Unaudited · TestnetExperimental software. Do not use real funds.
Strike
09GovernanceLive · 46630 and 421614

Admin keys

See who holds every admin key on Strike's contracts, what each key can do, and how that power shrinks before mainnet.

Three deployments on two testnets, read from the chains when the page loads: role logs since each deploy block, every holder confirmed with hasRole, and the last admin actions with their transactions.

Today the admin is the team's deployer key on the testnets (stage 0 below). On mainnet it is meant to be a Safe behind a 73-day timelock. The texts come from the roles table and the trust model . The rest of the evidence is on the proof page.

Deployments
3
46630 v2 and v3 · 421614 v3
Roles with a holder
AccessControl roles and Ownable owners
Distinct holders
confirmed with hasRole or owner()
Unknown holders
every holder is a team key or a Strike contract
01

Role holders

Each deployment's RoleGranted and RoleRevoked logs since its deploy block, replayed in order; every holder they leave is then confirmed with hasRole at one block.

Reading Robinhood Chain testnet v2…

02

What each role can do

Copied from the audit-readiness roles table and the trust model; roles they do not cover are described from the contract's own functions, linked.

RoleCanCannotSource
EpochManagerDEFAULT_ADMIN_ROLESet the oracle (setOracle), the pricer (setPricer), the spot buffer (at most 200 bps), volatility bounds, the fee manager and timings (bounded); list tokens. Every DEFAULT_ADMIN_ROLE also grants and revokes the other roles of its contract.Change a vault's mandate, set sigma outside the bounds it set, or change a settlement price once it is recorded. It has no function that moves user funds. Before a settlement price is recorded it can choose it by swapping the oracle (setOracle), and it sets sale prices through setPricer: "cannot move user funds" holds only for an honest admin.audit-readiness.md
EpochManagerGUARDIAN_ROLEPause new epochs, proposals and buys; cancel a series only after expiry + settlementGrace with no settlement price recorded.Block settlement or idle withdrawals; take funds.audit-readiness.md
EpochManagerKEEPER_ROLEUpdate sigma within bounds (at most 25% per update, once an hour); open epochs.Anything else.audit-readiness.md
EpochManagerFACTORY_ROLERegister new vaults.Not statedaudit-readiness.md
StockOracleDEFAULT_ADMIN_ROLEList tokens and feeds (setFeed); set the calendar and the sequencer feed. Every DEFAULT_ADMIN_ROLE also grants and revokes the other roles of its contract.Change a vault's mandate, set sigma outside the bounds it set, or change a settlement price once it is recorded. It has no function that moves user funds. Before a settlement price is recorded it can choose it by pointing the token at another feed (setFeed). Once a settlement price is recorded it is final.audit-readiness.md
AgentRegistryDEFAULT_ADMIN_ROLEBan an agent (setStatus), set the ERC-8004 registries and the registry parameters. Every DEFAULT_ADMIN_ROLE also grants and revokes the other roles of its contract.Change a vault's mandate, set sigma outside the bounds it set, or change a settlement price once it is recorded. It has no function that moves user funds.trust-model.md
AgentRegistrySLASHER_ROLESlash bonds, record results.Not statedaudit-readiness.md
FeeManagerDEFAULT_ADMIN_ROLEChange fees (capped at 30%) and redirect the treasury (setFees, setTreasury). Every DEFAULT_ADMIN_ROLE also grants and revokes the other roles of its contract.Change a vault's mandate, set sigma outside the bounds it set, or change a settlement price once it is recorded. It has no function that moves user funds.trust-model.md
FeeManagerDEPOSITOR_ROLECredit performance fees to an agent and the treasury (creditFees).Not statedFeeManager.sol
MarketCalendarDEFAULT_ADMIN_ROLEGrant and revoke CALENDAR_ROLE. Every DEFAULT_ADMIN_ROLE also grants and revokes the other roles of its contract.Change a vault's mandate, set sigma outside the bounds it set, or change a settlement price once it is recorded. It has no function that moves user funds.MarketCalendar.sol
MarketCalendarCALENDAR_ROLEMark NYSE holidays and early closes (setHolidays, setEarlyCloses).Not statedMarketCalendar.sol
OptionTokenDEFAULT_ADMIN_ROLERewire which contract mints and burns options (setManager); set the metadata URI (setURI).Not statedtrust-model.md
VaultFactoryDEFAULT_ADMIN_ROLERaise the ceiling on deposit caps (setMaxDepositCap).Change a vault's mandate: it is fixed when the vault is created.trust-model.md
MirrorFeedDEFAULT_ADMIN_ROLEGrant and revoke KEEPER_ROLE on the feed (testnet only).Not statedMirrorFeed.sol
MirrorFeedKEEPER_ROLEPush MirrorFeed rounds (testnet only). Every value is checked against the mainnet Chainlink round it copies by the price mirror audit; when it pushes is trusted.Anything else.trust-model.md
TestStockTokenDEFAULT_ADMIN_ROLEMint test stock tokens, pause the token or its oracle flag, and schedule a multiplier change (mint, setPaused, scheduleMultiplier). Test tokens on Arbitrum Sepolia only.Not statedTestStockToken.sol
UsdgDripownerRefill and sweep the test-USDG faucet (refill, sweep).Not statedUsdgDrip.sol
GasDripownerAllow or remove relayers and sweep the drip's ETH (setRelayer, sweep).Raise the amount per drip or the daily cap: both are fixed at deployment (amount, dailyCap).GasDrip.sol
GasDriprelayerSend drip(to): 0.0001 test ETH to a new wallet. Held by the app's /api/gas-drip relayer key (D49).Drip an address twice, drip to one holding 0.0001 ETH or more, or send more than 20 drips in a UTC day: the contract refuses each (AlreadyDripped, HasGas, DailyCapReached).decisions.md
03

Last admin actions

Role grants and revokes and every admin setter event (PricerSet, OracleSet, FeedSet, SpotBufferSet, SigmaSet, TimingsSet and the rest), newest first, with the sender of each transaction.

Robinhood Chain testnet v2. Choose another deployment under role holders.

04

Staged path

How the admin's power shrinks, each stage with commitments you can check with a test or a read.

  1. Stage 0: a deployer key on the testnets

    Current

    Robinhood Chain testnet (v2 and v3) and Arbitrum Sepolia, today

    The deployer 0x26b2…13Ff holds DEFAULT_ADMIN_ROLE on every contract, GUARDIAN_ROLE and the keeper roles. It can use every admin power at once. The CI keeper key 0x317a…AfF76 holds KEEPER_ROLE on the mirrored MirrorFeeds and nothing else.

  2. Stage 1: a Safe behind a 73-day timelock

    Robinhood Chain mainnet (chain 4663), at deployment; never run yet

    Deploy.s.sol's mainnet path ends with an OpenZeppelin TimelockController as the only holder of DEFAULT_ADMIN_ROLE on all seven contracts and of the calendar's CALENDAR_ROLE. The deployer renounces every admin role, and only the Safe can schedule, cancel and execute. The guardian (the Safe by default) keeps pause, unpause and emergencyCancel without a delay. A feed, oracle or pricer change is public as a CallScheduled event for 73 days before it can run.

  3. Stage 2: renounce what is no longer needed

    Mainnet, later, one contract at a time

    Each contract's admin role is separate, so each can be renounced on its own, as a scheduled renounceRole from the timelock. Once renounced, nobody can grant it again. Cheapest first: OptionToken, VaultFactory, FeeManager, AgentRegistry, then StockOracle and EpochManager when the stock list, the pricer and the bounds are final. GUARDIAN_ROLE probably never.

The reasons and the alternatives we rejected: D43 and the staged path in the trust model. Run the 12 timelock tests with forge test --root contracts --match-path "test/governance/*".

05

Check it yourself

Read-only, no key needed.

Is the deployer still the EpochManager's admin on Robinhood Chain testnet v2?

cast call 0x5A3b58DF27e4DD5E0fa6493D90fF653e0E199C99 "hasRole(bytes32,address)(bool)" 0x0000000000000000000000000000000000000000000000000000000000000000 0x26b277b434B1670f207Afd8946edA9AF78A613Ff --rpc-url https://rpc.testnet.chain.robinhood.com

Every pricer change on that EpochManager since its deploy block:

cast logs --address 0x5A3b58DF27e4DD5E0fa6493D90fF653e0E199C99 "PricerSet(address)" --from-block 125880607 --rpc-url https://rpc.testnet.chain.robinhood.com

The JSON behind this page: /api/governance?chain=46630 and ?chain=421614.