Decentralized autonomous organizations push cryptocurrency protocols to choose between unchangeable code and the ability to halt operations for safety reasons
Decentralized autonomous organizations face an inescapable tradeoff between code immutability and emergency safeguards, as research into Ethereum DAOs reveals how valid governance rules can be weaponized to concentrate power. For investors and protocol participants, understanding where voting power actually sits, as opposed to where it theoretically exists, has become essential to assessing DAO security and legitimacy.
- Compound’s Proposal 289 passed with 563,591 votes cast in the final 34 minutes of voting, worth approximately $24 million in COMP tokens at the time.
- Among 36 DAOs requiring registration, only four had registered more than half of their token supply; average registration was 21% of tokens.
- The ten largest holders controlled more than half of voting power in 39 of 48 Ethereum DAOs examined, with concentrated power often exceeding the practical electorate.
- $24M COMP tokens at stake in Proposal 289, the governance crisis that exposed Compound’s vulnerability
- 21% Average registration rate across DAOs requiring it, versus total token supply
- 53% Voting power controlled by Convex over Curve, demonstrating intermediary concentration
- 39 of 48 DAOs where ten largest holders held majority voting power
Compound, a major cryptocurrency lending protocol governed by token holders through a decentralized autonomous organization, experienced a significant governance crisis in July 2024 that exposed fundamental flaws in how these systems distribute power. The incident centered on Proposal 289, which sought to transfer 499,000 COMP tokens into a yield-bearing vehicle controlled by a small group of voters. Two earlier versions had already failed when, in the final 34 minutes of voting, supporting addresses suddenly cast 563,591 votes representing 82% of all votes in favor, with a large final block arriving just eight minutes before the deadline closed. The proposal passed 682,191 to 633,636, allowing the transfer to proceed despite signs of manipulation.
Compound’s Proposal 289 Exposed the Absence of Emergency Brakes
While Compound’s governance code functioned exactly as designed, this precise functioning revealed a critical problem: the system lacked an emergency mechanism to pause execution when suspicious voting patterns emerged. The protocol had no safeguard to halt a potential treasury raid that used valid governance rules. Researchers who later examined the incident traced the wallets involved and found they had accumulated more than 680,000 COMP over four months, with 563,790 tokens acquired through four centralized exchanges and another 118,089 borrowed through Compound itself. Before this campaign, the addresses held only 853 COMP and had minimal governance history.
Compound ultimately canceled the allocation and later implemented a veto role to add safeguards to its governance system.
However, this solution created a new problem: any defense against rushed or hostile votes typically requires giving someone more control over participation or the final outcome. This tradeoff between immutability and emergency powers now defines a core tension across decentralized finance governance.
Research Across 48 Ethereum DAOs Reveals Structural Vulnerabilities
Two 2024 studies from the Max Planck Institute for Software Systems and Vrije Universiteit Amsterdam examined 48 large Ethereum DAOs and found similar structural vulnerabilities extending far beyond Compound. One study traced how registration, staking, and delegation mechanisms concentrate voting power, while another mapped attacks that exploit valid governance rules. The research revealed that multiple reasonable security features, when combined, can inadvertently create pathways for hostile actors to gain control. Researchers classified 16 of 28 DAO incidents as attacks that different mechanisms could have prevented, with six involving smart contract bugs and ten depending on buying or borrowing enough tokens to influence votes.
Beyond Compound, seven other DAOs showed similar vulnerability to readily available voting power and late vote accumulation: Uniswap, Radicle, Gitcoin, Silo, Ampleforth, Hop, and Cryptex. The pattern suggests that accumulating tokens through exchanges and flash-borrowing mechanisms represents a repeatable attack vector across multiple protocols.
Registration Requirements Lock Out Most Token Holders from Actual Voting
Calling a governance token a vote oversimplifies how DAO participation actually works. Depending on the specific DAO’s design, a token holder may need to register a wallet, lock tokens, delegate them to another address, maintain a minimum balance, or pay transaction fees before they can cast a vote. Among the 48 DAOs examined, 36 required some form of registration before tokens could vote. Of those 36, only four had registered more than half of their outstanding token supply, with an average registered share of just 21% of total tokens across registration-based DAOs.
This gap reflects custody arrangements that fragment the electorate. Centralized exchanges held more than 10% of outstanding tokens on average across the sample, while DeFi contracts held another 3.5%. In 14 registration-based DAOs, exchange wallets and DeFi contracts combined controlled more tokens than the entire registered electorate. This created an unusual custody problem: allowing exchange wallets to vote converts custodians into political heavyweights, yet excluding them strips customers of governance rights attached to tokens they own.
Staking and Locking Services Created New Classes of Voting Intermediaries
Many DAOs implement staking requirements to make voting power expensive to acquire and slow to withdraw. Fifteen of the 48 DAOs required staking, with a median of 27.4% of tokens locked. Some imposed withdrawal delays of one to two weeks, while Curve, Angle, and Frax offered stronger voting power for locks lasting up to four years. This system makes attacks slower and more expensive, but it opened the door to a new class of intermediaries.
Crypto services emerged to let people maintain long locks while retaining trading freedom by holding the original tokens, issuing tradable substitutes, and keeping the voting rights. The arrangement concentrated enormous voting power in single entities. Convex controlled 53% of voting power for Curve and 46% for Frax, both with maximum native locks of four years. StakeDAO controlled 57% of Angle’s voting power, also locked for four years. Aura controlled 65% of Balancer’s voting power, though with a one-year maximum lock.
Delegation Amplifies Concentration Among Professional Governance Participants
Handing votes to a professional participant who tracks proposals makes practical sense, and repeated delegation builds durable political blocs. The concentration effect proves substantial: the ten largest holders controlled more than half of voting power in 39 of the 48 DAOs studied. Delegated voting was typically more concentrated than direct voting, and when registration, staking, and delegation rules combine, the people with the most capital, time, technical knowledge, or control over customer assets tend to dominate governance.
The 48 DAOs examined showed an even split between on-chain and off-chain voting: 24 used on-chain voting and 24 relied on off-chain systems. Uniswap demonstrated how different electorates can emerge within the same organization, with more wallets participating in free off-chain polls while larger voting power blocs appeared during paid on-chain voting. Despite DAOs’ decentralization goals, practical control often concentrates among a few dozen professionals, custodians, and large holders.
A New Framework for Measuring Actual Decentralization Is Needed
Decentralization requires richer analysis than token distribution alone. A comprehensive governance report would reveal how much supply can actually vote, how much power the largest delegates control, which intermediaries hold staked tokens, and who possesses authority to introduce, execute, or veto proposals. Smart contract audits already verify whether governance code follows its specification, but a constitutional audit would go further by examining where that specification ultimately sends authority in practice.
DAOs can spread ownership across thousands of wallets while still funneling practical control toward a concentrated group, with software that executes flawlessly throughout the process. The open question facing the industry is whether the governance token model itself can be reformed to align theoretical decentralization with practical control, or whether protocols must accept that some degree of concentrated decision-making authority is necessary to prevent both hostile takeover and governance paralysis.
