Polygon, a prominent Layer-2 scaling solution for Ethereum, is currently under intense scrutiny regarding its security protocols, specifically concerning the multisignature (multisig) contract that governs its administrative key. This critical key holds sway over an estimated $5 billion in user funds, prompting significant concerns from prominent figures within the cryptocurrency community. Justin Bons, Founder and CIO of Cyber Capital, has publicly accused the Polygon team of employing lax security measures, arguing that the current setup presents a substantial risk of a major hack or even an "exit scam."
Polygon, often recognized as a "sidechain" to Ethereum, operates as an Ethereum Virtual Machine (EVM)-compatible blockchain, maintaining its own network of validator nodes. Beyond its sidechain capabilities, the Polygon team has also made substantial investments in pure Layer-2 technologies, including the development of scaling solutions like Miden, which leverages zk-STARKs. This dual approach has positioned Polygon as a leading platform for fast, low-fee transactions, attracting a significant influx of users and capital. However, with this success comes the inherent responsibility to safeguard the assets entrusted to the network.
The core of the current controversy lies in the composition and control of the Polygon smart contract multisig. Bons detailed his concerns in a series of tweets on February 12, 2022, asserting that the network, in its current state, is both "insecure & centralized!" He elaborated, stating, "It would only take 5 people to compromise over $5B! 4 of those people are the founders of Poly! This is one of the largest hacks or exit scams just waiting to happen. Reckless & irresponsible, a warning to the wise."
The Multisig Vulnerability: A Concentration of Power
According to Bons’ analysis, the Polygon smart contract admin key is managed by an eight-signature multisignature contract, requiring a minimum of five signatures to execute critical actions. This structure, he argues, creates a significant vulnerability. "The Polygon smart contract admin key is controlled by a five out of eight multi-signature contract," Bons explained. "This means that the Polygon [team] can gain complete control over Polygon with only one of the four outside parties conspiring. The other four parties in the multisig were also selected by Polygon."
This assertion suggests a potential for undue influence and a lack of true decentralization in the control of these vital funds. Bons further contends that the four "outside parties" included in the multisig are "not exactly impartial," given their selection by the Polygon team. The ability to change the rules of the protocol via this admin key, he posits, opens the door to a scenario where "anything becomes possible," including the complete depletion of funds held within the Polygon contract.
A History of Transparency Concerns
This is not the first time Polygon’s operational transparency has been questioned. Chris Blec of DeFi Watch previously lodged a formal request with the Polygon team seeking greater clarity on their security and governance mechanisms. According to both Bons and Blec, this request went unanswered, further fueling concerns about the project’s openness. The lack of a prompt and comprehensive response to such inquiries can erode trust within the decentralized finance (DeFi) community, where transparency is paramount.
Polygon’s Response: Acknowledgment and a Path Forward
In response to the growing concerns and Bons’ public critique, the Polygon team has not remained entirely silent. Historically, the team has published multisig transparency reports in an effort to address similar questions. Mihailo Bjelic, a co-founder of Polygon, indirectly acknowledged the validity of the multisig concerns in a Twitter thread on February 14, 2022. He stated that the team is "working towards removing them" and that the multisig was implemented during an "early phase" of development, acknowledging it may not be an ideal long-term solution as the network matures.
Bjelic emphasized that multisigs are widely considered "the optimal approach to secure user funds in the early phases of development and are used by almost every scaling and bridging project." He pointed to the existing transparency report, which outlines a "plan to improve and eventually remove multisigs."
Addressing Bons’ specific points, Bjelic countered the notion of an "exit scam" being a realistic concern for Polygon. He argued that multisigs are primarily employed to protect users from external hacks, and Polygon’s usage of them is a demonstration of responsible stewardship, contrary to the accusations of recklessness.
However, Bons remained critical, deeming a five-out-of-eight multisig "wholly insufficient" for safeguarding $5 billion. His concern about collusion among the selected outside parties, who he claims were "given" to Polygon by the team, persists.
Bjelic, in turn, clarified that the outside parties are "reputable Ethereum/Polygon projects and were not selected by Polygon, they decided to participate." He further explained the rationale behind the multisig configuration: "The more signers, the harder it is to coordinate them in case an immediate reaction is required. We are trying to find the right balance here; we already have more signers than most of the other scaling projects." This suggests a delicate balancing act between security, operational efficiency, and decentralization.
Proposed Solutions and the Future of Polygon Governance
Justin Bons also put forth a set of recommendations for the Polygon team to enhance security and decentralization. A key suggestion is the decentralization of governance, empowering MATIC token holders to participate in decision-making. Currently, Polygon operates on a Delegated Proof of Stake (DPoS) model, which Bons argues is too centralized, citing data from Polygonscan indicating that only four validators mined a majority of blocks in the preceding seven days.
Bons proposed that once governance is decentralized, the smart contract admin key should be transferred to MATIC token holders, effectively establishing a "Matic DAO" (Decentralized Autonomous Organization). This would likely necessitate a migration to a new Polygon smart contract, a process Bons acknowledges would be "very difficult and costly." However, he framed it as "the price to pay for not doing things right, to begin with. It is the price we pay for decentralization and the security that comes along with that. This is what cryptocurrency should be all about."
Mihailo Bjelic echoed this sentiment, stating that the proposed solution "is definitely our goal, as described in the transparency report." He added that the implementation would be gradual to avoid increasing reaction times in the event of a critical bug, implying a phased approach to decentralization and the eventual removal of the multisig.
Broader Implications for Layer-2 Solutions
The controversy surrounding Polygon’s multisig controls highlights a broader challenge faced by many emerging blockchain projects, particularly those operating as Layer-2 scaling solutions. The tension between the need for rapid development and operational efficiency in the early stages versus the fundamental principles of decentralization and robust security is a constant balancing act.
Multisig contracts, while a common and often necessary tool for managing critical functions in nascent projects, can become points of centralization and vulnerability as the network grows and the value secured increases exponentially. The sheer scale of funds now managed by Polygon underscores the critical importance of a truly decentralized governance model and robust security infrastructure.
The debate also brings to the forefront the evolving landscape of blockchain security. While centralized exchanges and smart contracts on Layer-1 blockchains have historically been targets for hackers, the increasing value locked in Layer-2 solutions means they are becoming equally attractive targets. The allegations against Polygon, whether fully substantiated or not, serve as a potent reminder to the broader ecosystem of the need for continuous vigilance, transparency, and proactive security measures.
The future of Polygon, and indeed many other scaling solutions, will likely be shaped by how effectively they can transition from the initial, often more centralized, operational frameworks to fully decentralized governance structures that align with the core ethos of the cryptocurrency space. The ongoing dialogue and the eventual implementation of changes by the Polygon team will be closely watched by users, developers, and investors alike, serving as a case study in the critical evolution of decentralized technologies. CryptoSlate reached out to Polygon for further comment but received no response by the time of publication. The quotes have been edited for clarity and conciseness.







