Security
Multisig coordination for governance execution

A multisig is a safety mechanism until it becomes a bottleneck. Coordination - not cryptography - is what usually breaks.
Size the signer set deliberately
Too few signers concentrates risk; too many makes every execution a scheduling problem. Three-of-five is the practical baseline for most DAOs.
Make signing state visible
Signers should see which proposals are waiting, how many signatures remain, and how much of the timelock window is left - in one view, not a group chat.
Plan for the missing signer
Rotate signers on a schedule, keep a documented recovery path, and never let one person hold two keys.
Choosing a signer set that survives real life
Signer sets fail for boring reasons: people travel, change roles, lose devices or simply stop replying. A useful test is to ask whether the treasury could still move if any two signers vanished tomorrow. If the honest answer is no, the threshold or the roster is wrong.
Spread signers across timezones and across organisations. Five signers in the same office and the same chat group is one compromise away from being a single key, however impressive the threshold looks on paper.
Signing hygiene that prevents expensive mistakes
Every signer should verify the target address and the decoded call before approving, not just the human readable summary in the interface. Address substitution and disguised approvals remain among the most successful attacks on collective wallets.
Keep a rehearsed process for rotating a signer, and run it at least once before you need it under pressure. Rotation is also a governance action, so it should be proposed, approved and recorded like any other change.
Keep the execution path connected: this guide pairs well with rollup governance, governance proposal template and dao governance metrics, which cover the neighbouring steps between an approved vote and a settled onchain transaction.
Key concepts explained
New to this topic? These are the core terms you will meet again and again in governance work. Understanding them makes every proposal easier to read.
- Multisig
- A wallet that requires M-of-N signatures to move funds - for example 3 of 5 signers. It removes single-key risk but adds coordination overhead.
- Signer set
- The group of keyholders authorized to approve a multisig transaction. Diversity across timezones and organizations makes the set resilient.
- Threshold signature
- The minimum number of approvals needed before a multisig transaction is valid. Governance should verify this count before execution, not after.
- Signer rotation
- The governed process of adding or removing signers. Because rotation changes who controls funds, it should itself require a full proposal and timelock.
Frequently asked questions
- What threshold should a DAO multisig use?
- Three of five suits small working groups, while treasuries of real size commonly use four of seven or five of nine. The goal is a threshold high enough to resist collusion and low enough that routine payments never stall.
- Is a multisig the same as a DAO?
- No. A multisig is a wallet that requires several approvals. A DAO is the governance system that decides what that wallet should do. Many DAOs use a multisig as the execution arm of their governance.
- What happens if a multisig signer loses their key?
- As long as the remaining signers still meet the threshold, the wallet keeps working. The DAO should then approve a rotation transaction that removes the lost key and adds a replacement.