defirisk.co
rubric v1.7.0

Low-threshold multisig vs TVL

QuickSwap's assessment for RD-F-028 — scored red on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

On-chain required=2 (2-of-4 threshold) against $451M TVL. Peer norm at >$100M TVL is 5/8 or 4/7 minimum. 2 compromised or colluding signers suffice to execute arbitrary transactions with zero delay. Documentation claims 3-of-4 which conflicts with on-chain value — on-chain state is authoritative.

Sources #

  • Etherscan
    QuickSwap Admin Multisig readContractPolygonscan readContract on 0xdB74C5D4F154BBD0B8e0a28195C68ab2721327e5 shows required=2 (2-of-4)retrieved 2026-05-16
  • URL
    DefiLlama QuickSwap TVLDefiLlama TVL $451,399,708 for QuickSwap as of 2026-05-16; 2-of-4 is anomalously low for this TVLretrieved 2026-05-16

Methodology #

Determine whether the multisig threshold is abnormally low relative to TVL peer cohort (e.g., 2-of-3 for a protocol with >$100M TVL where peer norm is 5-of-8).

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol quickswap factor RD-F-028 score red collected_at 2026-05-16 08:48:31