Upgrade multisig signer configuration (M/N)
BENQI's assessment for RD-F-026 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
Secondary sources reference at least 4 signers but no M/N threshold or Safe address is publicly confirmed. getThreshold() cannot be called without the Safe address. Display string cannot be confirmed. Undisclosed multisig configuration at $277M TVL is assessed as yellow (could be below peer norm).
Sources #
- URLBENQI Security: Audits, Risk Architecture — DEV CommunitySecondary source referencing at least 4 signers in BENQI multisigretrieved 2026-05-16
- Risks & Audits | BENQIBENQI risks page: multisig framework without specific threshold disclosureretrieved 2026-05-16
Methodology #
Read `threshold` and `getOwners()` on the multisig controlling upgrade / sensitive ops. Store as `required` (M) and `total` (N); render as "M/N". For EOA admins record `required=1, total=1` (display "1/1"). Null when admin is immutable or full DAO with no fixed signer set.
See the full factor methodology and distribution across all protocols →