Mint Authority Permissions
Evaluates who can issue new tokens and under what constraints. The number of independent parties required to authorize issuance, and whether issuance is constrained at the contract level, are the primary inputs.
| Tier | Reasoning | Evidence |
|---|---|---|
| Single signer or undisclosed | One key with mint authority can issue any quantity without external constraint; what matters is how many independent humans must agree, and one equals the worst case. | Nine documented compromised-key minting incidents (Ronin, Harmony, Multichain, Heco, Orbit, Resolv, Ankr, PAID, ALEX) account for approximately $1.43B in realized losses. Resolv (March 2026) confirmed that hardware-protected keys produce the same loss profile as plaintext EOAs when on-chain controls are absent. |
| Bounded multisig (signer count, threshold, timelock as sub-factors) | A bounded multisig distributes mint authority across multiple keys with an explicit threshold and timelock, so unauthorized issuance requires collusion or compromise of several independent signers within the delay window. Signer count, threshold, and timelock duration are scored as sub-factors. | Paxos PYUSD, Circle USDC issuance multisigs, and Aave GHO Stewards 3-of-4 multisig operate at this tier. The compromised-key incident record shows loss severity scaling inversely with the number of independent signers required to authorize issuance. |
| Fully algorithmic mint logic gated by on-chain collateral | Algorithmic mint gated by on-chain collateral constrains supply at the contract level, so even complete key compromise cannot produce unauthorized issuance. | Algorithmic mint architectures (Liquity, MakerDAO Vaults, Lido stETH, Rocket Pool rETH) have not produced a mint-role incident across multi-year exposure. |