Contract Powers Registry / ethereum

AAVE

0x7fc66500c84a76ad7e9c93437bfc5ac33e2ddae9 on ethereum

In one line

upgradeable proxy (eip1967.implementation); admin is a contract owned by another contract; retained powers: upgrade.

UpgradeableYes
Source verifiedYes
Controlled byA contract
Confirmed powers1

Can this code be replaced?

Yes — this is a proxy. The address you interact with holds no logic of its own; it forwards calls to a second contract. Whoever holds the upgrade right can point it somewhere else, and every behaviour described on this page changes with it.

Patterneip1967.implementation
Current logic0x5d4aa78b08bc7c530e21bf7447988b1be7991322
Logic nameAaveTokenV3
Logic source verifiedYes
Raw storage evidence (2)

Who holds the keys?

Owner / admin0x86c3ffee349a7cff7ca88c449717b1b133bfb517
Found viaeip1967.admin slot
That address isA contract

owner is a contract — see admin.controller for what kind. It could be a multisig, a timelock, or a single-key wrapper — this registry does not open it. Follow the link above to see what that contract can do.

What the privileged role can still do

Each card is a capability found in the code. declared = the contract’s published interface exposes it. bytecode-heuristic = the 4-byte selector appears in the compiled code, which often means the contract implements it — but it can equally be a function this contract calls on another contract. Only a verified source settles that.

Code can be replaced

declared

The logic behind this address can be swapped for different code. Everything below can change with it.

Evidence (4)
  • changeAdmin(address) abi
  • upgradeTo(address) abi
  • upgradeToAndCall(address,bytes) abi
  • changeAdmin(address) bytecode-selector

What this page did not categorise

Nothing was dropped. Every state-changing function that the source restricts to a privileged role also matched one of the categories above — 3 of 18 functions in the published interface. The rest are callable by anyone, which is why they are not listed as powers. This is not proof there is no back door: a privileged path reached through another contract this one trusts would not show up here.

Is there a bug bounty on this?

The contract name matched 1 live program(s) in my Bounty Radar index. A name match is not proof this address is in scope — open the program and check its asset list.

ProgramPlatformMax bountyKYC
AAVE immunefi$1,000,000 Required

Raw facts

Chainethereum (chainId 1)
Contract nameInitializableAdminUpgradeabilityProxy
Compilerv0.6.10+commit.00c0fcaf
License
Bytecode size2,491 bytes (logic: 8,655)
DELEGATECALLpresent
SELFDESTRUCTabsent
CREATE2absent
Explorerview on block explorer ↗

Has any of this changed?

This page is rebuilt from the chain and diffed against the previous day. If the implementation behind this address is replaced, or the privileged key moves, it is listed on what changed with the before and after — also as RSS, so it can reach you without you coming back.

How this was produced, and what it cannot tell you

Storage slots, bytecode and eth_call results were read from public RPC nodes; where the source is verified, the published interface was read too. Nothing here is copied from another site’s opinion. Generated in 3073 ms on 2026-09-19.

What would change the answer: an upgrade after the date above; a power reachable only through a contract this one trusts; or role-based access control, whose holders this registry does not enumerate. Re-read the chain before you rely on it.

Machine-readable

Same facts as JSON, free, no key: /c/ethereum/0x7fc66500c84a76ad7e9c93437bfc5ac33e2ddae9.json. Live lookups for any address (not just this list) are $0.05 per call.

Want a human-grade read?

This page is automated pattern-matching. If you need someone to actually read the code and tell you what breaks, I do fixed-scope micro-audits — you pay after you read the report.