Curriculum·G203 Reading Audit Reports·about 30 min

The centralization finding you cannot audit away

By the end of this lesson you can

  • Explain why a centralization finding describes a risk no code fix can remove, only a governance or custody change
  • State how Multichain's collapse showed one person holding every key was the real risk, not the code
  • Compute the single-point-of-failure count for a protocol from who holds keys, servers and infrastructure
  • Read an audit's centralization section as the description of a trust you are being asked to extend

Graduate · enrolled learners

This lesson opens with Multichain, July 2023.

What happened
Multichain was a cross-chain bridge. In July 2023 roughly 126 million dollars left its contracts to unknown addresses, and the team's own statement was that assets had moved abnormally and it did not know why. The cause was off-chain and structural: the chief executive, Zhaojun, had been detained by Chinese police in May, and every server, every node and every operational key ran under his personal cloud account, which was confiscated with his devices. Nobody else on the team could access the infrastructure, monitor the outflows, or stop them, because one person held everything. Multichain ceased operations. Whether the outflow was theft by whoever obtained the keys or a controlled action is still not fully established; what is established is that the protocol's entire operation depended on one individual.
The decision point
Multichain had been audited. No audit could have changed the fact that decided its fate: one person held all the keys, ran all the servers, and controlled all the operational funds. That is a centralization finding, and it is a different kind of finding from a code bug, because there is no line to fix. The only remedies are governance and custody: distribute the keys, separate the infrastructure, remove the single point. An audit can name the centralization, and a good one does, but it cannot remove it, and a user reading that section is not reading a bug that will be patched. They are reading a description of exactly whom, and how few, they must trust for the protocol to keep working.
Recorded loss
$126,000,000

What you will be able to answer

  • What caused the Multichain collapse?
  • Why can an audit not fix centralization?
  • What does a centralization section describe?
  • How do you count single points of failure?

Orientation and Year One are open: anyone can read them without an account. From Year Two onward the lessons are for enrolled learners, because progress through the later years only means anything if it is tracked against a record.

It is free. We do not sell the list and there is nothing to buy at the end of it.

Terms used here

Sources and review

Confidence high·Volatility medium·Reviewed 2026-09-14·Owner unassigned

Contested

Whether the roughly 126 million dollar outflow was theft by a third party who obtained the keys or a controlled movement is not fully established; the established fact, one-person control of all infrastructure, is what the lesson relies on.

The Multichain autopsy is also used in G705-03 for detection. Here it is used for the centralization finding an audit cannot remove. Both angles are drawn from the same documented facts.