Kerckhoffs, 1883: a cryptosystem should be secure, even if everything about the system, except the key, is public knowledge.
Most protocol hacks are not clever exploits of audited code. They are ops failures. Leaked keys. Upgrades with no delay. Timelocks nobody monitors. One EOA holding admin.
So at
@roycoprotocol , we published the whole thing:
Every role and who holds it. Every multisig, its live signer set and threshold. Every execution delay. Every pending operation, decoded, while it sits in its 72h window. All chains, rendered live - directly from chain state.
Admin paths are multisig only. Core changes wait 72 hours in public, under guardian review and automated monitoring, and can be cancelled at any point before execution. Changing a role, a delay, or a guardian goes through the same pipeline.
Assume the adversary has this page bookmarked. We did.p