If you're an institution considering onchain activity, make @l2beat a part of your risk assessment. That's where you learn about the hidden trust assumptions.
I think people are seriously misunderstanding the role of audits. To quote the article below:
"Resolv’s smart contracts had received multiple audits from well-regarded security firms, none of which identified the privileged key vulnerability prior to the exploit"
I have no






