# Don’t Sign Blindly: Fast-Track Tools & Tactics for Multisig Transaction Verification - Alex | Lido

- Channel: [ETH Belgrade Community](https://streameth.org/eth-belgrade-community)
- Date: 2025-10-07
- Duration: 15:53
- Watch: https://streameth.org/watch/yt-E-daHiHmKYo
- YouTube: https://www.youtube.com/watch?v=E-daHiHmKYo

## Description

Don’t Sign Blindly: Fast-Track Tools & Tactics for Multisig Transaction Verification - Alex | Lido

## Transcript

Uh today uh I'm going to tell you a story about a big hack that shook the market and the industry as well as how we tried to avoid being a target of that hack. Uh name is Alex. I'm a contributor at the DAO. Uh I'm a DA techinfra lead uh lead of the team that make sureures that the governance rails are oiled up and ready for the proposal train arrival. Uh so what happened happened? Grand Theft Crypto the biggest hack uh in terms of extracted value in the history was made not by exploiting some smart contract but by hacking an offchain part on of the onchain operation. And why bother? Why is it important for Lido? Uh let's add a bit of context here. Uh, wid is a liquid staking protocol on Ethereum currently holding around uh 9 million uh if it's a middleware connecting users with uh with uh if and node operators and uh it allows to stake any amount of if uh get stiff if and use it across the DI uh and the whole beauty is governed by light the dowo. What is why the DAO? This is the question. Um and the answer is a topic of another talk. So we'll focus on just on one part of u the DAO. Uh which is or are committees. Uh so and there are more than 20 committees within the DAO. Each committee has its own purpose and uh almost each one has its own multisc brief list of operations that committees are executing. Of course, the most popular operations are uh grant issuance. Uh for example, it could be uh ecosystem grant or reward distribution or some kind of compensation. Uh so any any token transfer is uh under that category. Uh also we have uh within committees uh emergency brakes that allow to special mechanism that allow to post protocol for some time as well as easy track motions uh which are part of governance process. Easy track is an optimistic uh governance framework made for optimizing uh some mundane processes within DAO and other smart contract interactions and some uh those operations are holding some risks. Of course the biggest risk is to lose funds. uh currently the number is the maximum amount is uh 8 million USD and to make uh like unintentional procedures for example to pause different parts of protocol uh we don't we don't want that to happen. So when we heard the news about the hack, the reaction was immediate and uh all onchain operations were put on hold and we started to think how can we make sure that uh our not seek transactions are valid and how to make sure we are not signing something bad. Uh so the main problem the main issue is we can't trust safe UI and safe API anymore. This is the bold statement but at the moment they were compromised and we were not sure uh that we uh can trust them. So we need to find a way to basically to work with uh safe UI without trusting this UI and uh this problem could be split into three questions that we need to answer. First answer is how to verify transaction uh without inter without the safe. Second question is uh how to implement it fast because the clock's ticking all operations were put on hold and we want to unlock this process as soon as possible. Uh and third question uh standard one, how can we avoid worsening security? Because if we want to improve something, if we want to add a layer of defense, uh we could easily um make the surface of attack bigger and add unintentionally add some attack vectors. So uh in trying to answer those questions, our first step was just opening Twitter. Um user with a with a nickname PC Versace uh made a script a common interface to uh check and to verify safe transactions. Basically what I mean by verification is the process of calculating hashes uh that are visible as in the safe UI as well. Uh we'll get to them a bit later, but just to add context to this solution, um later after the author posted the script, uh audit company siphoning made its fork uh and it was better because it contained the offline mode which allowed to calculate those hashes without using safe API. So we started to try and uh to play the with this script. We reviewed the code and it was good enough for us to implement. Uh this is how the u like result of the the script looks like and you see in the red uh there are three hashes that we'll focus on. Uh basically the process looks like this. you see those hashes in the safe UI and you adding the second source of truth generating from uh this place you're generating those hashes and you see uh whether they're matching themselves or not. If there is a match for all three hashes, then you're good and you can proceed. But if not, uh you need to abort immediately and seek for help. Something is bad. And uh let's see what those hashes are. So uh you see on this screenshot, this is just an ordinary transaction of uh sending one USDT from one address to another. We have uh all our favorite fields like two value called data. Uh we have a type of operation and some uh nons and some safe related fields. But below all of that we see those hashes. Uh and uh let's see how can we calculate them. This is all possible uh because of uh EIP 712. So those three hashes uh it's very easy to to get them without interacting with some for example remote server. Uh you just need to know the uh safe config. So some values related uh with safe itself to get the domain hash and then you need all the transaction data to get the message hash. And if you wrap both those hashes into ketchup function, you'll get uh safety x hash. So those are three hashes that we need to verify. This is all great, but the question is will we use the CLI solution with uh more than hundred of signers within light the dowo? Uh I think the CLI could be very tedious and if you use script like this it's a very good temporary solution if you need to act immediately but if you want to improve process somehow uh you need to come up with something else. Of course, the most obvious answer is uh make some kind of UI. But there is an issue uh which is really a feature and not a not a bug. Uh we are cooking slowly but surely because the standards are are very high and the process is a multi-step with uh reviews and audits and all the checks all the checklists. So we can't like just make something deploy it to uh for example to Verto and say yeah this is good we can use it we approve it uh and we if we want to do something if we want to do something big and serious we need to consider the the whole timeline for doing that and that wasn't the situation there. So uh what we did uh the result of the hard work uh was a hash calculator. It is a very simple tool which serves only one purpose to generate those hashes. It has zero dependencies. Uh actually it has one but it's embedded in the script itself. Uh it is fully offline. Basically it is the HTML file that you can download and use. You can upload it into like some remote source. You can upload it into IPFS. You can use it locally, whatever you like. And it's pretty easy to run. You have basically an input field for each uh part of the safe transaction in the button. You generate hashes and compare them with what you see in the safe UI. This is the QR code for those who are interested in taking a look. Uh it is a public uh repo and it's open source. So all suggestions are are welcome. Uh and then so what's next? It's the question that uh popped up like immediately because the solution was good enough uh for uh for it to implement within the signers uh within the committees but it is still pretty raw and uh we were thinking on how can we improve the process and make it uh easier. Uh the problems that we saw is first problem it it's not most it's not the most important one but uh it's a bad developer experience because you have all the code in a single file. The second problem is um because of browser interface we are using browser to render the application. We are vulnerable to uh some brow like to browser um browser hacks uh and we need to copy paste the data that part can also be poisoned. So we need to be still extra careful and we need to validate all the fields that we are putting from one window to another. But still uh even those are problems that we have the solution is good enough uh to answer those questions that we had uh previously and improvements that we see uh safe is cooking as well and I hope they made uh access to the remote server more strict uh since then. But on the side of UI uh they now have a feature that allows you to basically copy the whole transaction uh payload uh and paste it in different forms and even download it as JSON file. So it is very more accessible because at the time uh that we were making this tool it was like they don't even show you the the whole hashes. They they show like first four symbols then dots then last four symbols and they have a copy button which can be easily hacked if someone has like an access to server like uh by by bit hacker head. So now it's uh better 10 times better and we can uh evolve our solution to be on par with the safe updated safe UI. But the endgame for such process as I see it uh is a full scale solution that will include not only some kind of tooling for uh checking the code data, checking the um multisk uh hashes but uh comprehensive guide for all signers with all steps and described cavits and also some kind of monitor monitoring solution because it's very important to see what's going on within those like 20 to 30 multi uh who are who are the owners, what's the threshold, what are the uh token approvals, etc. It's just it's just a general like security thing. So instead of conclusion uh a couple of advices they're pretty basic in general but please if you are going to sign some transaction please check all the values please use the tools that you trust uh they better be audited but at least you need to trust those tools use some uh cold data decoders to see what's going on within transaction uh that you are going to sign and if you are sure in any action you do, seek help from someone uh you trust and of course question yourself at every step. That's a pretty good advice in general. And what shouldn't you do? Uh you shouldn't rush while signing transactions. It's a very it's still very complex process unfortunately and you need to be careful at every step and do not store $1.4 billion on a single mod. That's uh like the common knowledge I think and uh I hope that the industry learned that lesson. Uh spoiler not really but maybe it will learn we'll learn it soon. And don't trust anyone especially yourself and especially me I guess. So that's all. Thank you so much for listening for your attention. You can follow me on Twitter. Uh we'll have some pretty interesting content soon and don't sign widely. Thank you.
