Admin Keys and Multisig Control
A small set of keys can pause, upgrade, mint, or move assets, so the system's safety depends on those keyholders and their operational security.
작동 방식
Most deployed protocols retain privileged roles: an owner that can change parameters, a guardian that can pause, a minter that can create tokens, an upgrader that can replace the logic entirely. These are usually held by a multisig requiring some threshold of signers, which reduces the risk of one person acting alone but concentrates the system into a handful of devices and people. Compromise of enough of those keys is equivalent to compromise of the protocol, without any flaw in the contract code, and the same is true of coercion or of a legal order directed at identifiable signers. A timelock changes the picture materially, because it turns a silent change into a publicly visible pending change with a window in which users can withdraw.
실제로 관찰 가능한 항목
Enumerate the privileged roles in the deployed contracts and resolve each to an address, then check whether that address is an externally owned account, a multisig, or a timelock, and what the multisig threshold and signer count are. Check whether signers are publicly identified, whether they are independent of one another, and whether they use separate hardware and jurisdictions. Read what the pause and mint functions can actually do, since a pause that also blocks withdrawals is a different instrument from one that only stops deposits.
선례
The Ronin bridge was drained in 2022 after attackers gained control of a majority of the keys in its validator multisig, with no flaw in the contract logic involved.
수치의 중요성에 영향을 미치는 요인
Weigh what the privileged roles can actually do, the threshold and independence of signers, whether a timelock delays changes, whether users can exit within that delay, and whether an emergency path bypasses it.
관련 요소
이 항목이 적용되는 자산
이 팩터가 적용되는 카테고리에서 규모가 가장 큰 자산들. 여기에 포함된다는 것은 해당 팩터가 그 유형의 자산에 관련된다는 의미이며, 실제로 발생했다는 의미가 아니다.