Hi all,
I’m an independent on-chain researcher (GitHub: s-papy, X: @RealSpap), not affiliated with Aave Labs, the Aave DAO, or any Aave service provider. Sharing one finding from a broader cross-protocol multisig research project, specific to Aave.
What I found
DeFi Saver’s admin Safe (0x25eFA336886C74eA8E282ac466BdCd0199f85BB9, 3-of-6, the true root of trust behind its AdminVault, confirmed live via admin()) shares one signer with Aave’s own official “Aave Governance Guardian Ethereum” Safe (0xCe52ab41C40575B072A18C9700091Ccbe4A06710, 5-of-9, per aave-dao/aave-permissions-book). DeFi Saver is an independent, unrelated DeFi position-automation protocol live since 2019, this isn’t a known Aave-affiliated entity holding a second role; it’s the first time this specific Governance Guardian signer has turned up on a Safe entirely outside the Aave ecosystem.
This isn’t an allegation of wrongdoing, it’s a structural observation: whoever holds that key has reach into two independent protocols’ privileged operations, something neither protocol’s own documentation would surface on its own.
Method: every address sourced from a protocol’s own docs or GitHub, independently re-verified on-chain via getOwners(), no API key, no third-party indexer, then cross-referenced against a combined roster of 339 protocols / 553 confirmed Safes checked so far. Full methodology and dataset: GitHub - s-papy/multisig-overlap-showcase: Independent, on-chain verified research: 8 named individuals hold trusted multisig signer keys across multiple, unrelated DeFi protocols at once, verified two ways including a live on-chain event replay. · GitHub. Live dashboard (re-executes the check on demand): Multisig Overlap | Dune.
Happy to share the exact getOwners() calls/addresses for independent verification, or to hear if this is already a known/monitored signer on your end.