urging every serious team to follow the steps below, for the sake of the entire industry.
and please, add a timelock. seriously, please do.
While we wait for the dust to settle and hope for the best there is, sharing a few pointers on hardening the admin control flow for programs:
1. Program-native multisig for all admin config ixs over and above the obvious external multisig/cold-wallet setup
2. Timelocked admin execution enforced onchain for critical changes to program config like new listings, thresholds for circuit breakers etc.
3. Real-time admin config alerts so team/community can act on time critical intel.
4. No-op buffer for emergency bricking so program upgrade multisig can swap in a single tx