0xMiden / 0xMiden/protocol

Lower-threshold procedures in a multisig can lead to draining the account

Aberta
#3,361 4 comentários 0 reações 0 responsáveis Ver no GitHub
fees standards
Linguagem predominante
Rust
Estrelas
132
Forks
167
Merge médio
1d 23h
PRs com merge (30d)
110

Descrição

> I think there is a potential attack vector for multisigs that support lower thresholds for some procedures. Specifically, let's say it is a 2-of-3 multisig, but one of the actions requires 1-of-3 signature. With such a setup, any one of the signers would potentially drain the account by providing bogus conversion info (the attacker wouldn't get the funds since they would be paid as fees, but the account would be drained).
>
> One potential solution is to this is to have a multisig account configure max_fee for low-threshold actions, but it also has some downsides.

posted by @bobbinth in https://github.com/0xMiden/protocol/pull/3303#discussion_r3606445400

Guia de contribuição

Abrir o guia de contribuição

Avaliação

Esta issue ainda não foi avaliada.

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.