SEAL FrameworksSecurity MapDocsMultisigDeploymentDomainsSignersSupply chainResponseAI agentsENSDisclosureThreat modelGapsAllTreasury and upgrade authority held by a multisig, the signing workflow, and the controls that keep signers from being the weak link.AssetsWhat can be lostGovernance authority1Treasury funds6User funds10ComponentsPeople, systems, accountsCI/CD pipeline1Custodial treasury7Governance module1Hardware wallet4Monitoring stack1Protocol multisig7Signers2Smart contracts4Attack surfacesHow it is reachedActive exploit window2Contract external calls and value flow1Contract upgrade path2Multisig signing workflow5Physical presence and travel3Researcher inbound path1Signer onboarding and offboarding1Transaction signing7ThreatsHow it failsBlind signingCustody access abuseGovernance attacksMisdirected transferMultisig operational failureSmart contract exploitsWhitehat legal freezeControlsWhat reduces itCold and hot wallet separation5Controlled-surrender wallet7Duress signing limits6External security review1Geographic key separation5Independent transaction verification5Multisig threshold policy6Published recovery address9Published security contact1Hardware-backed signer isolation6Simulate and decode before signing3Whitelist and delay policy5GuidanceWhere to implementSEAL certifications1Cold vs hot wallets3Key compromise runbook2Safe Harbor scope terms2SFC: Multisig operations7SFC: Treasury operations6Assessments stay in this browser. Share URLs may include view and focus. They never include assessment state.Export assessment Import assessment