The multisig is designed to require a threshold number of confirmations from a dynamic signer set to execute transactions.
However, when the signer set or required confirmations are updated, existing pending transactions are not reconciled against the new signer configuration, causing transactions to become permanently unexecutable.
Likelihood:
Occurs during normal governance operations such as signer rotation
Common when multisigs evolve over time (add/remove owners, adjust quorum)
Impact:
Permanent locking of already-approved transactions
Governance paralysis without fund loss recovery path
Confirmations are stored per-address without being invalidated or recalculated when ownership changes. This causes transactions to reference a non-existent quorum, permanently bricking them.
Invalidate or rebase confirmations when signer configuration changes.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.
The contest is complete and the rewards are being distributed.