h hoge.gg
Subscribe
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
● Security & Exploits

Who Guards the Guardians? DAO Security Councils in 2026

In 2026 DAOs bolted human circuit-breakers onto token voting. Marinade's council killed an attack in six hours; Onyx's timelock just ran out; ENS nearly tore itself apart over who holds the veto.

On 6 October 2026, the security firm Blockaid fired a real-time alert: roughly 620 million XCN tokens were leaving the treasury of Onyx, a Compound-style lending protocol on Ethereum, draining the contract down to about 1.89 million XCN. By the token’s price that day the haul was worth a few million dollars. What made the alert unusual was not a clever reentrancy trick or a leaked private key. The transfer moved through Onyx’s own front door. It cleared the proposal threshold, met quorum, and sat out the full two-day timelock before executing, exactly as the rules allowed (ChainCatcher).

To this day the Onyx episode is contested. The project said the movement simply executed a migration proposal it had publicly promoted, not a theft (KuCoin). Maybe that is true. But the ambiguity is the point. Whether the transfer was a planned migration or a hostile capture dressed up as one, nobody independent stood between the proposal and the money. The timelock ran its two days and nothing happened, because at Onyx a timelock is all there is. There was no one with both the authority and the attention to pull a brake.

That absence is the story of DAO security in 2026. After a summer in which governance attacks stopped being freak events and became a repeatable business, protocols reached for the one defense that seems to actually work: a human circuit-breaker. A small committee, usually a multisig, with the narrow power to cancel a malicious proposal while it waits in the timelock. The industry calls it a security council, a guardian, or an emergency veto. By October it had become the most important, and most contested, institution in on-chain governance. This piece is about that institution: where it came from, the two cases that defined it (one where the brake worked and one where it was never installed), and the uncomfortable question it forces. If a committee can override the vote, who guards the guardians?

Why the vote is the exploit

A governance attack does not break code. It uses the code as designed. In a token-voting DAO, control over the protocol is for sale: whoever assembles enough votes can pass a proposal, and a proposal can do anything the contracts allow, including sending the treasury to a new address. The venture firm a16z laid out the economics in a 2022 paper that still reads like a field manual. An attack is rational whenever the value it captures exceeds the cost of acquiring the votes plus the cost of execution (a16z crypto). Everything a defender does is an attempt to push one of those costs above the prize.

By 2026 attackers had turned that arithmetic into an assembly line. One takeover that summer, against a token called Token of Power, used a single passing vote to mint 10 billion new tokens in one transaction with no timelock standing in the way; another, against BarnBridge, needed only a few hundred dollars of governance tokens to seize an upgrade path (Blockaid). These were not elaborate hacks. They were cheap, repeatable, and increasingly templated, which is exactly why a static rulebook stopped being enough and why the industry started reaching for a human who could say no.

In 2026 the first term collapsed. Thinly traded governance tokens, long-abandoned DAOs whose treasuries still dwarfed their market caps, and flash loans that rent a majority for a single block all drove the cost of acquiring votes toward zero. Vitalik Buterin had warned why this was structural years earlier: a governance token bundles two very different things, an economic interest in the protocol and the right to steer it, and those two rights are, in his words, “very easy to unbundle.” An attacker who borrows the votes holds the steering wheel without owning the car, and feels nothing when the car goes off a cliff.

Once acquiring votes is cheap, the only lever left is the cost of execution: the friction between a passing vote and an irreversible transfer. That is where the security council lives. It does not try to make the vote honest. It assumes the vote can be captured and tries to buy time and a veto on the far side of it.

A timelock is a paywall, not a lock

The oldest piece of execution friction is the timelock: a mandatory delay between a proposal passing and its code running. The theory is that the delay gives honest holders time to notice and react. The problem is that a delay only helps if someone is watching and someone can act. Buterin put it bluntly: “timelocks are more like a paywall on a newspaper website than they are like a lock and key.” They slow you down; they do not stop you.

Term Finance proved the point in August. The DeFi lending protocol had done almost everything the textbooks recommend: a seven-day timelock, veto rights for liquidity providers, and a clean separation between the roles that manage the vaults and the roles that govern them. It still lost about $8.5 million, roughly 68% of the deposits in its vault product, after an attacker seeded a wallet with two ETH routed through Tornado Cash and bought up the thinly held governance token (The Block). The auditors at PeckShield and CertiK were clear that the code was fine: the attack “targeted the voting mechanics rather than any flaw in the underlying smart contract code.” Seven days of delay bought nothing, because the people entitled to veto never did.

A deterrent that never fires is a familiar problem in crypto security. Fraud proofs in optimistic systems, for instance, can sit unused for years while everyone assumes they work, a tension HOGE Wire has covered in the context of on-chain machine learning. A veto nobody is positioned to pull is the same kind of fiction. It looks like a defense on the governance page and behaves like a countdown in practice. The lesson DAOs took from Term was not “add a longer timelock.” It was “put a specific, empowered, awake party at the end of it.”

What a security council actually is

A security council is that awake party, formalized. In its cleanest form it is a multisig wallet, held by a named set of people, with exactly one meaningful power: to cancel a proposal that is sitting in the timelock. It cannot spend the treasury. It cannot write proposals of its own. It cannot rewrite a decision the token holders made. It can only stop a queued transaction before it executes, and only within the window the timelock provides.

The plumbing is standard. The widely used OpenZeppelin governance stack separates the Governor contract, which tallies votes, from a TimelockController, which actually holds the funds and enforces the delay, and it reserves a canceller role precisely so a guardian can kill a malicious action in flight (OpenZeppelin docs). OpenZeppelin warns that this role has to be scoped carefully, because the same keys that can cancel an attack can, if captured or abused, cancel everything. The council is a lock, and like any lock it is only as trustworthy as whoever holds the keys.

That is why the design is really a key-management problem wearing a governance costume. A 5-of-8 council is a 5-of-8 multisig, with all the questions that implies about signer independence, key custody, and collusion, the same questions that surround any shared-custody setup (our explainer on the cryptography under multisig and MPC wallets goes deeper). Choosing to have a guardian is easy. Choosing who it is, and how many of them must agree, is the hard part, and in 2026 it was where the fights happened.

Marinade: the six-hour veto

On 25 September, the brake worked exactly as intended, and almost nobody noticed, which is what success looks like. Marinade Finance, a leading liquid-staking protocol on Solana, found a bug in its Voter Stake Registry, the component that converts locked MNDE tokens into voting power. The flaw let an attacker assign artificially inflated voting power to a small amount of MNDE (KuCoin). With cheap votes in hand, the attacker filed two proposals: MIP-23, dressed up as a routine “security and maintenance” upgrade that would actually swap out the voting program, and a second proposal to move the DAO treasury.

Marinade’s DAO committee rejected both within six hours, roughly four days before they were scheduled to take effect (TokenPost). No funds moved. Staking, native staking, and the protocol’s other services were never touched. The honest voting power of MNDE holders, once the inflated votes were discounted, was decisively against the proposals anyway. Marinade patched the bug that night.

Set the two cases side by side and the difference is not the quality of the attack or the sophistication of the code. Onyx and Term had delays; Marinade had a delay and a standing body whose job was to watch the queue and act inside it. The timelock is the paywall. The council is the hand that reaches through it. One without the other is theater.

The guardian, in its many forms

Security councils are not new; the large Ethereum layer-2 networks pioneered them. What changed in 2026 is that they went from an L2 nicety to a survival tool for ordinary DeFi protocols. The models vary in who holds the veto and how tightly it is constrained. Arbitrum runs a twelve-member council elected by token holders (Arbitrum docs). Optimism splits power between a Token House and a reputation-based Citizens’ House. Compound’s long-standing Governor Bravo leans on a roughly two-day timelock but, like Onyx, has no empowered veto behind it. The table below maps the main shapes and how they fared when tested.

ModelWho holds the vetoWhat it can doWhat it cannot do2026 test
ENS Security Council8 members, 5-of-8 multisigCancel a queued proposal in the timelockMove treasury, write or rewrite proposalsRebuilt after a public fight
Marinade committeeDAO committeeReject malicious proposals pre-executionSpend treasury unilaterallyStopped an attack in 6 hours
Arbitrum12 elected membersEmergency actions, fast-track security fixesAct outside its charterNo major incident
OptimismBicameral houses plus councilVeto, remove sequencer powersBypass the two housesNo major incident
Compound Governor BravoNo standing guardianTimelock delay onlyCancel a passed vote in flightLegal-but-hostile capture risk
OnyxNo standing guardianTimelock delay onlyStop a cleared proposal620M XCN left the treasury

The ENS war over who holds the veto

If Marinade showed the guardian working, the Ethereum Name Service showed what happens when a community cannot agree on who the guardian should be. ENS, the protocol behind .eth names, had run a 4-of-8 security council with the standard narrow mandate: cancel malicious proposals in the timelock, nothing more. That council’s authority was set to expire on 24 July 2026, and the renewal became one of the ugliest governance episodes of the year.

The renewal passed the off-chain Snapshot poll, then failed the binding on-chain vote at 82% against. The reason was one person. Co-founder Nick Johnson, who controlled roughly 3.26 million ENS, about 80% of the votes cast in that executable and close to half of all delegated ENS, voted it down (The Block). He said he backed a council in principle but not that particular slate: “I abstained on the SC vote with a message explaining that I supported SC renewal but not with the current slate of members.” His view of what the body is for was sharper still: “The security council must exist as a backstop against compromise and violations of the ENS constitution, not as political officers.”

Not everyone saw a principled stand. Lefteris Karapetsas, founder of the portfolio tracker Rotki, reacted to one founder single-handedly overriding a community vote with four words: “And with that, ENS DAO is dead.” A community member went further and proposed dissolving the DAO altogether.

The resolution, in the end, hardened the guardian rather than killing it. A competing proposal, put forward by ENS Labs chief operating officer Katherine Wu and backed by Johnson, built a new eight-member council with a stricter 5-of-8 threshold, and on 20 July the DAO approved it, with a term running to 16 July 2028 (crypto.news). The new council can veto queued proposals aimed at “stolen governance credentials, fraud, vote buying, flash loans,” but explicitly cannot touch the treasury, author proposals, or wade into “controversial policy decisions.” ENS stated plainly that it had acted after watching BonkDAO lose $20 million in July for lack of exactly this kind of timelock-and-veto safeguard. The final irony: Johnson, the man who vetoed the old council’s renewal, sits on the new one.

Who guards the guardians?

The ENS fight exposed the paradox at the center of every security council. The body exists to stop a small group from seizing the protocol. Yet a 5-of-8 council is itself a small group that can seize a specific power, the power to veto. Johnson’s block made the abstraction concrete: when one holder commands half the delegated votes, the de facto guardian is already a single person, council or no council. The committee did not create that concentration; it just dragged it into the open.

From an attacker’s point of view, the council is simply a new target with a smaller attack surface. Why buy 51% of a liquid token when you can compromise five keys? The guardian does not remove the single point of failure; it relocates it from “anyone with enough money” to “whoever controls the multisig,” and trusts that a named, reputationally exposed, geographically scattered set of signers is harder to corrupt than an open token market. That is usually a good trade. It is not a free one.

Johnson’s own line is the whole debate in one sentence: the council should be a “backstop,” not a set of political officers. A guardian strong enough to stop a theft is strong enough to overrule a legitimate decision it dislikes, and the line between a malicious proposal and a merely unpopular one is exactly where discretion creeps in. Every DAO that installs a veto has to answer the same question the ENS community answered in public and at volume: powerful enough to save us, constrained enough not to rule us, and held by people we can actually name. Get any of the three wrong and the cure becomes the disease.

There are ways to make the trade less dangerous, and ENS reached for most of them. Its signers are public, named individuals rather than anonymous wallets. The council sits on a fixed two-year term that lapses on its own, so keeping it is a scheduled decision rather than a permanent grant. Token holders chose the slate by vote and get another say when that term expires. And the mandate is written down: cancel malicious or coercive proposals, stay out of policy. None of this dissolves the paradox, but it converts a vague, open-ended power into a bounded, accountable one, which is about the best a DAO can do short of having no guardian at all.

Can the brake itself be gamed?

Installing a guardian does not end the game; it changes the board. A council introduces its own failure modes, and a serious attacker will probe them. The first is the quiet one Term Finance demonstrated: the veto exists but nobody pulls it. A right to cancel that depends on volunteers happening to be awake, reachable, and paying attention during a holiday weekend is not a control, it is a hope. Marinade’s committee worked because acting on an alert was someone’s defined job, not a civic virtue.

The second failure mode is the signers themselves. A 5-of-8 multisig falls if five keys fall, and keys fall to stolen devices, social engineering, or a planted insider, the same threats that haunt every shared-custody setup. A council is only as strong as its weakest few signers and the operational security around them, which is why who sits on it matters as much as how many must agree.

The third is the most insidious: a proposal engineered to look harmless so the guardians wave it through. A single innocuous-sounding upgrade, like Marinade’s “security and maintenance” proposal that actually swapped out the voting program, can slip past signers who read the title and not the calldata. The veto only protects a DAO if the people holding it verify what a queued transaction really does, every time, which is a demanding standard to sustain across years in which almost nothing happens.

Detection is not response

2026 also gave DAOs something they lacked in earlier years: an early-warning system. On-chain monitors now watch governance contracts the way intrusion detection watches a network. Decurity’s Defimon bot flagged the Term Finance attack and several others in flight; Blockaid says it caught one takeover in real time by spotting a sudden concentration of votes paired with a suspicious payload (Blockaid). Across roughly seven takeovers between 9 June and 6 August, Blockaid tallied about $22 million drained, and the alerts often went out well before execution.

The hard lesson of the year is that an alert is not a defense. A monitor can scream that a malicious proposal is sitting in the timelock, but if no one has the authority to cancel it, the scream changes nothing; it just documents the loss in advance. Onyx had, in effect, a smoke alarm and no fire brigade. Marinade had both: detection plus a committee with the power to act on it inside the window. The pipeline only works end to end.

When a protocol has no guardian of its own, the brake sometimes comes from outside. In August, Binance said its security team spotted a malicious proposal targeting a roughly $1.2 million DAO treasury and coordinated with other exchanges to freeze the attacker’s deposits, killing the attack less than 48 hours before it would have executed (crypto.news). Binance named no project and the claim cannot be independently verified, but the shape is telling: when the DAO has no circuit-breaker, a centralized exchange can end up playing one. That is a strange outcome for a movement built to route around exactly that kind of intermediary.

Did the brake hold? A 2026 scoreboard

The year produced a natural experiment. Several protocols faced the same class of attack with different defenses in place, and the outcomes line up almost perfectly with whether a specific, empowered party could act inside the timelock. The pattern is not subtle.

IncidentDateDelay in placeEmpowered veto?Outcome
BonkDAOJul 2026No meaningful quorum or timelockNoAbout $20M drained
Term FinanceAug 20267-day timelock plus LP veto rightsIn theory, unusedAbout $8.5M drained
Binance near-missAug 2026Low proposal thresholdExternal (exchange)~$1.2M saved, per Binance
MarinadeSep 2026Timelock plus DAO committeeYesStopped in 6 hours, no loss
ENSJul 2026Timelock plus security councilYes, after a fightGuardian rebuilt, no loss
OnyxOct 20262-day timelockNo620M XCN moved, intent disputed

Read down the “empowered veto” column and the losses sort themselves. Where a named party could reach into the timelock and cancel, the treasury survived. Where the only defense was time, the time simply elapsed. The scoreboard is the argument for the security council, stated more plainly than any whitepaper could.

The centralization bill comes due

The security council does not stand alone. It is one line item in a larger bill that DeFi started paying in 2026: the cost of admitting that pure, leaderless, token-weighted governance did not survive contact with attackers. The retreat took several forms. ENS moved roughly $65 million of endowment under a foundation with real-world legal standing (The Block). Aave re-centralized around its core development company by attrition as its service providers walked. Uniswap wrapped its DAO in a Wyoming legal entity. A school of thought a16z calls governance minimization argues protocols should simply have less to vote on; Liquity went furthest, shipping a system with, in its own framing, no human governance at all (a16z crypto).

Seen that way, the guardian is the honest version of a truth the numbers already told. Chainalysis found that in major DAOs, fewer than 1% of holders typically control around 90% of the voting power (Cointelegraph), and research compiled by CryptoSlate this year put concentration like Convex holding roughly 53% of Curve’s votes and Aura around 65% of Balancer’s in the same frame (CryptoSlate). The vote was never as distributed as the branding implied. A security council does not add centralization so much as it names it, assigns it to specific people, and bounds what they are allowed to do with it.

Some of the people who built this field have made peace with that. Ali Yahya, a general partner at a16z, summarized the decade with unusual candor: “We spent the last 10 years rediscovering the hard way that direct democracy is a bad idea.” The security council is what that rediscovery looks like in Solidity.

Is pulling the brake even legal, and who is liable?

Handing a small committee the power to override a vote raises a question most DAOs would rather not think about: what is the legal status of the people holding the keys? In the United States there is no dedicated DAO regulator. The SEC and the CFTC reach protocols through securities and commodities law, and the courts have started to fill the gap. In the CFTC’s case against Ooki DAO, a federal court held that a DAO could be treated as an unincorporated association and a “person” under the law, and entered a $643,542 judgment against it (CFTC). If a DAO is an unincorporated association, its active participants, including the members of a security council, can in principle carry personal liability for what the organization does.

The attacker’s side of the ledger is no clearer. Avraham Eisenberg was convicted over the 2022 Mango Markets exploit, which combined market manipulation with a governance proposal, and then watched a judge vacate those convictions in 2025, partly on the logic that the trades executed exactly as the permissionless code allowed (CoinDesk). When the system does what it was programmed to do, prosecutors struggle to locate the crime. That uncertainty cuts both ways: it is why some captures are called attacks and others, like Compound’s “Golden Boys” proposal in 2024, are called aggressive but legal governance, and it is why a council that vetoes a technically valid proposal is standing on contested ground.

Europe has gone further toward naming CASPs and issuers under MiCA, though even there the rulebook targets service providers and token issuers rather than the governance design of a protocol with no company behind it, a gap our guide to MiCA walks through. For now, the guardian’s authority is a social and technical fact well ahead of its legal one. The multisig can cancel the transaction. Whether it should, and who answers for it afterward, is unsettled.

How to read a DAO’s emergency brake

For anyone holding a governance token or parking funds in a DAO-run protocol, the security council is now something to check as deliberately as you would check an audit. What a treasury holds, from stablecoins to staked ETH earning a validator yield, is only as safe as the weakest path to moving it. A short checklist before you trust a DAO with your money:

  • Is there a standing security council or guardian at all, or is a bare timelock the only thing between a vote and the treasury? A delay with no one behind it is a countdown, not a defense.
  • What exactly can the council do? The safe shape is cancel-only: it can stop a queued proposal but cannot spend the treasury or write proposals of its own.
  • What is the threshold, and who are the signers? A 5-of-8 of named, independent people is a very different risk from a 2-of-3 of pseudonyms or a team-controlled wallet.
  • Is the timelock long enough for a human to actually react? A two-day window is workable; a few hours is not.
  • Is monitoring wired to the veto? An alert from Blockaid or Defimon only helps if a signer who can cancel is watching the same channel.
  • Can any single holder override the council, as at ENS? If one wallet controls a near-majority of votes, the real guardian is that wallet, whatever the org chart says.

None of this makes a protocol safe. It tells you whether the protocol has honestly priced the risk that its own vote can be turned against it, and whether, when the alert fires, there is a hand positioned to pull the brake.

Frequently Asked Questions

What is a DAO security council?

A DAO security council is a small, named group, usually a multisig wallet, with the narrow power to cancel a malicious proposal while it waits in a governance timelock. It cannot spend the treasury or write its own proposals; it exists only as an emergency brake against a captured vote. ENS, Arbitrum, and Optimism all run versions of one.

Was the Onyx DAO treasury hacked in October 2026?

It is disputed. On 6 October 2026, about 620 million XCN left the Onyx treasury after a proposal cleared the protocol’s two-day timelock, and Blockaid flagged it as a possible exploit. Onyx said the transfer executed a migration it had previously announced, not a theft. Either way, no independent guardian stood between the proposal and the funds, which is the structural point.

How did Marinade Finance stop its governance attack?

On 25 September 2026, an attacker used a bug in Marinade’s Voter Stake Registry to inflate voting power and filed two malicious proposals. Marinade’s DAO committee rejected both within six hours, roughly four days before they could execute, and no funds were lost. It is the clearest example of a security council working as designed.

Can a timelock alone stop a governance attack?

No. A timelock only delays execution; it does not cancel anything. As Vitalik Buterin put it, a timelock is more like a paywall than a lock and key. Term Finance had a seven-day timelock and still lost about $8.5 million because no one exercised the veto before the delay ran out. A delay only helps if a specific, empowered party is watching and able to act within it.

Does a security council make a DAO centralized?

To a degree, yes, and that is the central trade-off. A council concentrates a specific power, the veto, in a small group, which becomes a new target and a point of control. Supporters argue the concentration was always there (fewer than 1% of holders usually control around 90% of votes) and that a council at least names it and limits it. The ENS fight of 2026 showed how hard it is to get that balance right.

Anneke de Vries is HOGE Wire’s security and exploits correspondent, covering DeFi governance, smart-contract risk, and on-chain forensics.

Share 𝕏 Post Telegram