If you're going to put a multisig in control of critical parts of your smart contract system, at least use it as intended: under the control of multiple independent parties (preferably all in different jurisdictions, with heterogeneous computing setups).
https://twitter.com/Mudit__Gupta/status/1425115177771405312…
yes the public can't confirm one way or the other, so they trust that the multisig signers are operating as promised/expected (fancy bonding protocols can be used to incentivize honesty but that was not the case here and not always applicable either).