0xMiden / 0xMiden/protocol

Lower-threshold procedures in a multisig can lead to draining the account

Đang mở
#3,361 4 bình luận 0 reaction 0 người được giao Xem trên GitHub
fees standards
Ngôn ngữ chính
Rust
Star
132
Fork
167
Merge trung bình
1 ngày 23 giờ
Pull request đã merge (30 ngày)
110

Mô tả

> I think there is a potential attack vector for multisigs that support lower thresholds for some procedures. Specifically, let's say it is a 2-of-3 multisig, but one of the actions requires 1-of-3 signature. With such a setup, any one of the signers would potentially drain the account by providing bogus conversion info (the attacker wouldn't get the funds since they would be paid as fees, but the account would be drained).
>
> One potential solution is to this is to have a multisig account configure max_fee for low-threshold actions, but it also has some downsides.

posted by @bobbinth in https://github.com/0xMiden/protocol/pull/3303#discussion_r3606445400

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.