★ Low-threshold multisig vs TVL
Concrete's assessment for RD-F-028 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
3-of-5 Safe threshold for ~$990M TVL. Any 3 of 5 signers can upgrade all vaults with no timelock delay, representing unilateral drain risk at ~$330M/signer. Peer norm for protocols >$500M TVL is 4-of-7 or 5-of-8. 3-of-5 is at the low boundary but not catastrophically low (e.g., 2-of-3 or 1-of-3 would be red).
Sources #
- EtherscanDefiLlama — Concrete TVL $989.8MDefiLlama TVL ~$989.8M: api.llama.fi/protocol/concreteretrieved 2026-05-17
- Safe Transaction Service — threshold=3/owners=5Safe API: threshold=3, owners=5 for ConcreteFactory owner Safe 0xdc29BD10retrieved 2026-05-17
Methodology #
Determine whether the multisig threshold is abnormally low relative to TVL peer cohort (e.g., 2-of-3 for a protocol with >$100M TVL where peer norm is 5-of-8).
See the full factor methodology and distribution across all protocols →
rubric_version v1.7.0 protocol concrete factor RD-F-028 score yellow collected_at 2026-05-17 14:36:59