Loading prices…
🩸BEARISH

Compound’s $24M Vote Exposes DAO Governance Risk

Research across 48 large Ethereum DAOs found that registration, staking, and delegation can narrow the practical electorate while leaving protocols exposed to legally valid governance attacks.

Compound’s Proposal 289 passed after a late burst of support sent 682,191 votes against 633,636, authorizing the transfer of 499,000 COMP, then worth about $24 million, to a yield-bearing vehicle. Wallets behind the campaign had accumulated more than 682,000 COMP over four months, including tokens traced through centralized exchanges and COMP borrowed through Compound itself. The measure was later canceled through a settlement, and Compound added a veto role that gave the protocol an emergency brake.

Why it matters

The incident shows that a DAO can execute a treasury raid without exploiting a smart-contract bug. Researchers studying 28 DAO incidents classified 16 as attacks, including ten involving the purchase or borrowing of enough tokens to influence a vote. Registration, staking, and delegation are intended to prevent spam, make attacks more expensive, and give passive holders representation, but each can also concentrate practical authority.

Across 48 large Ethereum DAOs, 36 required some form of registration, yet only four registered more than half of their outstanding token supply. The average registered share was 21% among those 36 organizations. Fifteen DAOs required staking, with a median 27.4% of tokens locked, while delegation made voting power even more concentrated than direct voting in many cases.

The ten largest holders controlled more than half of voting power in 39 of the 48 DAOs. In 14 registration-based DAOs, exchange and DeFi intermediary wallets controlled more tokens than the entire registered electorate. Researchers also found that voting blocs associated with governance services could reach 53% of voting power in Curve, 46% in Frax, 57% in Angle, and 65% in Balancer.

Market impact

Protocols now face a design trade-off rather than a simple choice between decentralization and control. Extending voting periods, requiring longer staking, or giving a council veto authority can reduce late-stage attacks, but it also shifts influence toward committed holders, professional delegates, locking services, or a small emergency body. The researchers identified seven other DAOs with similar exposure to readily available voting power and late accumulation, including Uniswap, Radicle, Gitcoin, Silo, Ampleforth, Hop, and Cryptex.

The security question is therefore changing from whether governance code follows its rules to whom those rules distribute authority.

Related tokens
$COMP

Frequently asked questions

  1. What happened with Compound Proposal 289?

    The proposal passed after a late burst of support and authorized the transfer of 499,000 COMP worth about $24 million. A later settlement canceled the allocation, and Compound added a veto role.

  2. Why was the Compound vote considered a governance attack?

    The transaction followed Compound’s authorized governance process, but the voting campaign accumulated more than 682,000 COMP, including borrowed tokens. That concentration created the risk of a legally valid but economically harmful treasury decision.

  3. How concentrated was voting across the DAOs studied?

    The ten largest holders controlled more than half of voting power in 39 of the 48 DAOs. Delegated voting was usually more concentrated than direct voting, increasing the influence of a smaller group of professional participants.

  4. What did registration and staking reveal about DAO participation?

    Among 36 DAOs that required registration, only four registered more than half of outstanding supply, and the average registered share was 21%. Fifteen DAOs required staking, with a median 27.4% of tokens locked.

  5. What should investors monitor in DAO governance?

    Investors should track registered supply, delegate concentration, intermediary wallets, proposal thresholds, execution rights, and emergency veto powers. Token distribution alone does not show who can introduce, approve, or block a proposal.

Source attribution
Aggregated from CryptoSlate · Verified · Last refreshed 1h ago
Open original →