Welcome to East to East to East to East to East. Yeah. Wonderful. Next up, we have uh Christopher with Multi6 Mystified. Thank you very much.
Hey guys. Um good afternoon. Nice to see you here. I'm kind of local here to Amsterdam, so uh always nice to see uh people coming to this event. Um yeah, thank you for making the trip.
I know Amsterdam is not the cheapest city to stay. So, uh, you know, definitely thanks for your efforts. Um, I'm going to talk a little bit about Multis. I work for Polygon, by the way. I lead the security team over there.
And I'm going to talk a little bit about Multi6 because it's lately kind of what I do or what I worry almost on a daily basis. No. So, uh, a fun fact, last night I was watching a movie with my wife. Uh, it's called Conclave. Maybe some of you watched it because, you know, we there's a new pope and I'm like, I don't get any of these things.
I'm actually self- American from Argentina. I'm like, I don't really get what the church does or anything like that. So, I saw let's watch the movie, understand how it works. And I'm like, holy this whole Conclave thing is the same thing that we do for multiigs and like just the the the internet in general and how everything works. So, I went directly to ChachiPT and I told them, please, you know, build me, you know, give me four reasons why conclaves are similar to multisig.
And this is uh basically what uh Chhatip came up through. No, but but really it's it's completely true. No, like first of all, threshold approvals. No, we need to set up thresholds, you know, three three out of five, six out of seven, 10 out of 13, stuff like that. You know, in in the pope's conclaves, it's you know, 2/3 of the actual um you know, pop uh basically cardinals over there need to agree and until they agree there's not the transaction is not going to be confirmed.
There's not going to be a new pope etc etc etc. Next one over here is about secrecy and isolation like like incredible as well. That's why we use things like hopefully everybody use here things like a hardware wallet and stuff like that so that the actual secrets don't go away and don't leave that room. No, one of the things that also impressed me a lot was um you know once all the voting is done on those little papers and stuff like that they burn all those papers. No, which may not be you know part of like the the the crypto ethos or stuff like that but it's like there is no trace of actually what people voted or didn't vote and stuff like that.
So in certain degree blockchain is better than you know a pope conclave because at least you have traceability about who voted for this pope or who didn't you know maybe this is a talk more about like how the church could use blockchain I don't know um you know another thing here redundancy resiliency all the whole idea and I'm going to talk about it later is you need to make sure that when you're using multiix and and and just in general when you're making decisions when you're creating consensus protocols make sure there is redundancy make sure that there is no single uh failure point or centralized point on that if somebody dies, disappears, is away from office or whatever it is that your business can still continue like you can still run transactions. No, that's why you have, you know, more people in that multisig that actually is required for for those signatures. Like don't make a one to one multisig, please ever like like you lose that key and you lose that multisig. Ha, how fun or a two out of two. No, it's stuff like that.
There may be reasons sometimes to do it, but in general like not not really recommended. And last but not least, you know, it's about, you know, collective trust. No, like in the end and then I think the base rollup talk that was just here before touched on it as well. In the end, a lot of the rollups and the systems and the blockchains and everything else that you see out there is based on trust. You're trusting this group of people, these group of signers in the future.
They're probably going to be robots, you know, to do the right thing, to sign the right transactions and uh, you know, move the protocols and the decisions forward. Yeah. So you know uh this has been happening for a long long time and multisigs are actually not new. No if you actually look at some other type of examples in the world outside of technology but also inside of technology. So one of the most um you know interesting at least for me as a security professional as engineer throughout my lifetime was all was these key ceremonies for the certificate routes.
No. So you know the internet is basically governed by a couple I don't know five 10 different certificate routes that are issued and basically you know give you the little lock in your browser that's because there we all trust these five or 10 companies to provide those locks to provide that encryption those encryption keys and there's a key ceremony that happens once in a while to rotate the keys to change them to update them etc etc where literally people are flown in from all over the world they don't even know where they're going they're locked up in a room. They're giving new computers like out of the box. They all sit together and they sing a song and magically the internet continues working year after year after year. Now, another example is like the the nuclear uh launch protocols.
I don't think it's a great multic over here, but you know, it's it's it's a two out of two multisig over here. At least that's what we know or what the movie shows us. No, like there's two people that need to come in with their keys, you know, and then and their little suitcases, you know, uh turn the key on and if those two people don't turn the key on, then no no nuclear, you know, systems will be attacked. Uh I think they could have a much better multi. Now imagine if the fate of the world, if the fate of the whole blockchain is, you know, like like I don't know, vitilix bootstrap node or whatever it is, is protected by a two out of two multisig like oh wow.
Yeah. Um, and last but not least, like pirate treasure chests. Now, uh, this one also was, uh, again, thanks Chachip for giving me ideas. No, if you're not using ChatBT or LLMs in general to do your work and to do everything your life, you're not going to make it in the future cuz, you know, this just makes your life so much easier and actually my presentation even a little bit more fun. um like treasure chest actually pirates had to have at least two keys you know or crew members with different keys to be to open the the treasure chest to ensure that you know nobody on the boat was actually able to steal uh the funds from it.
So these are there there are a bunch of other examples around there from how boards work in different companies. You know most companies especially the public ones have a board and in the end the big decisions about the companies there needs to be consensus among the board members. with different thresholds. Maybe everybody needs to agree, maybe some of them need to agree. But um again multiix consensus algorithms the only thing that we have created is um uh a traceable public way of actually doing these type of consensus decisions.
No. Uh that's really what multisix has been doing and and to be honest multis are going to be present everywhere now thanks to things like uh EIP702 that was just implemented on Ethereum that allows a lot of you know what we use as normal you know crypto wallets EOAS as they're normally called you know you're going to be able to actually use them as it was a multisc that comes with a lot of great benefits it comes with a lot of concerns uh attack vectors uh yeah things that I I'm still thinking about ways that you're going to be able to hack users even easier than you were able to do it before because signing a transaction nowadays, you know, while it still gives you access to your funds, it could give you access to a lot of other things because they can program, you know, something in reality behind it. So, um, in the end, you know, what we have reinvented here, as demonstrated by the Vatican, the pirates, uh, the nuclear bombs in the 50s and stuff like that is nothing new. No, the and the problems that multi6 have are also not new at all. No.
So, uh just I think everybody is kind of aware of some of the things over here. But one of, you know, these are a couple of one of of the biggest hacks that we've seen, you know, related to multisig starting by um why did I put multi-chain protocol? This is not multi-chain protocol. I changed it to uh skyroning. Uh so I'm sorry that that that SL that first one is wrong.
That's supposed to be Sky Mavis, uh, Axi Infinity, you know, one one of the biggest hacks over there. Basically, they were in this case, it wasn't a multi specifically. No, they compromised the validators over there, but in the end, it's kind of the same thing. No, so they compromised the validators and and be able to collude them in order to, you know, steal the money from the bridge. You got the orbit chain.
Again, the attacker was able to get seven of those 10 keys. Like, how did they get them? you know the information there's a lot of guesses most likely some type of fishing you know there's different methods they were able to do that you know in this case it was very unfortunate or these guys had very very bad security hygiene like getting the keys of seven signers wow like that's a lot of work um another one the radian capital obviously terrible multi security over here three out of 11 like you only needed three to compromise three people it is very easy to compromise people. Just send them a fake link. Hey, you got a million dollars.
Hey, I'm the prince of Nigeria. Whatever it is, you know, if you know somebody or you investigate, you do some aent, you're going to find a way to trick him to click into a link there. There's always a way. No. Um, and then last but not least, the very very very famous hack of Bybit that will be remembered for, you know, probably a couple of years until the next big hack hack happens.
No, which will probably be even bigger. Uh, you know, where you know to this co-wallet that hold a lot of the bybit funds. No, they were actually tricked. Uh, it's not really by bits fault to a certain degree. Let me put it that way.
So, uh, obviously the safe interface was compromised. They were seeing that everything was okay, you know, in general. Like they tried very minimally, but they tried to do the right thing. Hopefully they were looking what they were signing. No, we assumed that they actually looked what they were signing, but in the end they were tricked because the front end was changed and it was showing something different and they were tricked in order to sign a transaction that actually uh changed the safe multisig upgrade over there.
There's a lot of things they could have done like they you know sorry if anybody's from by bit over here but you know just check with another front end. Um, you know, obviously everybody's talking about verifying hashes nowadays and stuff like that, but if you would have just checked the payload, check with another front end, simulate, do some of the basic hygiene things that I'm going to talk right now, especially for a company like Bybit, like I I understand if you know it would have happened to anybody us over here, but you know, to a company as big as Bybit, not having good security practices for these type of transactions, yeah, seems uh kind of crazy. So, uh, yeah, that's it. Oh, yeah. I wanted to ask, so what what are the patterns over here?
Like what what's what's the attack vector in all of these hacks and all of the biggest hacks that you know you've seen in general? Humans. Yeah. Humans basically. And And how do we ensure that humans don't make mistakes?
Sorry. You know, no, we give them instructions, you know. That's why Eaya is very good at g at, you know, people building furniture from Eaya are really good at it because I gives very good instructions relatively on how to build the furniturees. You know, they've gotten over the years really great at explaining every single little piece, you know, of of how you have to build that piece of furniture. And in the end, you finish that furniture and you're like, "Wow, I'm I'm amazing.
I I should study, you know, civil engineering or become an architect after that. But there's a lot with it. Um, so just a couple of very simple recommendations. There's a lot more and I'm going to share a link afterwards that was built by somebody else really cool. So first of all, obviously use safe threshold signing, you know, setups.
Meaning, you know, don't do a three out of 10. Like no, that's that's horrible. That means that means that they only need to compromise three people and they can try with 10. So you know kind of the chances for for for for compromising three out of the 10 people they are quite high. The chances of compromise like it would be better to have a three out of five in that case because the chances of compromising five of the three out of out of that five people are less uh than compromising 10 of them.
Um, if you are part of councils or you manage councils or you're in governance or you know a lot of you probably do some onchain type of voting or participate in governance, make sure that when you're cho choosing the people that are part of the multisig first of all they're trusted. No, ideally you don't want fully anon people. No, they have to be some type of you know known who they are or sodo anon meaning that you know they're they're very known like if if if something happens you know that the police will be able to catch him or not catch him but you know be able to track him down or somebody will be able to track him down. Uh make sure they're techsavvy. No, I see so many councils and multi with people that just because they're great influencers and stuff like that, they're sitting in this councils, you know, getting their paycheck of 5K every month for whatever it is, and they have no idea how to verify transactions, check the payloads, and they're not even like interested in what the protocol is doing.
They're just there like, "Okay, yeah, I'll sign because I people believe in me because I'm I have a lot of followers in Twitter, whatever." No. And then uh diverse signers as well. No, ensure that you do have a little bit of diversity like you don't want a you don't want a multiig with like 10 security people like that multisig will never be able to execute anything because nobody will trust nobody and you know security people are annoying and it will ask too many questions and you want things to move forward. So make sure you have a diverse you know set of skills over there but in general everybody should be technical and understand how to interact and use multiix hardware wallets graphic um you know distributed you know around the world not everybody in the US or not everybody in Europe you know just in case you know things happen um time locks limits where possible implement as well um and then during the operations of things no uh one of the things that I've started to do that.
It's I feel it's relatively new. Probably a lot of people did it before me, but it's like having a dedicated browser profile or have a dedicated uh user in your computer like in your Mac or in your Windows. Just create a new user that you only use to do transactions. And that way you don't install any crap. You're not watching porn over there.
You're not, you know, lending your computer to your kids to do their homework or whatever it is. You know, it's a complete different user, a complete different browser profile. Yeah. Even better if your job if you're in finance and part of treasury and you do multi6 all single day then have a specific laptop just for this like there have been talks about Chromebooks. I've personally never used a Chromebook.
Um I don't know if it really works. It seems it works. No, it probably seems like a good idea. Don't trust me on this. But have a specific computer you only use for for signing stuff.
That would be you know the the best of the best. But again usability is not great unless this is your job. your job is signing 20 transactions per day or more. Um, health checks, monitoring, make sure that everybody's alive once in a while. No, like heartbeats, like every three months, like, hey, is everybody here?
Do you still have access? Like, people lose their wallets. It's normal. It's okay that you lost your wallet or, you know, you don't have access to it for whatever reason, you know, just make sure you're you're you're heartbeating and and that people are there. Notifications like also very useful.
There's a lot of like onchain den is a great uh app to do trans I wouldn't do the signing over there but they have great integrations with telegram slack and some other things to give you notifications uh and then have formal procedures. Yeah. Uh I have no idea how I'm doing on time but um two minutes. Okay. So I only have two slides.
So I'm going to give you this is kind of how we do transactions at Polygon. Yeah. It's not exactly the process, but it's more or less a process of how we do transactions over here. Now, and what I want you to really pay attention are those uh green check boxes because those are moments where security actually checks what's happening now. So, specifically for contract upgrades and real big transactions and stuff like that, the security team at Polygon, which I'm part of obviously, we do a lot of checks.
We obviously we have a pre-fi checklist. The payload is prepared by a developer, an engineer, and then security checks the payload. Okay, let's make sure the developer didn't put his address in a thousand bucks as well or a million bucks in there as well. Then the transaction is proposed. Once it's proposed, we check it again to make sure that nothing happened in between the payload was built and the payload was proposed.
I cannot tell you how many times we've seen like fat fingers, errors in copy paste, uh just just people choosing the wrong version of the payload because the version the payloads many times have different versions and like oh sorry I proposed the wrong one. It happens. It's okay. And that's why security checks once the transaction is proposed. Once it's proposed obviously you gather all the signatures security normally or you know just stay vigilant you know make sure that those signatures are coming through.
That's why alerts monitorings are important. Um then just before executing you do a last check as well like like even though you did all these checks and nothing really should have changed just check again. and get somebody else to check it for you if you don't have a security team or something like that just before you execute it. Execute and you check again make sure that what you deployed is what you expected to be deployed. I can promise you there have been so many mistakes in the ecosystem where things were deployed and only at the end they're like oh damn this is not the version of the code we needed to deploy know and uh do a bite bite uh bite code check or stuff like that and um yeah and then obviously you're going to have a lot of post-flight checklist stuff like in Polygon obviously we moni you know add to our monitoring ensure everybody's informed add to the bug bounty program a lot of other things Um, so just to recap a little bit about this, and this came out of me.
This was not CHPD, I promise. Um, uh, I'm really sorry. I'm going to have to cut you off. We've gone quite far over time now. No problem.
Thank you very much. Uh, thank you.
Automatic transcript — names and jargon may be misspelled.