENDER_ROLE |
2 | Facility, Morpho Blue 0xBBBBBbbBBb9cC5e90e3b3Af64bdAF62C37EEFFCb, MorphoRebalancer, and every PositionManager, MorphoBorrowPosition and Retargetter of the collateral (Fission included) |
RECEIVER_ROLE |
4 | Facility |
Asset-specific extra senders: 3F_PM_OWNER on wJAAA, 3F_OWNER on wUSCC, and the unused borrow position 0x90ddD25102a5A8B9Cd69767990C98611995a5B38 on wJAAA. Each wrapper also shows ISSUER_ROLE and SENDER_ROLE on the zero address, set by initialize with no initial issuer; the zero address cannot send transactions, so the grant is inert.
Requests
Section titled “Requests”Every Request created by the RequestFactory falls into one of these groups. PT and YT vaults have no owner: they are controlled by their Request.
| Group | Count | Owner | PULLER_ROLE (1) |
CONSUMER_ROLE (2) |
|---|---|---|---|---|
| Facility-bound | 43 | REPAYER |
Facility | CONSUMER |
| Early, all repaid | 8 | REQUEST_CREATOR |
Facility | CONSUMER |
| Retargetter-bound | 10 | Creating Retargetter | Creating Retargetter | Creating Retargetter |
| Test | 1 | REPAYER |
REPAYER |
REPAYER |
The test Request is 0x9CDa2D104039b892fc13c45C77D05E345577103b.
MorphoFlashLoanRequest
Section titled “MorphoFlashLoanRequest”0x9cCe1Ec365A9822A257C09cdeF9D0642dfF36108. Owner: 3F_OWNER. EXECUTOR_ROLE (1): FACILITATOR. Allowed scripts: SyncDeposit 0xfD893b617b212d64e601eb143F7700BA35485c9A and SyncAllocatorDeposit 0xe65De96B5d032344d7153e59Df57C4df69e44C88.
Facilitator Helpers
Section titled “Facilitator Helpers”Two helper contracts from the facilitators repository hold FACILITATOR_ROLE on the Facility. Both are owned by 3F_OWNER and upgradeable directly by 3F_ADMIN_PROTECTED, without the timelock.
| Contract | Address | EXECUTOR_ROLE (1) |
|---|---|---|
| CommitDeposit | 0x19189B5c136c25BD2615D369661fc131419e37f6 |
FACILITATOR |
| MorphoAllocator | 0x9BDcb584a2304e394705932c8b67114E3908241f |
FACILITATOR, MorphoFlashLoanRequest |
RequestWhitelist
Section titled “RequestWhitelist”0x3FcD87948cBF46605D6ded0ed56d3daCcd9daf9e. Ownable, owned by 3F_LABS. While the owner is set, only the owner can submit whitelist and unwhitelist, and each call also needs a validator quorum of signatures.
| Setting | Value |
|---|---|
| Validators | GUARDIAN_A, GUARDIAN_B, and the placeholders 0x000000000000000000000000000000000000dEaD and 0x00000000000000000000000000000000DeaDBeef |
| Quorum | 1 |
Compliance officers (can pauseFor / unpause) |
COMPLIANCE |
Roles Modifiers
Section titled “Roles Modifiers”Two Safes delegate a few calls through a Zodiac Roles Modifier v2 module. Each member can execute only the scoped call, from the Safe, without collecting the threshold. Both modifiers are owned by the Safe they serve, so only that Safe can change members or scopes.
3F_OWNER
Section titled “3F_OWNER”0xEb4F957AC16A51feeE7A12f6610ad75874F8433c, role pauser.
| Member | Allowed calls |
|---|---|
| 3F signers 1 to 6 | Facility.pauseFor(duration) and TransferGuard.pauseFor(token, duration) on the shared guard, with duration between 1,800 and 3,600 seconds |
Any single 3F signer can therefore pause the Facility or a shared-guard token for 30 to 60 minutes. 0x1416ebd818B3A6c7EB287b341d2c1637664156D6 and 0xCBB347c09eBAb616ffB2A6D79F07b9cF8C728D0F are still enabled as modules but their pauser role was revoked, so they can no longer execute anything.
FAC_FUND
Section titled “FAC_FUND”0x0fDE5755D4f36bb321ED93C22aC0857398FB78CD.
| Role | Member | Allowed calls |
|---|---|---|
setDescriptor |
3F_DEV |
Facility.setDescriptor(any) |
cancelRequest |
3F_OWNER |
CentrifugeFund.cancelRequest(any) on wJAAA Funds 1 to 10 |
Unlisted Contracts
Section titled “Unlisted Contracts”These contracts are owned by protocol Safes but are not part of the live deployment. They hold no value and no role on a live contract, except the wJAAA sender grant noted above.
| Contract | Address | Owner | Notes |
|---|---|---|---|
| BorrowOffersRegistry | 0xAd3DF76A70724c94a7e93F000696b50e2728cFd2 |
3F_PM_OWNER |
Same implementation as the live registry; deployed alongside it and unused. Proxy admin TIMELOCK |
| MorphoAllocator proxy | 0xb8947d2725D3E9De9b19fC720f053300c50981e5 |
3F_OWNER |
Stray proxy of the MorphoAllocator v2 implementation. Proxy admin 3F_ADMIN_PROTECTED |
| MorphoBorrowPosition × 13 | — | 3F_PM_OWNER |
Empty borrow positions on non-canonical wJAAA and wmGLO markets, not bound to a PositionManager |
Verifying On-Chain
Section titled “Verifying On-Chain”export ETH_RPC_URL=<mainnet RPC>
# Owner and role bitmask of any OwnableRoles contractcast call 0x4e013ca8fF612a58F53C822904cDD0eC538a4A4F "owner()(address)"cast call 0x4e013ca8fF612a58F53C822904cDD0eC538a4A4F "rolesOf(address)(uint256)" <account>
# Safe signers and thresholdcast call <safe> "getOwners()(address[])"cast call <safe> "getThreshold()(uint256)"
# Timelock delay and role holders (roles are indices 0-3)cast call 0xC1abf27242829D4c8a4dE2704Fa1bC3D29836fA5 "minDelay()(uint256)"cast call 0xC1abf27242829D4c8a4dE2704Fa1bC3D29836fA5 "roleHolders(uint256)(address[])" 1
# Proxy admin, from the factory that deployed the proxycast call 0x54F862fa0612A8709F6Dec4A7B39AF015CD4E82E "adminOf(address)(address)" <proxy>