Admin Keys and Multisig Control
A small set of keys can pause, upgrade, mint, or move assets, so the system's safety depends on those keyholders and their operational security.
仕組み
Most deployed protocols retain privileged roles: an owner that can change parameters, a guardian that can pause, a minter that can create tokens, an upgrader that can replace the logic entirely. These are usually held by a multisig requiring some threshold of signers, which reduces the risk of one person acting alone but concentrates the system into a handful of devices and people. Compromise of enough of those keys is equivalent to compromise of the protocol, without any flaw in the contract code, and the same is true of coercion or of a legal order directed at identifiable signers. A timelock changes the picture materially, because it turns a silent change into a publicly visible pending change with a window in which users can withdraw.
実際に観測できるもの
Enumerate the privileged roles in the deployed contracts and resolve each to an address, then check whether that address is an externally owned account, a multisig, or a timelock, and what the multisig threshold and signer count are. Check whether signers are publicly identified, whether they are independent of one another, and whether they use separate hardware and jurisdictions. Read what the pause and mint functions can actually do, since a pause that also blocks withdrawals is a different instrument from one that only stops deposits.
先例
The Ronin bridge was drained in 2022 after attackers gained control of a majority of the keys in its validator multisig, with no flaw in the contract logic involved.
重要性を左右する要因
Weigh what the privileged roles can actually do, the threshold and independence of signers, whether a timelock delays changes, whether users can exit within that delay, and whether an emergency path bypasses it.
関連要因
この対象となる資産
このファクターが適用されるカテゴリに分類される、最大規模の資産。ここへの掲載は、そのファクターが当該種類の資産に関連することを意味するのであり、それが発生したことを意味するものではない。