defirisk.co
rubric v1.7.0

Low-threshold multisig vs TVL

Beefy Finance's assessment for RD-F-028 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

Dev multisig controlling all vault upgrades across $119.7M TVL is 3-of-6 (50% threshold). While not below the absolute red floor (2-of-3 or lower), 3-of-6 is below peer norm for $100M+ TVL protocols (3-of-5 or 4-of-7 is standard). Three signers could collude or be compromised to control vault upgrades across ~34 chains. Treasury multisig is 4-of-7 (57%) but controls no protocol functions.

Sources #

  • Internal
    Beefy data cache — Dev multisig threshold00-data-cache.json safe_multisigs[1].threshold=3, owner_count=6retrieved 2026-05-16
  • Docs
    Beefy Contracts and Timelocks Documentation3/6 signer multisig controls all privileged functions and assets held by the Beefy protocolretrieved 2026-05-16

Methodology #

Determine whether the multisig threshold is abnormally low relative to TVL peer cohort (e.g., 2-of-3 for a protocol with >$100M TVL where peer norm is 5-of-8).

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol beefy factor RD-F-028 score yellow collected_at 2026-05-16 13:10:30