• bitcoinBitcoin (BTC) $ 97,110.00
  • ethereumEthereum (ETH) $ 3,389.50
  • tetherTether (USDT) $ 0.999636
  • xrpXRP (XRP) $ 2.24
  • bnbBNB (BNB) $ 667.19
  • solanaSolana (SOL) $ 186.07
  • dogecoinDogecoin (DOGE) $ 0.323834
  • usd-coinUSDC (USDC) $ 0.999356
  • staked-etherLido Staked Ether (STETH) $ 3,384.30
  • cardanoCardano (ADA) $ 0.917421
  • tronTRON (TRX) $ 0.246075
  • avalanche-2Avalanche (AVAX) $ 38.92
  • chainlinkChainlink (LINK) $ 22.83
  • wrapped-stethWrapped stETH (WSTETH) $ 4,054.69
  • the-open-networkToncoin (TON) $ 5.33
  • suiSui (SUI) $ 4.64
  • shiba-inuShiba Inu (SHIB) $ 0.000022
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 96,823.00
  • hyperliquidHyperliquid (HYPE) $ 33.34
  • polkadotPolkadot (DOT) $ 7.17
  • stellarStellar (XLM) $ 0.363044
  • hedera-hashgraphHedera (HBAR) $ 0.258075
  • wethWETH (WETH) $ 3,405.65
  • bitcoin-cashBitcoin Cash (BCH) $ 452.66
  • leo-tokenLEO Token (LEO) $ 9.27
  • uniswapUniswap (UNI) $ 13.37
  • pepePepe (PEPE) $ 0.000018
  • litecoinLitecoin (LTC) $ 100.08
  • wrapped-eethWrapped eETH (WEETH) $ 3,575.77
  • nearNEAR Protocol (NEAR) $ 5.19
  • ethena-usdeEthena USDe (USDE) $ 0.999198
  • bitget-tokenBitget Token (BGB) $ 4.16
  • aptosAptos (APT) $ 10.13
  • usdsUSDS (USDS) $ 1.00
  • internet-computerInternet Computer (ICP) $ 10.41
  • aaveAave (AAVE) $ 310.73
  • crypto-com-chainCronos (CRO) $ 0.161131
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.482143
  • mantleMantle (MNT) $ 1.18
  • ethereum-classicEthereum Classic (ETC) $ 26.46
  • render-tokenRender (RENDER) $ 7.33
  • vechainVeChain (VET) $ 0.046441
  • mantra-daoMANTRA (OM) $ 3.87
  • moneroMonero (XMR) $ 192.00
  • whitebitWhiteBIT Coin (WBT) $ 24.37
  • bittensorBittensor (TAO) $ 470.85
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 1.31
  • daiDai (DAI) $ 0.999742
  • ethenaEthena (ENA) $ 1.12
  • arbitrumArbitrum (ARB) $ 0.772166
  • kaspaKaspa (KAS) $ 0.121836
  • filecoinFilecoin (FIL) $ 5.02
  • fantomFantom (FTM) $ 1.03
  • algorandAlgorand (ALGO) $ 0.339182
  • okbOKB (OKB) $ 45.01
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 2.64
  • cosmosCosmos Hub (ATOM) $ 6.72
  • blockstackStacks (STX) $ 1.73
  • ondo-financeOndo (ONDO) $ 1.73
  • optimismOptimism (OP) $ 1.82
  • immutable-xImmutable (IMX) $ 1.41
  • bonkBonk (BONK) $ 0.000032
  • celestiaCelestia (TIA) $ 5.11
  • movementMovement (MOVE) $ 0.990385
  • theta-tokenTheta Network (THETA) $ 2.18
  • injective-protocolInjective (INJ) $ 21.36
  • binance-peg-wethBinance-Peg WETH (WETH) $ 3,401.68
  • the-graphThe Graph (GRT) $ 0.213230
  • dogwifcoindogwifhat (WIF) $ 2.03
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 97,076.00
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.029790
  • sei-networkSei (SEI) $ 0.439398
  • worldcoin-wldWorldcoin (WLD) $ 2.26
  • thorchainTHORChain (RUNE) $ 5.13
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 3,497.56
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.995439
  • rocket-pool-ethRocket Pool ETH (RETH) $ 3,808.10
  • flokiFLOKI (FLOKI) $ 0.000172
  • jasmycoinJasmyCoin (JASMY) $ 0.033964
  • gatechain-tokenGate (GT) $ 13.07
  • mantle-staked-etherMantle Staked Ether (METH) $ 3,556.50
  • lido-daoLido DAO (LDO) $ 1.73
  • galaGALA (GALA) $ 0.036470
  • tokenize-xchangeTokenize Xchange (TKX) $ 18.92
  • flare-networksFlare (FLR) $ 0.027217
  • makerMaker (MKR) $ 1,658.61
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 96,755.00
  • beam-2Beam (BEAM) $ 0.027663
  • fasttokenFasttoken (FTN) $ 3.32
  • usual-usdUsual USD (USD0) $ 0.997654
  • the-sandboxThe Sandbox (SAND) $ 0.573068
  • pyth-networkPyth Network (PYTH) $ 0.375251
  • nexoNEXO (NEXO) $ 1.35
  • kucoin-sharesKuCoin (KCS) $ 11.16
  • tezosTezos (XTZ) $ 1.31
  • kaiaKaia (KAIA) $ 0.224584
  • based-brettBrett (BRETT) $ 0.131837
  • solv-btcSolv Protocol SolvBTC (SOLVBTC) $ 97,076.00
  • raydiumRaydium (RAY) $ 4.44
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 3,495.74
  • eosEOS (EOS) $ 0.818370
  • heliumHelium (HNT) $ 6.87
  • binance-staked-solBinance Staked SOL (BNSOL) $ 191.55
  • ethereum-name-serviceEthereum Name Service (ENS) $ 35.49
  • aerodrome-financeAerodrome Finance (AERO) $ 1.62
  • jupiter-exchange-solanaJupiter (JUP) $ 0.848602
  • xdce-crowd-saleXDC Network (XDC) $ 0.076470
  • flowFlow (FLOW) $ 0.716150
  • starknetStarknet (STRK) $ 0.489846
  • arweaveArweave (AR) $ 16.32
  • bitcoin-svBitcoin SV (BSV) $ 54.16
  • dydx-chaindYdX (DYDX) $ 1.49
  • aioz-networkAIOZ Network (AIOZ) $ 0.939549
  • iotaIOTA (IOTA) $ 0.297638
  • bittorrentBitTorrent (BTT) $ 0.000001
  • msolMarinade Staked SOL (MSOL) $ 232.38
  • curve-dao-tokenCurve DAO (CRV) $ 0.822260
  • coredaoorgCore (CORE) $ 1.10
  • neoNEO (NEO) $ 14.21
  • axie-infinityAxie Infinity (AXS) $ 6.34
  • elrond-erd-2MultiversX (EGLD) $ 35.12
  • matic-networkPolygon (MATIC) $ 0.483199
  • decentralandDecentraland (MANA) $ 0.485055
  • solv-protocol-solvbtc-bbnSolv Protocol SolvBTC.BBN (SOLVBTC.BB) $ 96,171.00
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 96,459.00
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 3,392.30
  • pendlePendle (PENDLE) $ 5.21
  • zcashZcash (ZEC) $ 53.37
  • apecoinApeCoin (APE) $ 1.17
  • fartcoinFartcoin (FARTCOIN) $ 0.824912
  • eigenlayerEigenlayer (EIGEN) $ 3.86
  • mog-coinMog Coin (MOG) $ 0.000002
  • jito-governance-tokenJito (JTO) $ 2.99
  • chilizChiliz (CHZ) $ 0.086688
  • akash-networkAkash Network (AKT) $ 3.23
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 3,384.63
  • ai16zai16z (AI16Z) $ 0.696531
  • conflux-tokenConflux (CFX) $ 0.162042
  • wormholeWormhole (W) $ 0.273922
  • popcatPopcat (POPCAT) $ 0.760798
  • usddUSDD (USDD) $ 0.997808
  • mina-protocolMina Protocol (MINA) $ 0.619411
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 200.53
  • spx6900SPX6900 (SPX) $ 0.780447
  • compound-governance-tokenCompound (COMP) $ 81.92
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 3,379.32
  • roninRonin (RON) $ 1.92
  • superfarmSuperVerse (SUPER) $ 1.57
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.37
  • havvenSynthetix Network (SNX) $ 2.07
  • ecasheCash (XEC) $ 0.000035
  • gnosisGnosis (GNO) $ 263.98
  • dog-go-to-the-moon-runeDOG•GO•TO•THE•MOON (Runes) (DOG) $ 0.006721
  • chiaChia (XCH) $ 21.24
  • dydxdYdX (ETHDYDX) $ 1.49
  • zksyncZKsync (ZK) $ 0.180778
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.324328
  • ether-fi-staked-btcEther.fi Staked BTC (EBTC) $ 96,526.00
  • amp-tokenAmp (AMP) $ 0.007858
  • notcoinNotcoin (NOT) $ 0.006424
  • axelarAxelar (AXL) $ 0.751177
  • chex-tokenCHEX Token (CHEX) $ 0.658429
  • peanut-the-squirrelPeanut the Squirrel (PNUT) $ 0.649530
  • tether-goldTether Gold (XAUT) $ 2,626.64
  • fraxFrax (FRAX) $ 0.994096
  • layerzeroLayerZero (ZRO) $ 5.72
  • mantle-restaked-ethMantle Restaked ETH (CMETH) $ 3,557.08
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000112
  • reserve-rights-tokenReserve Rights (RSR) $ 0.011277
  • baby-doge-coinBaby Doge Coin (BABYDOGE) $ 0.00000000
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 3,686.70
  • grassGrass (GRASS) $ 2.42
  • turboTurbo (TURBO) $ 0.008436
  • usualUsual (USUAL) $ 1.26
  • vanaVana (VANA) $ 18.62
  • safeSafe (SAFE) $ 1.09
  • cat-in-a-dogs-worldcat in a dogs world (MEW) $ 0.006379
  • ordinalsORDI (ORDI) $ 26.76
  • super-oethSuper OETH (SUPEROETHB) $ 3,402.32
  • oasis-networkOasis (ROSE) $ 0.083043
  • echelon-primeEchelon Prime (PRIME) $ 10.94
  • blurBlur (BLUR) $ 0.265356
  • 1inch1inch (1INCH) $ 0.392770
  • trust-wallet-tokenTrust Wallet (TWT) $ 1.30
  • beldexBeldex (BDX) $ 0.077428
  • susdssUSDS (SUSDS) $ 1.02
  • paypal-usdPayPal USD (PYUSD) $ 0.999381
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 97,297.00
  • creditcoin-2Creditcoin (CTC) $ 1.27
  • pax-goldPAX Gold (PAXG) $ 2,623.28
  • dexeDeXe (DEXE) $ 9.03
  • apenftAPENFT (NFT) $ 0.00000052
  • pumpbtcpumpBTC (PUMPBTC) $ 96,065.00
  • livepeerLivepeer (LPT) $ 13.89
  • goatseus-maximusGoatseus Maximus (GOAT) $ 0.507086
  • gigachad-2Gigachad (GIGA) $ 0.052223
  • nervos-networkNervos Network (CKB) $ 0.010945
  • arkhamArkham (ARKM) $ 1.50
  • kusamaKusama (KSM) $ 31.38
  • true-usdTrueUSD (TUSD) $ 0.999789

Multisig in defi: a marketing gimmick or a real security solution? | Opinion

0 112

Disclosure: The views and opinions expressed here belong solely to the author and do not represent the views and opinions of crypto.news’ editorial.

Multisig, short for multisignature, is a security feature widely used in decentralized finance projects to enhance the security of digital assets. It requires multiple private keys to authorize a transaction instead of a single key, adding an extra layer of security. Multisigs are regarded as a robust security mechanism to protect the integrity of defi projects, but whether this is the case in practical scenarios is a matter of debate.

You might also like: Web3 urgently needs a paradigm shift in its security approach | Opinion

So, does deploying multisig technology truly guarantee security, or does it merely create a mirage of safety? Let’s find out.

Aspects that make multisig a significant security measure

Multisigs represent a fundamental security practice in the defi space, often acting as indicators of a project’s commitment to robust security measures. By requiring several signatures or approvals before executing transactions, they mitigate the risk of unauthorized access or malicious activities. Such measures signify a project’s dedication to safeguarding users’ assets and maintaining transparency.

In an environment where security concerns are paramount, incorporating multisigs underscores a proactive approach to building trust within the defi community and contributing to the overall integrity of decentralized financial platforms.

However, to ensure this idea works in practice, special attention must be paid to the implementation process and managing the multisigs. If a multisig is achieved by having, say, three out of five signatures among the team that manages the project itself, then this feature is little more than a marketing gimmick. De facto, the team still has 100% of the power to alter any smart contract as they desire.

For this to become an accurate security measure, it makes sense to add time-delay transactions, which means that some time passes between the proposal being offered for governance and the transaction being carried out.

Just as importantly, there should be diversification among the signatories so there is limited scope of one influencing the decision of the other. If 60-70% or more of the signatories belong to a single team managing the project, this multisig raises security concerns and becomes ineffective. To my mind, the best option is when half of the signatures in a multisig belong to non-team members. These could be advisors, active community members, project investors, and so on.

It is worth noting, though, that being a signatory in a multisig is quite a big responsibility because these people need to be quite reactive. It brings me back to my original point—that a lot of forethought has to go into how a project sets up its multisig function and what it oversees.

Decoding the duality: the impact of smart contract upgradeability on security

When discussing defi security and multisigs, it is worth bringing up the topic of smart contract upgradeability.

Upgradeability allows developers to adapt to changing market conditions, promptly facilitate deployment of bug fixes and security patches, and add new functionalities without requiring users to migrate to a new contract. This flexibility and promptness are crucial for the evolving nature of the defi space because migrating to a new contract entails a significant amount of complexity and challenges.

While upgradeability can offer flexibility and the ability to fix bugs or add new features, it also introduces certain considerations and potential security risks. Multisigs can offer a viable solution to this problem, provided all contracts, whether upgradable or not, are overseen by a multisig. Ideally, the contracts would be comprised of diverse teams and community members and would have ironclad communication regarding every action, so there is no scope for unauthorized alterations.

Is it possible to ensure the multisig is genuinely decentralized?

The effectiveness of the multisig is highly dependent on the diversity of the teams. Ensuring that a multisig is genuinely controlled by the community and advisors, beyond just the project team, requires a combination of governance mechanisms, transparency, and security measures.

The projects need to implement a decentralized governance model that allows for the participation of community members, advisors, and other stakeholders in the multisig. This decentralization minimizes the risk of a single point of failure, making it harder for malicious actors to compromise the system through a single target, such as the project team being hacked or doing a rug pull due to having complete control over the system. Like this, the community has a say in verifying the security and integrity of the multisig.

One way of achieving this is by involving key opinion leaders (KOLs) within the project who are interconnected and actively participate in the process. Many KOLs use ENS addresses publicly associated with them (and mention them on Twitter (X) handles that are unique in principle and can be used for multisig. This process works because the KOL technically owns the address and serves as their verification. Unfortunately, this is not a universal method—since not everyone likes ENS, if nothing else. I, personally, have only seen this practice applied in some of the larger projects.

Implementation is the key

Multisig is very popular in defi projects because of its flexibility and risk-mitigating capabilities. However, it all comes down to the implementation part of it. This practice relies on the coordinated efforts of multiple signatories to validate and execute transactions.

If there is a breakdown in communication between them, it can lead to delays, misunderstandings, or even conflicting decisions, leaving the system open to exploitation. All signatories need to be on the same page, understand the intent behind transactions, and be able to respond promptly to any potential security threats or suspicious activities.

Unfortunately, this is not an easy feat to achieve—quite a few issues need to be tackled first, which means that multisignatures are a good security practice; they are not a panacea that can be relied on without reservation.

Kate Kurbanova

Kate Kurbanova is a co-founder of Apostro, a risk management firm focused on economic attacks. She is a professional who leverages established traditional financial practices to enhance defi risk management. Kate’s expertise extends to data analysis, evaluating risk management strategies, and analyzing economic vulnerabilities in web3.

Source

Leave A Reply

Your email address will not be published.