Bitcoin Forum
July 26, 2026, 07:03:55 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Multisig is not enough guarantee your money is secure in Defi?  (Read 60 times)
shinratensei_ (OP)
Legendary
*
Offline

Activity: 3906
Merit: 1054


Leading Crypto Sports Betting & Casino Platform


View Profile
Today at 04:10:06 AM
 #1



Recently I found the Triple H wallet hacking on my timeline, the hacking caused $9.7M to be drained and the exploiter already bridged funds to Ethereum but it got me thinking.

  • Humanity protocol, 3-of-6 multisig, still got hacked loss ~$32 M
  • UXLINK, multisig compromised, ~$27M gone
  • Drift protocol, 2-of-5 multisig compromise, ~$285M gone

And many more stil counting...

It got me thinking, it seems using multisig doesn't even guarantee safety of Defi because the developer of the project, the people who you expect to know what they are doing, is doing their job badly.
If the hack was because bug and contract code exploit even with proper audit, understandable. However, even with multisig and these projects are still hacked, it feels so strange.

At this point, do you think it's still worth staking or locking any amount of money in Defi? And do you think multisig has become pointless in the hand of these altcoin developers?

I'm not blaming the multisig, the multisig is working as intended but it seems doesn't matter what security measure you take, if the developers are incompetent, it will break regardless.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
fullfitlarry
Sr. Member
****
Offline

Activity: 434
Merit: 329


You Attract What You Are


View Profile
Today at 07:36:16 AM
 #2

At this point, do you think it's still worth staking or locking any amount of money in Defi? And do you think multisig has become pointless in the hand of these altcoin developers?

With that way hackers are breaking in? I don't think it's worth the risk. And just imagine waking up one day and seeing that you have been hack and all money is gone.

I'm not blaming the multisig, the multisig is working as intended but it seems doesn't matter what security measure you take, if the developers are incompetent, it will break regardless.

Developers have the burden of proof here. They're the one who needs to hardened their code to protect us from the loopholes and exploits that cyber criminals are going to see. So yes, it doesn't matter your security practice, if the code itself is the problem then everything is going to break apart.

_act_
Legendary
*
Offline

Activity: 1694
Merit: 1943



View Profile
Today at 08:56:34 AM
 #3

Also the Bybit exchange that was hacked that billion of dollar was stolen in some coins was from a multisig wallet which is another example.

At this point, do you think it's still worth staking or locking any amount of money in Defi? And do you think multisig has become pointless in the hand of these altcoin developers?
Staking or locking my money? I can not do that because it is not worth it for me. Multisig is not pointless, but who knows if it is insider information. I do not trust anyone among them.

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits PREDICT..
█████████████████████████
█████████████████████████
███████████▀▀░░░░▀▀██████
██████████░░▄████▄░░████
█████████░░████████░░████
█████████░░████████░░████
█████████▄▀██████▀▄████
████████▀▀░░░▀▀▀▀░░▄█████
██████▀░░░░██▄▄▄▄████████
████▀░░░░▄███████████████
█████▄▄█████████████████
█████████████████████████
█████████████████████████
.
.WHERE EVERYTHING IS A MARKET..
█████
██
██







██
██
██████
Will Bitcoin hit $200,000
before January 1st 2027?

    No @1.15         Yes @6.00    
█████
██
██







██
██
██████

  CHECK MORE > 
rat03gopoh
Legendary
*
Offline

Activity: 2744
Merit: 1094


NO KYC Exchanger☝️


View Profile WWW
Today at 10:07:36 AM
 #4

While multisig wallets remain useful, in the case of a hack like this, the most likely scenario is the involvement of one or more insiders. Essentially, interacting with Defi still places trust in a third-party system, as you must transfer funds to an address(es) you don't control. This is a potential point of failure.

 
 b1exch.to 
  ETH      DAI   
  BTC      LTC   
  USDT     XMR    
.███████████▄▀▄▀
█████████▄█▄▀
███████████
███████▄█▀
█▀█
▄▄▀░░██▄▄
▄▀██▄▀█████▄
██▄▀░▄██████
███████░█████
█░████░█████████
█░█░█░████░█████
█░█░█░██░█████
▀▀▀▄█▄████▀▀▀
Dr.Bitcoin_Strange
Hero Member
*****
Offline

Activity: 1386
Merit: 610


Leading Crypto Sports Betting & Casino Platform


View Profile
Today at 03:59:43 PM
 #5

Using multisig is not pointless and can greatly protect users funds if the necessary precautions are taken to prevent attackers from exploiting vulnerabilities. Take Humanity Protocol, for example. Reports indicate that the hack was successful because three keys were stored on a single device that was compromised by the attacker. This already made the multisig setup weak because the minimum number of required keys had been obtained by the hacker. To a great extent, it was the mistake of the Humanity Protocol team to store three keys on one device.

In the case of Drift Protocol, the success of the hack was said to be possible because of social engineering. The attackers tricked two team members (two signers) into unknowingly pre-signing malicious transactions. They spent months socially engineering members of the team and eventually succeeded in stealing the funds because of the two signers.

Multisig is very secure, but not when there is poor custody of the keys or when signers fail to adequately verify transactions before signing them.

Allegedly, another reason behind some of these hacks is the abuse of administrative privileges. An administrator may cooperate with a hacker or create loopholes that give an attacker significant leverage to succeed in their hack attempts.

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
GiorgoArm15
Newbie
*
Offline

Activity: 5
Merit: 0


View Profile
Today at 04:01:58 PM
 #6

I think a few of these examples actually weaken your argument once you look at what really happened instead of just seeing the word “multisig”

Humanity Protocol is probably the best example. It wasn’t multisig that failed - all 6 keys were reportedly stored on a single employee’s laptopp. Once that machine was compromised, the attacker could satisfy both the Ether and BNB Chain signer requirements. That’s a basic key custody failure, not a multisig design failure

N-of-M doesn’t mean much if all N keys live in the same place

Drift is another case that’s more complicated than “developer incompetence.” Investigators linked it to a North Korean APT that reportedly spent months social engineering two signers before obtaining pre-signed transactions. That’s a state-backed operation. Multisig raises the bar, but it can’t stop a patient attacker targeting the people behind the keys

UXLINK is different again. The issue was a delegatecall vulnerability in the multisig contract itself, which allowed the attacker to bypass signer approvals entirely. That’s a smart contract bug, not a failure of the multisig model

And Triple-A doesn’t really belong on the list either, since it was reportedly a hot wallet compromise rather than a multisig breach. That’s a completely different threat model

To me, multisig solves one specific problem: protecting against a single compromised private key. It doesn’t magically protect against poor key management, social engineering, insider threats, or bugs in the multisig contract itself

It’s kinda separate probs
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!