A proposed transaction can be confirmed and executed after the signer set changes.
Confirmations are tracked per address and accepted if the confirmer currently has the signing role. There is no snapshot of the signer set when a transaction is proposed, no expiration window for proposals, and outstanding confirmations are not invalidated when the signer set changes. This enables later signers (added after proposal) to retroactively complete quorum for earlier proposals.
Likelihood
This occurs during normal signer management operations when owner replaces a signer after a transaction is proposed.
This can also occur after an account compromise when new signers are added.
Impact
Funds can be transferred by a different signer set.
The stated multisig guarantee (e.g., "3‑of‑N required") is broken.
Add a grant timestamp and prevent newly-granted signers from confirming transactions proposed before their grant
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.
The contest is complete and the rewards are being distributed.