Upgrade multisig signer configuration (M/N)
Stake DAO's assessment for RD-F-026 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
4-of-7 threshold per LlamaRisk secondary source. Safe API blocked (HTTP 422). SDGP-67 confirms threshold unchanged after signer rotation. On-chain getThreshold() not readable via WebFetch. Rendered as '4/7'. Secondary source only — cannot confirm on-chain.
Sources #
- GovernanceSDGP-67 Multisig Signer ReplacementSDGP-67: 'This change does not modify the underlying multisig threshold'retrieved 2026-05-16
- LlamaRisk Asset Risk Assessment — Liquid LockersLlamaRisk states 'StakeDAO 4-of-7 multisig has the ability to rug its users'retrieved 2026-05-16
Methodology #
Read `threshold` and `getOwners()` on the multisig controlling upgrade / sensitive ops. Store as `required` (M) and `total` (N); render as "M/N". For EOA admins record `required=1, total=1` (display "1/1"). Null when admin is immutable or full DAO with no fixed signer set.
See the full factor methodology and distribution across all protocols →