Skip to content
3F Docs

Ownership

This page maps every privileged account on the Ethereum mainnet deployment to the contracts it controls: the Safes and their signers, the operational accounts, who can upgrade what, and who holds each role on each contract. For what each role allows, see Roles. For why ownership is split this way, see Verification Council. Contract addresses are listed on the Deployments overview and the integration pages.

Every Safe below runs Safe v1.4.1 with no transaction guard set. Two of them also have a Zodiac Roles Modifier enabled as a module, which lets specific accounts run a narrow set of calls without collecting the threshold.

Name Address Threshold Signers Modules
3F_ADMIN_PROTECTED 0xA9F5262c1aa97C6E519D6f8837658C8f9979bA24 2 of 3 3F_OWNER, CHAINSECURITY, ARAGON None
3F_PM_OWNER 0xA0f6CbC8dBa8B106473E5F70fe04a3ea6c3bFD26 2 of 3 3F_OWNER, ARAGON, STEAKHOUSE None
FAC_FUND 0xf1C632965888ABA4612EbcD00AB6d2898Cae147b 2 of 3 3F_OWNER, CHAINSECURITY, ARAGON Roles Modifier 0x0fDE5755D4f36bb321ED93C22aC0857398FB78CD
REPAYER 0xe1dD48D8797D83bB98AdA9b4cf8A1c39554d0cb5 2 of 3 3F_LABS, 3F_FOUNDATION, ARAGON_REPAYER None
3F_OWNER 0xC82003FC812F8eFE93cdA63d9f8Ee8c0A3EF5d60 4 of 7 3F signers 1 to 6, 3F_FOUNDATION Roles Modifier 0xEb4F957AC16A51feeE7A12f6610ad75874F8433c
3F_LABS 0x9e2f211E5e8cAaD07F2E2210928Aa274b458042D 2 of 5 3F signers 1 to 5 None
3F_DEV 0xb7794058B48CF9d0DD55a2f4A5379B3610Da34eC 2 of 3 3F signers 1 to 3 None
3F_LEAD 0xea643d989d7373236Dc2684b7d2BDc6f6bBC1e14 1 of 2 3F signers 4 and 5 None
3F_FOUNDATION 0xdb15A55bCBb05d2bF64bB5F8D8fD79FBb850b982 1 of 2 Foundation signers 1 and 2 None

The first four are the Verification Council Safes. 3F_LEAD holds no role on any protocol contract.

Name Address Type Signs for
3F signer 1 0x118D6a9Dc45c0A4C6d68090eF59fB818Baa802b3 EOA 3F_OWNER, 3F_LABS, 3F_DEV
3F signer 2 0x9E7237C460e0a7F3fD69B0928751FeeB54331f86 EOA 3F_OWNER, 3F_LABS, 3F_DEV
3F signer 3 0xD993e26f736Ec1fb54aDBFE69CeD4973Bf32CFc0 EOA 3F_OWNER, 3F_LABS, 3F_DEV
3F signer 4 0xa44481Cd8fa3936F847bd3f6Ed0dfEFBa857C54f EOA 3F_OWNER, 3F_LABS, 3F_LEAD
3F signer 5 0xc3AC7bCd42c0f33F286e5B24591851e7b9132A2e EOA 3F_OWNER, 3F_LABS, 3F_LEAD
3F signer 6 0x0129c2CE87b9DF9955ca3144a5B6F6D7Cf829b86 EOA 3F_OWNER
Foundation signer 1 0xAE278997e11c9C595f11EDc5F99783f3811ef42C EOA 3F_FOUNDATION
Foundation signer 2 0x710780A22edbFaf2fdb095006429088F41CF4489 EOA 3F_FOUNDATION
ARAGON 0xe8B545678da773d2E865dc28e40566b07445C14e Smart account 3F_ADMIN_PROTECTED, 3F_PM_OWNER, FAC_FUND
ARAGON_REPAYER 0x6FfF2908C25030Bf21112EC8E545c650A5792996 Smart account REPAYER
CHAINSECURITY 0xe9DB188CdeE033a2837b1964B00082695fB7eCe2 EOA 3F_ADMIN_PROTECTED, FAC_FUND
STEAKHOUSE 0x827e86072B06674a077f592A531dcE4590aDeCdB Safe (2 of 7) 3F_PM_OWNER

ARAGON_REPAYER runs the same smart-account implementation as ARAGON and is the Aragon seat on the Repayer Safe described on the Verification Council page.

Hot accounts run by 3F services or partners. None of them owns a contract except REBALANCER, which owns the MorphoRebalancer.

Name Address Operator Holds
FACILITATOR 0x95026A338084241E739250f4F9d2F5745dE81bDd 3F back-end Facility facilitator; executor on MorphoFlashLoanRequest, CommitDeposit and MorphoAllocator
GUARDIAN_A 0x296b6A2946F47a1BB8913A6f4338eF963a95ACC4 3F guardian Facility guardian; RequestWhitelist validator
GUARDIAN_B 0x961b27Db4a9AE0C4dF73b34e08f01362f44F8bef Second guardian Facility guardian; RequestWhitelist validator
PAUSER_A 0x457a7882D63a2185CA3cC2F814C64e51a6750388 Hypernative Facility compliance (pause); pauser on both TransferGuards
COMPLIANCE 0x8A58B8EadD9Ce5599bc4D8A0111D2DEC2501c07C 3F back-end Compliance on both TransferGuards; RequestWhitelist compliance officer
CURATOR 0x6F97fD89DFA931683C8c6ffD7c7bA2D37B9873C6 3F back-end Curator on every PositionManager
REBALANCER 0x029b9AaCD5496A27b877f6433468B082b9e4cEEe 3F back-end Owner of MorphoRebalancer; rebalancer and consumer on every Retargetter
CONSUMER 0x2ADaC155B8Decc03D4F5f003d4A02af05Dc74398 3F back-end Consumer on every Facility-bound and early Request
REQUEST_CREATOR 0x2C47E654116ccFc27a4beE06Dd9D8610Df840f83 3F back-end Owner of eight early Requests, all repaid (see below)
MIDAS_PAYMENT 0xFD6EBf2e5801dfd26B66770a479683FC04f0F405 Payment operator PAYMENT_ROLE on every MidasFund

GUARDIAN_B and MIDAS_PAYMENT have never sent a transaction: they only sign off-chain or hold a role for later use.

Implementation upgrades go through the Upgrade Timelock, except for the two facilitator helper proxies, which 3F_ADMIN_PROTECTED administers directly.

0xC1abf27242829D4c8a4dE2704Fa1bC3D29836fA5, a Solady Timelock with a minimum delay of 24 hours (86,400 seconds).

Role Index Holders
ADMIN_ROLE 0 3F_ADMIN_PROTECTED
PROPOSER_ROLE 1 3F_ADMIN_PROTECTED
EXECUTOR_ROLE 2 3F_ADMIN_PROTECTED, 3F_OWNER
CANCELLER_ROLE 3 3F_ADMIN_PROTECTED

The timelock owns all 12 beacons listed on the Deployments overview: CentrifugeFund, USCCFund, ParetoFund, MidasFund, PositionManager, BorrowPosition, TransferGuard, Request, PT Token, YT Token, MorphoFlashLoanRequest and Retargetter.

Admins are stored in the factory that deployed the proxy and read with adminOf(proxy).

Proxy Address Factory Admin
Facility 0x4e013ca8fF612a58F53C822904cDD0eC538a4A4F Grunt ERC1967Factory TIMELOCK
wJAAA 0x86b495e4Cb00AB18Ad94BFD7920479cC79E8eBFE Grunt ERC1967Factory TIMELOCK
wUSCC 0xF458Ad24B1dE7c653e8471efB0b87710b316b7D9 Grunt ERC1967Factory TIMELOCK
wFalconX 0x4614F7A56A3Eb83b2Ff9fA4B4b9575B28Fb68644 Grunt ERC1967Factory TIMELOCK
wmGLO 0xB8d692e46D624b3c650282Ed3011Bf6d7B1dB5e8 Grunt ERC1967Factory TIMELOCK
BorrowOffersRegistry 0x07ab1Ac9cBA9d0CAf5dEF80a463B15e72d9b50c3 Grunt ERC1967Factory TIMELOCK
RequestWhitelist 0x3FcD87948cBF46605D6ded0ed56d3daCcd9daf9e Solady canonical ERC1967Factory TIMELOCK
CommitDeposit 0x19189B5c136c25BD2615D369661fc131419e37f6 Grunt ERC1967Factory 3F_ADMIN_PROTECTED
MorphoAllocator 0x9BDcb584a2304e394705932c8b67114E3908241f Grunt ERC1967Factory 3F_ADMIN_PROTECTED

The Grunt factory is 0x54F862fa0612A8709F6Dec4A7B39AF015CD4E82E and the Solady canonical factory is 0x0000000000006396FF2a80c067f99B3d2Ab4Df24.

Role values are the on-chain bitmask (1 << index) passed to grantRoles. The owner of an OwnableRoles contract can call every owner-or-role function directly, and is the only account that can grant roles.

Owner: FAC_FUND.

Role Value Holders
FACILITATOR_ROLE 1 FACILITATOR, MorphoFlashLoanRequest 0x9cCe1Ec365A9822A257C09cdeF9D0642dfF36108, CommitDeposit, MorphoAllocator
GUARDIAN_ROLE 2 GUARDIAN_A, GUARDIAN_B
COMPLIANCE_ROLE 4 PAUSER_A, 3F_OWNER

COMPLIANCE_ROLE gates pauseFor and revertDeposit. The guardian quorum is set per intent at creation.

Owner: 3F_PM_OWNER, on all 42 PositionManagers (wJAAA, wUSCC, wFalconX, wmGLO and Fission).

Role Value Holders
MINTER_ROLE 1 Facility
CURATOR_ROLE 2 CURATOR
REBALANCER_ROLE 4 MorphoRebalancer 0x882fFC4d28A52Cbd6940dfdb03a93FfCCbE6E096, plus the tier’s own Retargetter on every tier from 2x up

The wJAAA PositionManagers also carry direct grants to 3F_PM_OWNER: curator and rebalancer on 2x, 3x, 4x, 5x, 6x, 8x and 10x, rebalancer on 7x, and curator on 1x. The 9x tier has none.

Ownable. Each borrow position is owned by the PositionManager it belongs to. Offer proposals and revocations are authorized through the BorrowOffersRegistry.

Owner: 3F_PM_OWNER. No account holds PROPOSER_ROLE (1) or GUARDIAN_ROLE (2), so today only 3F_PM_OWNER can post or revoke offers on borrow positions.

Owner: FAC_FUND, on all 38 Retargetters.

Role Value Holders
REBALANCER_ROLE 1 REBALANCER
CONSUMER_ROLE 2 REBALANCER

0x882fFC4d28A52Cbd6940dfdb03a93FfCCbE6E096. Ownable, owned by the REBALANCER account. Not upgradeable.

Owner: FAC_FUND, on every fund. DEPOSITOR_ROLE is held by the Facility and by every Retargetter of the same collateral, including the Fission Retargetter of that collateral.

Fund Count OPERATOR_ROLE (1) DEPOSITOR_ROLE (2) Other
CentrifugeFund (wJAAA) 10 3F_OWNER Facility, 10 Retargetters; 3F_PM_OWNER on Funds 1 to 7 —
USCCFund (wUSCC) 17 3F_OWNER Facility, 17 Retargetters —
ParetoFund (wFalconX) 14 3F_OWNER Facility, 6 Retargetters —
MidasFund (wmGLO) 12 FAC_FUND Facility, 5 Retargetters PAYMENT_ROLE (4): MIDAS_PAYMENT. VAULT_MANAGER_ROLE (8): none

On the MidasFunds the operator role is granted to the owner Safe itself, so there is no separate operator account.

Owner: FAC_FUND, on both guards.

Guard COMPLIANCE_ROLE (1) PAUSER_ROLE (2)
Shared 0x809649b3Af57E0AE8c53342e628F367EaA464622 COMPLIANCE PAUSER_A, 3F_OWNER
Fission 0xE1544f832B3317f32368d0CA5ba7ea053E1112aB COMPLIANCE PAUSER_A

Owner: 3F_PM_OWNER, on wJAAA, wUSCC, wFalconX and wmGLO.

Role Value Holders
ISSUER_ROLE 1 Every fund of the same collateral
SENDER_ROLE 2 Facility, Morpho Blue 0xBBBBBbbBBb9cC5e90e3b3Af64bdAF62C37EEFFCb, MorphoRebalancer, and every PositionManager, MorphoBorrowPosition and Retargetter of the collateral (Fission included)
RECEIVER_ROLE 4 Facility

Asset-specific extra senders: 3F_PM_OWNER on wJAAA, 3F_OWNER on wUSCC, and the unused borrow position 0x90ddD25102a5A8B9Cd69767990C98611995a5B38 on wJAAA. Each wrapper also shows ISSUER_ROLE and SENDER_ROLE on the zero address, set by initialize with no initial issuer; the zero address cannot send transactions, so the grant is inert.

Every Request created by the RequestFactory falls into one of these groups. PT and YT vaults have no owner: they are controlled by their Request.

Group Count Owner PULLER_ROLE (1) CONSUMER_ROLE (2)
Facility-bound 43 REPAYER Facility CONSUMER
Early, all repaid 8 REQUEST_CREATOR Facility CONSUMER
Retargetter-bound 10 Creating Retargetter Creating Retargetter Creating Retargetter
Test 1 REPAYER REPAYER REPAYER

The test Request is 0x9CDa2D104039b892fc13c45C77D05E345577103b.

0x9cCe1Ec365A9822A257C09cdeF9D0642dfF36108. Owner: 3F_OWNER. EXECUTOR_ROLE (1): FACILITATOR. Allowed scripts: SyncDeposit 0xfD893b617b212d64e601eb143F7700BA35485c9A and SyncAllocatorDeposit 0xe65De96B5d032344d7153e59Df57C4df69e44C88.

Two helper contracts from the facilitators repository hold FACILITATOR_ROLE on the Facility. Both are owned by 3F_OWNER and upgradeable directly by 3F_ADMIN_PROTECTED, without the timelock.

Contract Address EXECUTOR_ROLE (1)
CommitDeposit 0x19189B5c136c25BD2615D369661fc131419e37f6 FACILITATOR
MorphoAllocator 0x9BDcb584a2304e394705932c8b67114E3908241f FACILITATOR, MorphoFlashLoanRequest

0x3FcD87948cBF46605D6ded0ed56d3daCcd9daf9e. Ownable, owned by 3F_LABS. While the owner is set, only the owner can submit whitelist and unwhitelist, and each call also needs a validator quorum of signatures.

Setting Value
Validators GUARDIAN_A, GUARDIAN_B, and the placeholders 0x000000000000000000000000000000000000dEaD and 0x00000000000000000000000000000000DeaDBeef
Quorum 1
Compliance officers (can pauseFor / unpause) COMPLIANCE

Two Safes delegate a few calls through a Zodiac Roles Modifier v2 module. Each member can execute only the scoped call, from the Safe, without collecting the threshold. Both modifiers are owned by the Safe they serve, so only that Safe can change members or scopes.

0xEb4F957AC16A51feeE7A12f6610ad75874F8433c, role pauser.

Member Allowed calls
3F signers 1 to 6 Facility.pauseFor(duration) and TransferGuard.pauseFor(token, duration) on the shared guard, with duration between 1,800 and 3,600 seconds

Any single 3F signer can therefore pause the Facility or a shared-guard token for 30 to 60 minutes. 0x1416ebd818B3A6c7EB287b341d2c1637664156D6 and 0xCBB347c09eBAb616ffB2A6D79F07b9cF8C728D0F are still enabled as modules but their pauser role was revoked, so they can no longer execute anything.

0x0fDE5755D4f36bb321ED93C22aC0857398FB78CD.

Role Member Allowed calls
setDescriptor 3F_DEV Facility.setDescriptor(any)
cancelRequest 3F_OWNER CentrifugeFund.cancelRequest(any) on wJAAA Funds 1 to 10

These contracts are owned by protocol Safes but are not part of the live deployment. They hold no value and no role on a live contract, except the wJAAA sender grant noted above.

Contract Address Owner Notes
BorrowOffersRegistry 0xAd3DF76A70724c94a7e93F000696b50e2728cFd2 3F_PM_OWNER Same implementation as the live registry; deployed alongside it and unused. Proxy admin TIMELOCK
MorphoAllocator proxy 0xb8947d2725D3E9De9b19fC720f053300c50981e5 3F_OWNER Stray proxy of the MorphoAllocator v2 implementation. Proxy admin 3F_ADMIN_PROTECTED
MorphoBorrowPosition × 13 — 3F_PM_OWNER Empty borrow positions on non-canonical wJAAA and wmGLO markets, not bound to a PositionManager
Terminal window
export ETH_RPC_URL=<mainnet RPC>
# Owner and role bitmask of any OwnableRoles contract
cast call 0x4e013ca8fF612a58F53C822904cDD0eC538a4A4F "owner()(address)"
cast call 0x4e013ca8fF612a58F53C822904cDD0eC538a4A4F "rolesOf(address)(uint256)" <account>
# Safe signers and threshold
cast call <safe> "getOwners()(address[])"
cast call <safe> "getThreshold()(uint256)"
# Timelock delay and role holders (roles are indices 0-3)
cast call 0xC1abf27242829D4c8a4dE2704Fa1bC3D29836fA5 "minDelay()(uint256)"
cast call 0xC1abf27242829D4c8a4dE2704Fa1bC3D29836fA5 "roleHolders(uint256)(address[])" 1
# Proxy admin, from the factory that deployed the proxy
cast call 0x54F862fa0612A8709F6Dec4A7B39AF015CD4E82E "adminOf(address)(address)" <proxy>