Token provenance. The Base token's own history, stated with the same explicitness as the bridge's, all timestamps UTC and every step verifiable from
RoleGranted/
RoleRevoked events since the deployment block.
2026-02-04 20:55: EfixDITokenBase deployed by the deployer EOA
0x7C54…7537, later classified as compromised; the constructor granted it DEFAULT_ADMIN, MINTER, PAUSER and BRIDGE (
tx 0x98c6…e437 ↗).
2026-03-07: DEFAULT_ADMIN granted to the operator EOA
0x9eFc…9e12 (
tx 0x9c18…f150 ↗), which self-granted MINTER the same hour (
tx 0xfb42…2a19 ↗); the deployer's ADMIN and MINTER were revoked minutes later.
2026-05-15 22:54: DEFAULT_ADMIN granted to the Safe multisig
0x9040…EeD4 (
tx 0x461f…3cf2 ↗), and a cleanup batch at 23:08 revoked every remaining role except the operator EOA's MINTER: BRIDGE and PAUSER from the deployer, MINTER and BRIDGE from the MinterBurner, DEFAULT_ADMIN from the operator EOA (
tx 0x8f37…da96 ↗).
2026-05-27: MINTER granted to the successor signer
0x8f8C…CCb1, an MPC-custodied address (
tx 0xb2fd…249b ↗); it received 0.01 ETH of gas from the operator EOA about an hour earlier as part of the same migration (
tx 0x0a88…33fb ↗); gas funding confers no authority.
2026-05-28 15:43: MINTER revoked from the operator EOA (
tx 0xb001…e729 ↗). Since then the sole MINTER is
0x8f8C…CCb1; the only other active roles are the Safe's DEFAULT_ADMIN and PAUSER, and BRIDGE_ROLE has zero holders, which anyone can verify with
hasRole on Basescan.