# Deployed Multisig Process Improvement discusssion

**URL:** https://forum.safefoundation.org/t/deployed-multisig-process-improvement-discusssion/6491
**Category:** General
**Created:** [April 30, 2025, 3:06pm UTC](https://forum.safefoundation.org/t/deployed-multisig-process-improvement-discusssion/6491 "2025-04-30T15:06:45Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![RexShinka](https://avatars.discourse-cdn.com/v4/letter/r/9fc348/32.png) [@RexShinka](https://forum.safefoundation.org/u/RexShinka)
#### Post date: [April 30, 2025, 3:06pm UTC](https://forum.safefoundation.org/t/deployed-multisig-process-improvement-discusssion/6491/1 "2025-04-30T15:06:45Z")

</div>

The Compound Finance community recently [voted](https://www.tally.xyz/gov/compound/proposal/425?govId=eip155:1:0x309a862bbC1A00e45506cB8A802D1ff10004c8C0) to improve their multisig process and documentation, improving things for both the signers and the community. Please note this is a process improvement only, no changes to the software. The improvement included proof of distinct humanity, regular testing of the signers, comprehensive documentation for both [public](https://docs.google.com/document/d/19-GFwd34UlPHIx-AjlGlI3BQcWq71UKe/edit?usp=sharing&ouid=116885299862333606958&rtpof=true&sd=true) and the [signers](https://docs.google.com/document/d/1cbvX4pCFqjfERGO4Vm8SqY4HW_y9WFdA/edit?usp=sharing&ouid=116885299862333606958&rtpof=true&sd=true) and a [history](https://docs.google.com/document/d/1U9mn79a4tpiJdTAFpfPXUVHgPuCQanCk/edit?usp=sharing&ouid=116885299862333606958&rtpof=true&sd=true) document of all multisig transactions.

[DeFiSafety](https://www.defisafety.com/) developed this process and is presently marketing it to other DeFi protocols. DeFiSafety has been [rating](https://www.defisafety.com/app) DeFi protocols on their quality processes and transparency for almost 5 years. We used this background in developing this process.

Questions:

1. Is this something that is already been developed?

2. Does the DAO want to be involved in the development of such a process in any way?

3. Any comments on what other DeFi protocols, exchanges, etc. might be interested in implementing such processes?

I am open to any form of comment, question or discussion.

When doing this work, 2 areas of improvement became clear. Please indicate if the DAO might have interest in these ideas such that I could propose them in more detail.

a) A comprehensive multisig best practise document including various types of multisigs (treasury and pause) with how to manage them.

b) A dedicated signing computer with locked down OS, minimal software that includes a hash with each signature such that the proposer can verify all signatures were signed by secure computers before executing.

Thanks for your time

Rex

[rex@defisafety.com](mailto:rex@defisafety.com)

Telegram @ShinkaRex

---

<div class="post-metadata">

### Author: ![amanwithwings](https://dub1.discourse-cdn.com/flex013/user_avatar/forum.safefoundation.org/amanwithwings/32/3997_2.png) [@amanwithwings](https://forum.safefoundation.org/u/amanwithwings)
#### Post date: [May 5, 2025, 8:23am UTC](https://forum.safefoundation.org/t/deployed-multisig-process-improvement-discusssion/6491/2 "2025-05-05T08:23:04Z")

</div>

Hey @RexShinka, interesting initiative! What kind of feedback are you looking for, in particular?

SafeDAO does not use a community multi-sig at the moment, so the potential for application of the initiative here is quite limited.

---

<div class="post-metadata">

### Author: ![RexShinka](https://avatars.discourse-cdn.com/v4/letter/r/9fc348/32.png) [@RexShinka](https://forum.safefoundation.org/u/RexShinka)
#### Post date: [May 5, 2025, 1:58pm UTC](https://forum.safefoundation.org/t/deployed-multisig-process-improvement-discusssion/6491/3 "2025-05-05T13:58:19Z")

</div>

I have 2 big questions with this post.

1. Do DAO members know of any other individuals or organizations who are doing multisig process efforts?
2. Does the DAO want to discuss formally supporting this initiative in some way? Safe.Global support would be a massive multiplier for the impact this initiative could have. I understand this is a big ask as it is a scope change for the DAO. However, as recent security incidents (Radiant Capital as just one example) have shown, multisig process weakness is among the biggest security threats in our space right now. No other crypto brand is better positioned to take up the multisig security processes than SAFE.

Do you have a community call? Maybe I could join.

---

<div class="post-metadata">

### Author: ![1a35e1](https://dub1.discourse-cdn.com/flex013/user_avatar/forum.safefoundation.org/1a35e1/32/4336_2.png) [@1a35e1](https://forum.safefoundation.org/u/1a35e1)
#### Post date: [May 5, 2025, 8:33pm UTC](https://forum.safefoundation.org/t/deployed-multisig-process-improvement-discusssion/6491/4 "2025-05-05T20:33:35Z")

</div>

From a process side we have one of the only mobile signing solutions that was supported from a SafeDAO grant.

You can see how it works here; [Native voting with Safe on Snapshot — Lighthouse Labs](https://mirror.xyz/lighthousegov.eth/hXRNIREb5VibvuqWjN940gf7yZQLJGZjrjPPCE4Ja2M)

Please note this is for currently for Voting only. Happy to discuss/explore if you wanted something similar for collecting signatures and notifying signers for txns.

Also heard good things about [https://www.onchainden.com/](https://www.onchainden.com/)

---

<div class="post-metadata">

### Author: ![amanwithwings](https://dub1.discourse-cdn.com/flex013/user_avatar/forum.safefoundation.org/amanwithwings/32/3997_2.png) [@amanwithwings](https://forum.safefoundation.org/u/amanwithwings)
#### Post date: [May 6, 2025, 6:25am UTC](https://forum.safefoundation.org/t/deployed-multisig-process-improvement-discusssion/6491/5 "2025-05-06T06:25:59Z")

</div>

> 1. Do DAO members know of any other individuals or organizations who are doing multisig process efforts?

I co-authored this with Tally and eth limo at DAOstar: [DAOIP-8: Applicable Controls for DAOs](https://github.com/metagov/daostar/blob/main/DAOIPs/daoip-8.md). Its a light weight first version for a best practices guide / security standard that will become more comprehensive over time. The section on key management is currently under developed. If you are interested in contributing, I would love to chat! DAOIP-8 should eventually get merged with [SEAL’s frameworks](https://seal-frameworks.vercel.app/). Full research [here](https://daostar.org/reports/security.pdf).

> 1. Does the DAO want to discuss formally supporting this initiative in some way? Safe.Global support would be a massive multiplier for the impact this initiative could have. I understand this is a big ask as it is a scope change for the DAO. However, as recent security incidents (Radiant Capital as just one example) have shown, multisig process weakness is among the biggest security threats in our space right now. No other crypto brand is better positioned to take up the multisig security processes than SAFE.

Why do you think it’s a scope change for the DAO? In any case, this might be a good application once the grant program is live. Feel free to share the initial idea here to garner community feedback.

---

<div class="post-metadata">

### Author: ![RexShinka](https://avatars.discourse-cdn.com/v4/letter/r/9fc348/32.png) [@RexShinka](https://forum.safefoundation.org/u/RexShinka)
#### Post date: [May 11, 2025, 7:36pm UTC](https://forum.safefoundation.org/t/deployed-multisig-process-improvement-discusssion/6491/6 "2025-05-11T19:36:34Z")

</div>

Thanks for the replies. Sorry for the delay.

Thanks for sharing DAOIP-8. It is a great resource. I am already a contributor to the SEAL Frameworks and multisig process will be my main contribution. I can put links to any drafts here for review and comment. Where can I see the status of the next grant round?

My stretch goal is for approval from Safe Global of the DeFiSafety multisig processes. This would mean I could say some kind of “approved by”. I ask for this as it will improve the number of protocols that would implement better multisig processes. Right now when I propose to DAO’s I mostly get shrugs and move on. Weak processes are the new weakest link in DeFi (because our software processes have become strong). I am open to any conversations on how to make this happen (even before grants).

I will be at Consensus and Futurist next week if anyone wants to chat IRL. Telegram ShinkaRex.
