Normal behavior:
A multisig should not have a single EOA with unilateral control over membership and transaction flow.
Issue:
Owner has exclusive control over:
granting/revoking signers
(often) proposing transactions
Even if the ghost-vote bug is fixed, owner control still creates a backdoor:
compromised owner can replace honest signers with attacker signers
then approve and execute malicious transactions
Likelihood:
Owner key compromise is common.
This is a design-level weakness.
Impact:
Full takeover of multisig governance and funds.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.
The contest is complete and the rewards are being distributed.