So important to guard any possible malicious profitable actions behind vetos, timelocks and token votes.
At Inverse we have privileged msigs, but they can only:
- Emergency pause or restrict behaviour
- Act within bounds set by token votes
Tbh I think the attack surface from compromised access controls is what made the team targets.
At the risk of sounding like a preacher, do you know which teams are not likely targets of these kinds of attacks?
Uniswap. Curve. Liquidity. Sky. Aave.
If the Liquity, Sky, or Aave teams could introduce new collateral with a multi-sig, they too would be targeted.
If Uniswap’s or Curve’s pools could be upgraded with a multi-sig, they too would be targeted.
Multi-sig usage is okay in certain cases, but not when the attack surface includes the introduction of new collateral which can drain the protocol.