Security

Multisig coordination for governance execution

Multisig coordination illustration with several signer keys unlocking one DAO wallet
Multisig coordination illustration with several signer keys unlocking one DAO wallet

A multisig is a safety mechanism until it becomes a bottleneck. Coordination - not cryptography - is what usually breaks.

Size the signer set deliberately

Too few signers concentrates risk; too many makes every execution a scheduling problem. Three-of-five is the practical baseline for most DAOs.

Make signing state visible

Signers should see which proposals are waiting, how many signatures remain, and how much of the timelock window is left - in one view, not a group chat.

Plan for the missing signer

Rotate signers on a schedule, keep a documented recovery path, and never let one person hold two keys.

Choosing a signer set that survives real life

Signer sets fail for boring reasons: people travel, change roles, lose devices or simply stop replying. A useful test is to ask whether the treasury could still move if any two signers vanished tomorrow. If the honest answer is no, the threshold or the roster is wrong.

Spread signers across timezones and across organisations. Five signers in the same office and the same chat group is one compromise away from being a single key, however impressive the threshold looks on paper.

Signing hygiene that prevents expensive mistakes

Every signer should verify the target address and the decoded call before approving, not just the human readable summary in the interface. Address substitution and disguised approvals remain among the most successful attacks on collective wallets.

Keep a rehearsed process for rotating a signer, and run it at least once before you need it under pressure. Rotation is also a governance action, so it should be proposed, approved and recorded like any other change.

Keep the execution path connected: this guide pairs well with rollup governance, governance proposal template and dao governance metrics, which cover the neighbouring steps between an approved vote and a settled onchain transaction.

Key concepts explained

New to this topic? These are the core terms you will meet again and again in governance work. Understanding them makes every proposal easier to read.

Multisig
A wallet that requires M-of-N signatures to move funds - for example 3 of 5 signers. It removes single-key risk but adds coordination overhead.
Signer set
The group of keyholders authorized to approve a multisig transaction. Diversity across timezones and organizations makes the set resilient.
Threshold signature
The minimum number of approvals needed before a multisig transaction is valid. Governance should verify this count before execution, not after.
Signer rotation
The governed process of adding or removing signers. Because rotation changes who controls funds, it should itself require a full proposal and timelock.

Frequently asked questions

What threshold should a DAO multisig use?
Three of five suits small working groups, while treasuries of real size commonly use four of seven or five of nine. The goal is a threshold high enough to resist collusion and low enough that routine payments never stall.
Is a multisig the same as a DAO?
No. A multisig is a wallet that requires several approvals. A DAO is the governance system that decides what that wallet should do. Many DAOs use a multisig as the execution arm of their governance.
What happens if a multisig signer loses their key?
As long as the remaining signers still meet the threshold, the wallet keeps working. The DAO should then approve a rotation transaction that removes the lost key and adds a replacement.

Keep reading