Vitalik posted on X that the ideal security rule for multisig is for each signer to change keys after every operation. According to Odaily, he said this assumes ECDSA may become insecure but will not be broken immediately, so protection against mempool front-running is still needed. Vitalik added that, if possible, signatures should still be collected offline to shorten the time between signature disclosure and key invalidation, and warned that misconfigured or rushed upgrades can easily lead to fund losses.