EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

ENS DAO launches biennial veto committee after a $20 million BonkDAO attack

2026-07-22 00:11:08
Bookmark

ENS DAO activates a new security committee to block malicious governance proposals

Overview

ENS DAO approves the establishment of an eight-member committee that requires five members to sign before the malicious proposal is implemented.

The committee has the power to veto transactions that have been queued, but cannot use treasury funds or rewrite governance proposals. Its two-year term was established after multiple recent DAO governance attacks, including the theft of BonkDAO's $20 million treasury.

Committee Operating Mechanism

The committee will run for two years using a five-eighths multi-signature structure, which means that at least five members need to agree to block a transaction. This move provides the final security review of the two-day time-lock mechanism governed by ENS. Successful proposals will not be implemented immediately after the vote closes, but will enter a waiting period, giving the community time to review queued transactions and allowing the committee to intervene when the proposal meets certain emergency conditions. The term of office of the committee ends on July 16, 2028.

The new security committee has no authority to transfer funds from ENS DAO's treasury, create governance proposals, or change proposals that have been approved by token holders. It also cannot replace cancelled transactions with other actions. Its contract only allows members to cancel operations that are still pending within the governance time lock.

ENS described the committee as an "emergency brake" to deal with malicious proposals that have been voted on by the DAO but have not yet been implemented. The scope of its authorization covers attacks involving theft of governance certificates, fraud, vote bribery, lightning lending attacks and other attacks involving obtaining voting rights through abnormal market participation. Controversial policy decisions alone do not justify the committee's intervention.

Raise the threshold for intervention

The new structure raises the threshold needed for intervention. The outgoing safety committee uses a four-in-eight approval requirement, while the new team requires five signatures from its members to block proposals. Its authority will automatically expire after two years unless the ENS DAO approves an extension through another governance vote.

Members must also adhere to the public charter, sign an appointment agreement with the ENS Foundation, and complete identity and background checks. ENS said the framework includes a process for removing committee members who deliberately act beyond their authority.

BonkDAO attack brings renewed attention to governance security

ENS announced the committee shortly after BonkDAO suffered a major governance attack. BonkDAO reportedly said a malicious proposal stole approximately $20 million worth of BONK tokens from its treasury in July. The group then contacted law enforcement and began tracking the funds.

Subsequent analysis of the BonkDAO attack found that the DAO lacked multiple security measures now built into the ENS model, including timelocks and emergency multi-signature vetoes. In the BonkDAO case, the attacker gained enough voting power to pass a seemingly effective proposal, and the low participation rate made treasury vulnerable to governance capture.

ENS cited the BonkDAO event when explaining why governance itself could be a route to attack. It also mentioned the 2022 Beanstalk vulnerability, in which attackers temporarily gained enough voting rights through lightning loans and passed a proposal to transfer assets. The new ENS authorization specifically allows intervention when there is documentary evidence that the proposal was passed through the use of flash loans or similar vote manipulation.

ENS's approach does not prevent malicious proposals from entering the governance process or winning the vote. Instead, it creates a two-day window between approval and execution. If the proposal meets the emergency rules set out in the committee's charter, five committee members can take action within this window.

Tornado Cash attack shows malicious code can evade voting

ENS also pointed to the 2023 Tornado Cash governance takeover event as another type of threat. In this case, the attacker submitted a proposal that appeared legal at the time of review but changed behavior after approval. The attacker then gained control of the protocol governance system.

At the time, it was reported that the malicious proposal allowed attackers to control Tornado Cash's governance and be able to extract locked voting assets. The incident suggests that token holders may approve codes without detecting hidden behavior.

ENS said stronger delegation and voter participation mechanisms could make certain governance attacks more costly because attackers need greater voting power to control the outcome. However, these measures do not fully address issues such as certificate theft, coordinated token purchases, bribery, or proposals that contain malicious code. The safety committee added an independent review window after the vote closed.

This power remains limited to emergencies approved by the ENS DAO. Ordinary disputes over expenses, agreement direction, and organizational policies are still handled by token holders and representatives, even if committee members disagree with the outcome.

Eight members will take over until July 2028

The new committee members include ENS founders Nick Johnson, Hudson Jameson, Pablo Sabbatella, Colton Liberacki, Kevin Gaspar, Alex Van de Sande, Griff Green and Alex Netto. The ENS elected these members through ranking voting under Governance Proposal EP 6.50.

Candidates need to have a good track record in ENS governance or have professional experience in areas such as smart contract security, event response, governance design, and multi-signature operations. Subsequently, the DAO approved the on-chain proposal and granted the new security committee contract cancellation authority.

The cancellation authority of the outgoing committee will expire on July 24, and the new term will last until July 16, 2028. The ENS activated the replacement committee before old privileges expired to avoid the lack of emergency cancellation mechanisms for the DAO during the transition.

Under the approved structure, most governance proposals will continue to be voted on and implemented without committee involvement. The eight-member team will intervene in the process only if successful proposals are still within the two-day timeline and meet the established conditions for malicious or exploitative governance attacks.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP