Admin keys
See who holds every admin key on Strike's contracts, what each key can do, and how that power shrinks before mainnet.
Three deployments on two testnets, read from the chains when the page loads: role logs since each deploy block, every holder confirmed with hasRole, and the last admin actions with their transactions.
Today the admin is the team's deployer key on the testnets (stage 0 below). On mainnet it is meant to be a Safe behind a 73-day timelock. The texts come from the roles table and the trust model . The rest of the evidence is on the proof page.
Role holders
Each deployment's RoleGranted and RoleRevoked logs since its deploy block, replayed in order; every holder they leave is then confirmed with hasRole at one block.
What each role can do
Copied from the audit-readiness roles table and the trust model; roles they do not cover are described from the contract's own functions, linked.
| Role | Can | Cannot | Source |
|---|---|---|---|
| EpochManagerDEFAULT_ADMIN_ROLE | Set the oracle (setOracle), the pricer (setPricer), the spot buffer (at most 200 bps), volatility bounds, the fee manager and timings (bounded); list tokens. Every DEFAULT_ADMIN_ROLE also grants and revokes the other roles of its contract. | Change a vault's mandate, set sigma outside the bounds it set, or change a settlement price once it is recorded. It has no function that moves user funds. Before a settlement price is recorded it can choose it by swapping the oracle (setOracle), and it sets sale prices through setPricer: "cannot move user funds" holds only for an honest admin. | audit-readiness.md |
| EpochManagerGUARDIAN_ROLE | Pause new epochs, proposals and buys; cancel a series only after expiry + settlementGrace with no settlement price recorded. | Block settlement or idle withdrawals; take funds. | audit-readiness.md |
| EpochManagerKEEPER_ROLE | Update sigma within bounds (at most 25% per update, once an hour); open epochs. | Anything else. | audit-readiness.md |
| EpochManagerFACTORY_ROLE | Register new vaults. | Not stated | audit-readiness.md |
| StockOracleDEFAULT_ADMIN_ROLE | List tokens and feeds (setFeed); set the calendar and the sequencer feed. Every DEFAULT_ADMIN_ROLE also grants and revokes the other roles of its contract. | Change a vault's mandate, set sigma outside the bounds it set, or change a settlement price once it is recorded. It has no function that moves user funds. Before a settlement price is recorded it can choose it by pointing the token at another feed (setFeed). Once a settlement price is recorded it is final. | audit-readiness.md |
| AgentRegistryDEFAULT_ADMIN_ROLE | Ban an agent (setStatus), set the ERC-8004 registries and the registry parameters. Every DEFAULT_ADMIN_ROLE also grants and revokes the other roles of its contract. | Change a vault's mandate, set sigma outside the bounds it set, or change a settlement price once it is recorded. It has no function that moves user funds. | trust-model.md |
| AgentRegistrySLASHER_ROLE | Slash bonds, record results. | Not stated | audit-readiness.md |
| FeeManagerDEFAULT_ADMIN_ROLE | Change fees (capped at 30%) and redirect the treasury (setFees, setTreasury). Every DEFAULT_ADMIN_ROLE also grants and revokes the other roles of its contract. | Change a vault's mandate, set sigma outside the bounds it set, or change a settlement price once it is recorded. It has no function that moves user funds. | trust-model.md |
| FeeManagerDEPOSITOR_ROLE | Credit performance fees to an agent and the treasury (creditFees). | Not stated | FeeManager.sol |
| MarketCalendarDEFAULT_ADMIN_ROLE | Grant and revoke CALENDAR_ROLE. Every DEFAULT_ADMIN_ROLE also grants and revokes the other roles of its contract. | Change a vault's mandate, set sigma outside the bounds it set, or change a settlement price once it is recorded. It has no function that moves user funds. | MarketCalendar.sol |
| MarketCalendarCALENDAR_ROLE | Mark NYSE holidays and early closes (setHolidays, setEarlyCloses). | Not stated | MarketCalendar.sol |
| OptionTokenDEFAULT_ADMIN_ROLE | Rewire which contract mints and burns options (setManager); set the metadata URI (setURI). | Not stated | trust-model.md |
| VaultFactoryDEFAULT_ADMIN_ROLE | Raise the ceiling on deposit caps (setMaxDepositCap). | Change a vault's mandate: it is fixed when the vault is created. | trust-model.md |
| MirrorFeedDEFAULT_ADMIN_ROLE | Grant and revoke KEEPER_ROLE on the feed (testnet only). | Not stated | MirrorFeed.sol |
| MirrorFeedKEEPER_ROLE | Push MirrorFeed rounds (testnet only). Every value is checked against the mainnet Chainlink round it copies by the price mirror audit; when it pushes is trusted. | Anything else. | trust-model.md |
| TestStockTokenDEFAULT_ADMIN_ROLE | Mint test stock tokens, pause the token or its oracle flag, and schedule a multiplier change (mint, setPaused, scheduleMultiplier). Test tokens on Arbitrum Sepolia only. | Not stated | TestStockToken.sol |
| UsdgDripowner | Refill and sweep the test-USDG faucet (refill, sweep). | Not stated | UsdgDrip.sol |
| GasDripowner | Allow or remove relayers and sweep the drip's ETH (setRelayer, sweep). | Raise the amount per drip or the daily cap: both are fixed at deployment (amount, dailyCap). | GasDrip.sol |
| GasDriprelayer | Send drip(to): 0.0001 test ETH to a new wallet. Held by the app's /api/gas-drip relayer key (D49). | Drip an address twice, drip to one holding 0.0001 ETH or more, or send more than 20 drips in a UTC day: the contract refuses each (AlreadyDripped, HasGas, DailyCapReached). | decisions.md |
Last admin actions
Role grants and revokes and every admin setter event (PricerSet, OracleSet, FeedSet, SpotBufferSet, SigmaSet, TimingsSet and the rest), newest first, with the sender of each transaction.
Staged path
How the admin's power shrinks, each stage with commitments you can check with a test or a read.
Stage 0: a deployer key on the testnets
CurrentRobinhood Chain testnet (v2 and v3) and Arbitrum Sepolia, today
The deployer 0x26b2…13Ff holds DEFAULT_ADMIN_ROLE on every contract, GUARDIAN_ROLE and the keeper roles. It can use every admin power at once. The CI keeper key 0x317a…AfF76 holds KEEPER_ROLE on the mirrored MirrorFeeds and nothing else.
Every admin call is an event (FeedSet, OracleSet, PricerSet, TimingsSet, RoleGranted), and hasRole answers who holds what: the tables above are read from both.
The price mirror audit fails if an EpochManager stops reading its recorded StockOracle or a StockOracle its audited MirrorFeed. This detects a swap; it does not prevent one.
Stage 1: a Safe behind a 73-day timelock
Robinhood Chain mainnet (chain 4663), at deployment; never run yet
Deploy.s.sol's mainnet path ends with an OpenZeppelin TimelockController as the only holder of DEFAULT_ADMIN_ROLE on all seven contracts and of the calendar's CALENDAR_ROLE. The deployer renounces every admin role, and only the Safe can schedule, cancel and execute. The guardian (the Safe by default) keeps pause, unpause and emergencyCancel without a delay. A feed, oracle or pricer change is public as a CallScheduled event for 73 days before it can run.
The delay is longer than the longest epoch plus the grace, each probed from the contracts; the deploy path refuses a shorter one.
Nobody calls an admin setter directly (not the deployer, the Safe or the guardian), only the Safe schedules, and the delay changes only through itself.
Each of the three calls is public from scheduling and cannot run a second early.
Scheduled the moment the longest possible epoch opens, with the timings at their caps, each call lands after that epoch's honest price is final.
Depositors leave before the call can run: from an idle vault, from a running epoch, and from an epoch whose agent never proposes.
An epoch that opens after the call is scheduled still settles on the honest feed.
For any opening time up to a day after the schedule, proposal time, tenor and settlement time within the grace, the call is still waiting.
Control: with any delay shorter than that window, the same feed swap lands first and the vault settles at the attacker's price.
Stage 2: renounce what is no longer needed
Mainnet, later, one contract at a time
Each contract's admin role is separate, so each can be renounced on its own, as a scheduled renounceRole from the timelock. Once renounced, nobody can grant it again. Cheapest first: OptionToken, VaultFactory, FeeManager, AgentRegistry, then StockOracle and EpochManager when the stock list, the pricer and the bounds are final. GUARDIAN_ROLE probably never.
Renouncing the StockOracle's and the EpochManager's admin role through the timelock makes the three swaps revert even when the timelock executes them, while the guardian still pauses and an epoch still opens, sells and settles.
Check it yourself
Read-only, no key needed.
Is the deployer still the EpochManager's admin on Robinhood Chain testnet v2?
cast call 0x5A3b58DF27e4DD5E0fa6493D90fF653e0E199C99 "hasRole(bytes32,address)(bool)" 0x0000000000000000000000000000000000000000000000000000000000000000 0x26b277b434B1670f207Afd8946edA9AF78A613Ff --rpc-url https://rpc.testnet.chain.robinhood.comEvery pricer change on that EpochManager since its deploy block:
cast logs --address 0x5A3b58DF27e4DD5E0fa6493D90fF653e0E199C99 "PricerSet(address)" --from-block 125880607 --rpc-url https://rpc.testnet.chain.robinhood.com