Skip to main content

Timelock Duration on Critical Actions

Evaluates the delay between approval and execution of upgrades and mint actions, and whether that delay is actively monitored. The timelock is the user's exit window before contested actions occur.

TierReasoningEvidence
No timelock, or bypassable via emergency execution pathA timelock is the user's exit window before contested actions occur. No or short timelock, or one bypassable through an emergency execution path, means a compromised or malicious action becomes immediate and irreversible.Radiant Capital's October 2024 exploit ($53M) executed instantly because there was no timelock on transferOwnership. Ankr's deployer EOA similarly pushed a malicious mint implementation with no upgrade delay. Beanstalk's emergencyCommit (24h seasoning) was bypassed by a flash-loaned supermajority vote in April 2022 ($182M).
1 to 72 hoursA meaningful delay creates a response window between approval and execution, but its protective value is conditional on the proposal queue actually being monitored; the delay alone does not guarantee detection.Moonwell (March 2026) showed that a 48-hour timelock provided no protection because no one monitored the proposal queue — an attacker spent approximately $1,800 on MFAM tokens to push a near-fatal proposal.
72+ hours with active monitoring and community visibilityA long delay combined with active monitoring of the proposal queue and community visibility ensures the community has both the time and the information to detect and respond to contested actions before they execute.Arbitrum's Security Council 13-day delay with verifiable on-chain proposal visibility anchors the top tier.