defirisk.co
rubric v1.7.0

Low-threshold multisig vs TVL

Midas's assessment for RD-F-028 — scored red on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

Safe 0xB60842E9 is configured 1-of-3 for a protocol with $161M TVL. Peer norm for this TVL band is ≥4-of-7 (superstate uses 4-of-7; spiko uses 3-of-5). A single signer can unilaterally propose and execute via the Safe-mediated upgrade path (TimelockController requires Safe-signed calls but any one of the 3 owners can sign). Abnormally low threshold vs TVL. [★ CRITICAL]

Sources #

Methodology #

Determine whether the multisig threshold is abnormally low relative to TVL peer cohort (e.g., 2-of-3 for a protocol with >$100M TVL where peer norm is 5-of-8).

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol midas factor RD-F-028 score red collected_at 2026-05-16 09:34:55