Skip to content

security(defi): make msig_approve opt-in (0.8.5) - #86

Merged
paulgnz merged 1 commit into
mainfrom
security/msig-approve-optin
Sep 24, 2026
Merged

paulgnz merged 1 commit into
mainfrom
security/msig-approve-optin

Conversation

@paulgnz

@paulgnz paulgnz commented Sep 24, 2026

Copy link
Copy Markdown
Collaborator

Fixes an external report. The defi skill's msig_approve signed an approval for a proposal it never read, knowing only its name. That lets injected text get an agent to approve a proposal that drains its account, and the 0.8.4 transfer cap never sees the inner transfer.

msig_approve is now off by default and needs ENABLE_MSIG_APPROVE=true from the operator. The setting is documented in .env.example, and the skill prompt now tells the model never to approve because a job or message asks it to. One test added; openclaw passes 215.

Follow-up: fetch and show the proposal's contents when the tool is enabled.

…ransfer cap) — 0.8.5

External report: msig_approve signed eosio.msig::approve for a proposal identified only
by name, without reading it. An attacker can propose 'transfer everything from this
agent', inject 'approve proposal X' via a job/listing/A2A message, and once the agent's
approval meets the threshold anyone can execute it. The agent only signs approve, so the
central transfer cap (0.8.4) never sees the inner transfer.

msig_approve now refuses unless the operator sets ENABLE_MSIG_APPROVE=true (default off,
documented in .env.example and the skill prompt). Test added; openclaw 215 pass.
@paulgnz
paulgnz merged commit 10389f3 into main Sep 24, 2026
7 checks passed
@paulgnz
paulgnz deleted the security/msig-approve-optin branch September 24, 2026 21:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant