# Independent finding: a DeFi Saver admin signer is also one of Aave's own Governance Guardian signers

**URL:** <https://governance.aave.com/t/independent-finding-a-defi-saver-admin-signer-is-also-one-of-aaves-own-governance-guardian-signers/25626>\
**Category:** General\
**Created:** [September 11, 2026, 6:55pm UTC](https://governance.aave.com/t/independent-finding-a-defi-saver-admin-signer-is-also-one-of-aaves-own-governance-guardian-signers/25626 "2026-09-11T18:55:27Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![spap](https://avatars.discourse-cdn.com/v4/letter/s/f19dbf/32.png) [@spap](https://governance.aave.com/u/spap)\
**Post date:** [September 11, 2026, 6:55pm UTC](https://governance.aave.com/t/independent-finding-a-defi-saver-admin-signer-is-also-one-of-aaves-own-governance-guardian-signers/25626/1 "2026-09-11T18:55:27Z")

</div>

Hi all,

I’m an independent on-chain researcher (GitHub: s-papy, X: @RealSpap), not affiliated with Aave Labs, the Aave DAO, or any Aave service provider. Sharing one finding from a broader cross-protocol multisig research project, specific to Aave.

**What I found**

DeFi Saver’s admin Safe (0x25eFA336886C74eA8E282ac466BdCd0199f85BB9, 3-of-6, the true root of trust behind its AdminVault, confirmed live via admin()) shares one signer with Aave’s own official “Aave Governance Guardian Ethereum” Safe (0xCe52ab41C40575B072A18C9700091Ccbe4A06710, 5-of-9, per aave-dao/aave-permissions-book). DeFi Saver is an independent, unrelated DeFi position-automation protocol live since 2019, this isn’t a known Aave-affiliated entity holding a second role; it’s the first time this specific Governance Guardian signer has turned up on a Safe entirely outside the Aave ecosystem.

This isn’t an allegation of wrongdoing, it’s a structural observation: whoever holds that key has reach into two independent protocols’ privileged operations, something neither protocol’s own documentation would surface on its own.

**Method** : every address sourced from a protocol’s own docs or GitHub, independently re-verified on-chain via getOwners(), no API key, no third-party indexer, then cross-referenced against a combined roster of 339 protocols / 553 confirmed Safes checked so far. Full methodology and dataset: [GitHub - s-papy/multisig-overlap-showcase: Independent, on-chain verified research: 8 named individuals hold trusted multisig signer keys across multiple, unrelated DeFi protocols at once, verified two ways including a live on-chain event replay. · GitHub](http://github.com/s-papy/multisig-overlap-showcase). Live dashboard (re-executes the check on demand): [Multisig Overlap | Dune](http://dune.com/s_pap/multisig-overlap).

Happy to share the exact getOwners() calls/addresses for independent verification, or to hear if this is already a known/monitored signer on your end.
