Breaking
ITSerie A: Roma beat Atalanta 2-1, Inter comeback and win 3-2 against Napoli, Turin wins in FlorenceFRTop 14 2026-2027: Stade Français wins with difficulty against Perpignan, Lyon dominates ClermontINPM Modi travels by Delhi Metro to attend SRCC centenary celebrationsARAlgerian authorities recover the body of a child who fell into a well in the state of El Bayadh after 4 days of searchingUSMichael Carrick's Manchester United Faces Early Season Tests Against Everton and Champions League DebutDEElversberg sensationally wins 4:3 against Borussia MönchengladbachRUTwo senior officers of the Armed Forces of Ukraine were eliminated as a result of missile attacks in the Kharkov and Poltava regionsSAUAE Lottery Lucky Day Draw No. 260905 Awards Cash Prizes, Jackpot Rolls OverARThe United States and Iran are exchanging blows in the Gulf as tensions rise and warnings of the conflict expandingAR100 dead were buried in Gaza, most of them children and women, after they were recovered from under the rubbleITSerie A: Roma beat Atalanta 2-1, Inter comeback and win 3-2 against Napoli, Turin wins in FlorenceFRTop 14 2026-2027: Stade Français wins with difficulty against Perpignan, Lyon dominates ClermontINPM Modi travels by Delhi Metro to attend SRCC centenary celebrationsARAlgerian authorities recover the body of a child who fell into a well in the state of El Bayadh after 4 days of searchingUSMichael Carrick's Manchester United Faces Early Season Tests Against Everton and Champions League DebutDEElversberg sensationally wins 4:3 against Borussia MönchengladbachRUTwo senior officers of the Armed Forces of Ukraine were eliminated as a result of missile attacks in the Kharkov and Poltava regionsSAUAE Lottery Lucky Day Draw No. 260905 Awards Cash Prizes, Jackpot Rolls OverARThe United States and Iran are exchanging blows in the Gulf as tensions rise and warnings of the conflict expandingAR100 dead were buried in Gaza, most of them children and women, after they were recovered from under the rubble
BackHow DAO Governance Rules Can Enable Treasury Raids Despite Flawless Code Execution
How DAO Governance Rules Can Enable Treasury Raids Despite Flawless Code Execution
Developing
CryptoSlate2 hours agoTech2 min read

How DAO Governance Rules Can Enable Treasury Raids Despite Flawless Code Execution

Quick Look

  • In July 2024, Compound DAO narrowly passed a controversial proposal to transfer $24 million in COMP tokens to a small group of voters during a last-minute voting surge, exposing how governance mechanisms like registration, staking, and delegation can concentrate power and enable treasury raids even when code functions as intended.
  • Research from Max Planck Institute and Vrije Universiteit Amsterdam found similar vulnerabilities across 48 major Ethereum DAOs, where voting power is often controlled by a small number of large holders, exchanges, and delegation services, undermining broad participation despite thousands of token holders.

AI-generated summary

Why It Matters

Compound is a crypto lending protocol governed by COMP token holders who delegate voting power through a DAO structure. In July 2024, Proposal 289 sought to allocate 499,000 COMP (~$24 million) to a yield-bearing vehicle controlled by a small group, which passed after a last-minute voting surge despite two prior failures.

Font size

Compound is a crypto lending protocol governed by holders who delegate their COMP tokens, a setup known as a decentralized autonomous organization, or DAO. It works like an online republic, with token holders debating proposals, voting, and letting software carry out the result.

In July 2024, that republic nearly sent a fortune to a small group of voters. Proposal 289 asked Compound to transfer 499,000 COMP, then worth about $24 million, into a yield-bearing vehicle they controlled. Two earlier versions had failed, and the third seemed headed the same way.

Then, during the final 34 minutes, supporting addresses cast 563,591 votes, equal to 82% of all support for the proposal. The last big block landed eight minutes before the deadline, and the measure passed by 682,191 votes to 633,636.

While this was extremely controversial and remains highly contested, there was no issue with the code, as it worked exactly as intended.

But that was the problem: the wallets had gathered enough COMP and delegated their voting power before the period closed, but Compound lacked an emergency authority that could pause the software. Several reasonable rules had combined into a convenient path for a treasury raid.

Compound reached a settlement that canceled the allocation and later added a veto role, placing a brake in the system built around automatic token-holder rule.

That captures the central DAO dilemma, because most defenses against rushed or hostile votes give somebody more control over participation or the final result.

Two 2026 studies from the Max Planck Institute for Software Systems and Vrije Universiteit Amsterdam traced a similar problem across 48 large Ethereum DAOs. One examined how registration, staking, and delegation concentrate voting power, while the other mapped attacks that use valid governance rules.

The ballot has a velvet rope

Calling a governance token a vote isn't really correct. Depending on the DAO, a holder may need to register a wallet, lock tokens, delegate them, maintain a minimum balance, or pay for an on-chain transaction before they can actually cast that vote.

Proposals face obstacles of their own, because someone needs enough tokens or delegated support to introduce them in the first place, and the idea may pass through a forum and informal poll before a binding vote on the blockchain or through an off-chain service such as Snapshot.

Once the tally clears the quorum and approval formula, a smart contract, multisignature wallet, or named person carries the result into effect.

While each of these gates solves a real problem, it also favors a particular participant or type of participant.

Proposal thresholds discourage spam and malicious code, but they inadvertently reserve authorship for wealthy holders and established delegates. On-chain voting makes those results enforceable, but transaction fees favor people with enough money and conviction to use it. Free off-chain polls draw a wider crowd, then depend on a smaller group for execution.

The researchers found an even split: 24 DAOs used on-chain voting and 24 used off-chain systems.

Uniswap showed how different electorates can form inside the same organization: more wallets joined its free off-chain polls, while much larger blocks of voting power appeared during the paid on-chain phase that could make a proposal binding.

Turnout is only one small part of this, because a protocol may have thousands of token holders while a few addresses control proposals, votes, and execution. By the time the public tally appears, the rules have already picked the electorate.

The security rules pick the ruling class

DAOs often keep tokens in treasury contracts, and founding teams or investors may hold allocations that have yet to vest, so registration separates circulating tokens from balances that currently carry voting rights.

Among the 48 DAOs, 36 required some form of registration, and only four had registered more than half of their outstanding supply. Across those 36 organizations, the average registered share was 21%, meaning the practical electorate usually covered a small fraction of all tokens.

Much of the missing supply belonged to users whose coins were held by exchanges or deposited into DeFi protocols. Centralized exchanges held more than 10% of outstanding tokens on average across the sample, and DeFi contracts held another 3.5%.

In 14 registration-based DAOs, those intermediary wallets controlled more tokens than the entire registered electorate.

That creates a very strange and rather unique custody problem, because an exchange wallet can represent thousands of customers even though the blockchain sees one address with one giant balance.

Letting the exchange vote turns a custodian into a political heavyweight, while excluding it strips customers of governance rights attached to tokens they paid for. Most DAOs also let one wallet send all its power to a single delegate, which makes splitting votes among the underlying owners difficult.

Staking tackles a different vulnerability by making voting power expensive to build and slow to unwind. A would-be attacker can buy or borrow a large position, approve a favorable proposal, and sell once the vote ends, while a lock keeps that voter financially exposed to the result for longer.

Fifteen DAOs required staking, with a median of 27.4% of tokens locked. Some imposed a one- or two-week withdrawal wait, while Curve, Angle, and Frax offered stronger voting power for locks lasting up to four years. The system rewards patience and turns liquid wealth into a prerequisite for political influence.

Crypto soon produced middlemen for people who wanted influence and the freedom to trade. These services maintain long locks, issue tradable substitutes, and keep the original voting rights. The arrangement concentrated enormous voting blocs inside a few services, according to the researchers’ measurements:

Delegation works the same because most holders have limited appetite for forum arguments about collateral ratios. Handing votes to a professional participant makes sense, and repeated delegation builds durable political blocs.

The ten largest holders controlled more than half of voting power in 39 of the 48 DAOs, while delegated voting was usually more concentrated than direct voting.

Registration protects treasury balances, staking makes a quick attack costlier, and delegation gives passive holders a voice through someone who pays attention. Put them together, and the people with the most capital, time, technical fluency, or control over customer assets tend to run the place.

A legal DAO vote can still be a raid

The second paper defines a governance attack as an actor using the authorized process to win an outcome that harms the wider organization.

Among 28 DAO incidents, researchers classified 16 as attacks that a different mechanism could have prevented. Six involved contract bugs, while ten depended on buying or borrowing enough tokens to influence a vote.

Compound is the best example because the wallets associated with Proposal 289 gathered more than 680,000 COMP over four months.

Researchers traced 563,790 tokens through four centralized exchanges and another 118,089 borrowed through Compound itself, even though those addresses had held only 853 COMP before the buildup and had little history in the protocol's politics.

The late burst took advantage of a community that expected the third proposal to fail. Compound could have extended the vote when a large bloc appeared near the deadline, required longer staking, or allowed a trusted council to pause execution.

Every option would have moved power toward reactive voters, committed holders, locking services, or a small emergency body.

But Compound chose the emergency brake, and in the 2024 configurations researchers reviewed, seven other DAOs shared its exposure to readily available voting power and late vote accumulation: Uniswap, Radicle, Gitcoin, Silo, Ampleforth, Hop, and Cryptex.

Those systems can evolve through governance, so the list records a moment in 2024, while a current security rating would require a fresh review.

Decentralization needs a richer accounting than token distribution alone. A good governance report would show how much supply can vote, how much power the largest delegates control, which intermediaries hold staked tokens, and who can introduce, execute, or veto proposals.

Smart contract audits already ask whether governance code follows its specification, while a constitutional audit would ask where that specification sends authority.

DAOs can spread ownership across thousands of wallets and still funnel practical control toward a few dozen professionals, custodians, and large holders, with software that performs flawlessly all the way through.

What to Watch

AI outlook — possibilities, not facts

  • More Ethereum DAOs will adopt emergency pause or veto mechanisms following the Compound incident and related research

    Likely · Within months

  • Regulatory scrutiny of DAO governance models will increase due to concerns about voter concentration and potential for treasury raids

    Possible · Within months

Open Questions

  • Did the beneficiaries of Proposal 289 return the funds after the settlement?
  • How many of the 48 studied DAOs have implemented emergency pause mechanisms since the 2024 research?
  • What specific changes did Compound implement beyond adding a veto role to prevent recurrence?

Related Topics

This article was originally published by CryptoSlate.

Related Stories

Trezor says logistics vendor ShipMonk breach exposed data for 67,000 additional U.S. customers
Developing·

Trezor says logistics vendor ShipMonk breach exposed data for 67,000 additional U.S. customers

Trezor disclosed that a breach at logistics provider ShipMonk exposed contact and order data for approximately 67,000 additional U.S. customers, expanding the initial incident from 13,689 to a total of roughly 80,689 potentially affected individuals. The exposed data includes names, emails, phone numbers, shipping addresses, and order numbers from November 2019 to August 2021, despite Trezor's 90-day data deletion policy and written assurances from ShipMonk. The breach did not compromise Trezor's wallet systems or private keys, but poses risks of phishing, fraud, and physical targeting.

CryptoSlate
2 min read
Robinhood Chain Launches as Layer-2 Network for Tokenized Assets and DeFi
Developing·

Robinhood Chain Launches as Layer-2 Network for Tokenized Assets and DeFi

Robinhood Chain, a layer-2 blockchain built on Ethereum via Arbitrum Dedicated Blockchains, launched on mainnet July 1, 2026, enabling tokenized stocks, ETFs, and DeFi applications. It uses ETH as gas, supports EVM compatibility, and has seen rapid growth in transactions, DEX volume, and fees, with notable activity from meme coins like Cash Cat and Pons, and tokenized assets reaching $219.49 million in market cap by September 4, 2026.

Decrypt
3 min read
Solana's rent reduction lowers SOL reserve requirements for token accounts
Developing·

Solana's rent reduction lowers SOL reserve requirements for token accounts

Solana's first rent reduction, live since September 3, lowers the SOL required to maintain token accounts, allowing excess SOL to be reclaimed. A full 90% reduction would enable tenfold account growth for the same reserve requirement, though only the initial step is active on mainnet. The change reduces upfront capital for new accounts and lets existing account holders withdraw surplus SOL via authorized transactions.

CryptoSlate
2 min read
Google patches high-severity Chrome flaw actively exploited in the wild
BREAKING·

Google patches high-severity Chrome flaw actively exploited in the wild

Google has patched a high-severity Chrome vulnerability (CVE-2026-85046) after discovering attackers were already exploiting it. The type-confusion flaw in the V8 JavaScript engine affects Windows, Mac, and Linux versions. Google awarded a $1,000 bug bounty to researcher Salvatore Gulizia for reporting the issue on August 4, 2025, but has not identified attackers, victims, or the exploit's capabilities.

Decrypt
1 min read
More on this topiccompound