★ Low-threshold multisig vs TVL
Compound V3 (Comet)'s assessment for RD-F-028 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
Community MultiSig confirmed 4-of-6 by OpenZeppelin compound-security-policies README (6 named signers: Paul L./Gauntlet, 0age/OpenSea, arr00, blck, Jared F., TennisBowling; threshold: 4/6). DeFiScan reports 4-of-8 and states the multisig does not meet security council standards (requires >=7 signers, >=51% threshold). Either reading is below the >=5-of-8 peer norm for $1.35B TVL. Powers limited to pause + proposal cancel.
Sources #
- URLhttps://www.defiscan.info/protocols/compound-v3/ethereumretrieved 2026-04-28
- https://etherscan.io/address/0xbbf3f1421d886e9b2c5d716b5192ac998af2012cretrieved 2026-04-28
- https://github.com/OpenZeppelin/compound-security-policies/blob/main/README.mdretrieved 2026-04-28
Methodology #
Determine whether the multisig threshold is abnormally low relative to TVL peer cohort (e.g., 2-of-3 for a protocol with >$100M TVL where peer norm is 5-of-8).
See the full factor methodology and distribution across all protocols →