DeFi · News

Shared signer links Aave Guardian and DeFi Saver admin Safe

An independent on-chain finding reveals one signer is part of both Aave's 5-of-9 Governance Guardian and DeFi Saver's 3-of-6 admin Safe.

Shared signer links Aave Guardian and DeFi Saver admin Safe

One signer appears on two privileged multisigs. That’s what independent on-chain researcher spap published to the Aave Governance Forum on September 11, 2026.

The addresses are explicit. DeFi Saver’s admin Safe (0x25eFA336886C74eA8E282ac466BdCd0199f85BB9) is a 3-of-6 multisig. Aave’s official “Aave Governance Guardian Ethereum” Safe (0xCe52ab41C40575B072A18C9700091Ccbe4A06710) runs 5-of-9. A single signer appears in both sets.

Spap is careful about scope. From the forum post: “This isn’t an allegation of wrongdoing, it’s a structural observation: whoever holds that key has reach into two independent protocols’ privileged operations, something neither protocol’s own documentation would surface on its own.”

Neither Safe can execute through that signer alone — DeFi Saver requires three approvals, Aave requires five. The forum post lists the thresholds as three of six for DeFi Saver and five of nine for Aave; it does not establish whether either threshold recently changed. But the same key sits inside both approval groups, meaning one signer is present in both protocols’ privileged approval groups.

One shared signer represents 1 of DeFi Saver’s 6 admin positions, or 16.7% of that signer set, and 1 of Aave’s 9 Guardian positions, or 11.1%. Those figures don’t measure voting power on their own; they show what fraction of each approval group belongs to the same unidentified entity.

DeFi Saver has operated as an independent DeFi position-automation protocol since 2019. The research project behind spap’s finding says it has examined 339 protocols across 553 confirmed Safes. As spap observes, the overlap is something neither protocol’s own documentation would surface on its own — that is the researcher’s characterization, not a claim independently verified by this desk.

For users, the concern is operational. Anyone depending on Aave’s Guardian-controlled actions, or on DeFi Saver’s admin controls, now has a disclosed cross-protocol dependency running through one key.

aave defi saver governance multisig spap
Marcus Feld

Marcus Feld

DeFi & On-chain Analyst · 6 years covering crypto · Author page

Marcus Feld is CoinScoop's DeFi and on-chain analyst. He digs into L2 activity, stablecoin flows and protocol revenue, translating raw chain data into plain-English calls.

Disclosure: This article is independent journalism and is for information only — it is not financial advice. CoinScoop is reader-supported and may earn a commission from some links. Read our disclosure policy →