0xMiden / 0xMiden/protocol

Lower-threshold procedures in a multisig can lead to draining the account

オープン
#3,361 コメント 4 件 リアクション 0 件 担当者 0 名 GitHub で見る
fees standards
主要言語
Rust
スター
132
フォーク
167
平均マージ
1日 23時間
マージ済み PR(30日)
110

説明

> I think there is a potential attack vector for multisigs that support lower thresholds for some procedures. Specifically, let's say it is a 2-of-3 multisig, but one of the actions requires 1-of-3 signature. With such a setup, any one of the signers would potentially drain the account by providing bogus conversion info (the attacker wouldn't get the funds since they would be paid as fees, but the account would be drained).
>
> One potential solution is to this is to have a multisig account configure max_fee for low-threshold actions, but it also has some downsides.

posted by @bobbinth in https://github.com/0xMiden/protocol/pull/3303#discussion_r3606445400

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。