defirisk.co
rubric v1.7.0

Multisig signers co-hosted

A governance & admin factor in the v1.7.0 rubric. Measured per protocol on a s cadence.

Methodology how we score#

What this measures
This factor assesses whether the signers of a protocol's governance multisig are co-hosted — sharing the same autonomous system number, data center, cloud provider, or custodian. The assessment combines on-chain address analysis (network fingerprints from signing transactions) with OSINT on the addresses' activity patterns. Co-hosting means that a single infrastructure compromise could simultaneously expose multiple signer keys, collapsing the effective threshold.

Why it matters
The security guarantee of a 3-of-5 multisig depends entirely on the independence of the five signing parties. If three of those signers operate on the same cloud infrastructure or with the same custodian, a single breach of that provider collapses the 3-of-5 to a practical 0-of-2 recovery problem. The evidence base includes cases where hardware co-location with a compromised vendor reduced an apparently robust multisig to a single-point-of-failure. This factor is particularly relevant for protocols that disclose their signer list publicly — the co-hosting analysis can then be performed at the address level using on-chain transaction metadata.

Green / Yellow / Red
Green is assigned when signers are demonstrably distributed across different cloud providers or custody solutions and no co-hosting signals appear in on-chain data. Yellow covers cases where partial co-hosting is suspected but unconfirmed, or where signer distribution is not publicly verifiable. Red is assigned when on-chain or OSINT evidence confirms that a quorum-forming set of signers share the same infrastructure or custodian.

Common gray cases
This factor is grayed when the signer list is not public and on-chain inference is inconclusive — a common state for protocols that do not publish their multisig composition.

Notable historical examples
No cross-hacked incidents currently linked in database for this factor.

Measurement what to look for#

Determine whether multisig signers share ASN / data-center / custodian according to on-chain and OSINT inference.

Data & output #

Data source
Chainalysis/TRM cluster feed for signer addresses + ASN lookup on signing IP patterns (OSINT) + curator assessment
Output format
Green / Yellow / Red
Evidence artifact
Signer address list + ASN/custodian inference per signer + curator note
Confidence signal
green = signers demonstrably on independent infrastructure; yellow = partial evidence of co-hosting or insufficient data; red = confirmed co-hosting (same ASN or same custodian for majority); gray = cannot infer from available data

Scored protocols 0 carry this factor#

No protocols have been scored for this factor yet.

Linked hacks no historical incidents linked#

No historical incidents are linked to this factor.
rubric_version v1.7.0factor RD-F-029category 2carried 0critical no