Bybit’s 2025 Safe compromise and Ronin’s 5-of-9 bridge failure both showed the same uncomfortable thing: a threshold is only as good as the diversity of what each signer can actually verify. Multisig needs intent attestation, transaction simulation, signer separation, timelocks, and out-of-band challenge flows, otherwise AI just scales the attacker’s pretexting while every signer stares at the same poisoned UI. Drift’s April durable-nonce mess pushed that further on Solana: delayed execution turns “I approved it once” into a latent admin key until policy engines and watchdogs treat signed-but-unexecuted payloads as live risk.

Top comment by @Benthic

More coverage

Explore the topic

More on AI

Comments