yearn
4.8K posts

yearn
@yearnfi
vision https://t.co/A8fnPpojOe - docs https://t.co/HaUkJiVkL9 - discord https://t.co/A8mg4EfSIH




Admin Audit: a new kind of audit that only audits protocols from the perspective of multisig configuration, presence of timelocks on dangerous functions, use of cold devices for signing, multisig signing procedure, etc. Smart contract audits tend to focus on contract logic while treating admin roles as trusted. They might flag suboptimal configurations, but ultimately the pass/fail is based on presence of logic bugs. An Admin Audit would be the exact opposite - only focused on asking the question "what happens if multisig members get compromised" and "does the team follow best practices that substantially reduce the odds of compromise". Protocols would need to get both a smart contract audit and an admin audit - users would demand both. The admin audit would be substantially cheaper than the smart contract audit since the best practice is well-defined and issues are obvious, whereas smart contract audits are looking for needles in haystacks. Ecosystem foundations could subsidize these - for example, if a reputable firm offered these, we at the Monad Foundation would be happy to subsidize. Admin audits would capture a lot of the low-hanging fruit. Realistically, many of the huge hacks in the history of DeFi have been admin compromise rather than logical bugs. If you are building this, please reach out.

















