Skip to main content

Signer composition and verifiability of the upgrade authority

A nominal upgrade-multisig threshold carries information only if signer independence and role assignment can be confirmed by an outside observer. Opaque role management turns offboarding failures and unrevoked access into persistent attack vectors on the upgrade path.

TierReasoningEvidence
UnclearA nominal multisig threshold cannot be relied upon without verified signer independence. Opaque role management turns offboarding failures and unrevoked access into persistent attack vectors.Ronin's 5-of-9 was functionally controlled by Sky Mavis ($625M loss); Orbit Chain's 7-of-10 was defeated by a former CISO relaxing firewalls ($81.5M loss); Multichain's self-described MPC was administered by a single principal ($126M loss).
ClearClear documentation with named roles, on-chain verifiable access control, published multisig addresses, and verifiable signer composition allows an external observer to assess the actual concentration of upgrade control.MakerDAO governance multisigs, the Lido validator set, and Aave Stewards publish named roles and on-chain-verifiable access control.