Accelerating governance capture resistance | By @blockful_io

🗳️ With @tallyxyz winding down, delegates and token holders need reliable places to participate. Multiple independent frontends aren't just nice to have, they reduce single points of failure. 🔗 Anticapture is now available as a governance interface: anticapture.com
1
7
44
7,808
Another day, another attempt to capture an abandoned governance. Rarible is part of a series of attacks carried out on abandoned DAOs that either (1) hold a treasury or (2) control ways to extract money in some form. Option 2 has been becoming increasingly popular. A DAO may not have money, but it can mint new tokens or drain funds from users who granted infinite approvals 5 years ago. We're preparing a deeper analysis of this risk currently circling the market. Keep an eye on @anticapture 👀
Another abandoned governance is under attack - this time it's Rarible's. @rarible was a well-known NFT marketplace between 2020 and 2022. It moved millions of dollars during the NFT frenzy. The protocol and its treasury are governed by $veRARI holders - locked $RARI - using veNomics to set voting power in the DAO, just like Curve does. On September 20, a wallet bought 3.5 ETH worth of $RARI and locked it in Rarible's contracts, receiving 132,576 veRARI in voting power. Moments later, the same wallet submitted a proposal from a supposed activist investor called Falcon. According to the proposal text, they would "unlock veRARI's value for its holders." In practice, if approved, the proposal transfers ownership of all contracts to "Falcon." The voting period ends on September 25 at 08:53 UTC. Rarible DAO has a Security Council, so it is able to block the attack, if it manages to get the multisig signers who control the Council to act in time. The strangest part of this attack is that Rarible has only $368 in its treasury, yet the attackers spent $9,311 to capture its governance. Like other attacks, they don't want money - they want control over what Rarible can do, such as: - The ability to mint unlimited $RARI tokens on the market and sell them on the secondary market (while shorting it on an exchange) - Stealing users' funds via $WETH, $USDC, and other token approvals (including NFTs) granted to Rarible's marketplace - Draining all the tokens locked in the veRARI contract These are just simple possibilities that let attackers extract profit without needing a treasury to steal from. Over time, these attacks are getting more sophisticated, and the pool of potential victims keeps growing - even projects with no money worth stealing. We recommend that anyone holding an address with approvals granted to Rarible revoke them, to avoid any trouble in case governance is indeed captured.
131
After receiving a 3M $ENS delegation and voting on 2 proposals with that voting power, nick.eth withdrew the delegation and now has only 151K $ENS delegated to his address. The tokens are still held in wallets he controls, but they are not currently being used to vote in ENS DAO governance.
New major governance change detected: nick.eth received a 3M ENS delegation. To put in perspective, the quorum is 1M ENS and average turnout ~1.4M ENS.
1
1
3
527
Attack attempts continue to happen in DAOs with abandoned multi-million dollar treasuries. The capture of decentralized organizations and protocols is a reality - and it will continue to happen if projects don't prioritize the security of their treasuries and contracts. That's why we built @anticapture
@AmpleforthOrg was the target of a governance attack attempt this past weekend. An address submitted a proposal requesting a supposed DAO payment of $2.5M to a grantee, the project's entire USDC treasury. The project exists and is discussed on the forum, so it could slip by at first glance. However, in the last few hours, the proposal that would have executed the attack was canceled. The address that submitted the proposal was receiving a delegation from another wallet. That wallet held 87K $FORTH, with 70K $FORTH being the minimum required to submit a proposal. Today, the owner of those $FORTH decided to sell their entire position in the governance token. @AmpleforthOrg governance has a mechanism that allows anyone to cancel a proposal when the submitter holds less than 75K $FORTH. Seventy blocks after the $FORTH sale, an address canceled the proposal that would have stolen the $2.5M in USDC. In parallel, a proposal to move treasury administration to the Ampleforth team's multisig entered voting. It was submitted one day after the attacker's proposal and will begin being voted on tomorrow. If approved, Ampleforth would move administration of its treasury (via Timelock) to a 2-of-5 multisig, thereby preventing any $FORTH holder from moving the funds currently held in treasury. That would prevent further attacks, but it would also end the utility of $FORTH - using the DAO's money.
1
4
234
anticapture retweeted
With @anticapture we can assess ENS DAO's revenue and identify the main activities that generated income for the protocol. The main revenue sources are (1) new registrations, (2) renewals, and (3) premium sales. Revenue from new registrations has currently been declining, but revenue from premium sales has increased over the past 3 months - in August alone, it reached $113K. Premium sales are ENS domains that have already expired and passed the 90-day grace period. After that period, the domain goes into a 21-day descending auction. Its price starts at $100M and drops to 0 by day 21. The DAO charges a premium in this auction for whoever wants to claim the domain. The difference between the premium paid in the auction and the cost of registering the ENS name is an additional revenue source for the DAO - today, just as important as renewals or new registrations.
3
9
317
the fly is preventing governance attacks
47
With market optimism over the past few weeks, governance token prices have risen, increasing the cost to attack DAOs. On @Uniswap, for example, $UNI doubled in price: it went from $3.29 on August 18 to $7.37 on September 5. Even with the drop in the DAO's Delegated Supply, the cost to overtake it jumped from $534M to $1.2B. So, in a bull market, @Uniswap and other DAOs end up becoming more expensive to attack. On the other hand, their treasuries, which are based on governance tokens, also become more valuable.
1
4
155
$COMP, from @Compound_xyz , saw a spike in on-chain transfers on September 2, six days ago. At first, the movement seemed strange, but there is a justification. The proposal to move funds from the old Franchiser contracts, which delegate $COMP from the treasury to delegates, to a new contract (FranchiserPool) was approved. As a result, delegation was rebalanced, including a delegation of 33K $COMP to blockful. It's interesting to be able to find, on a platform like @anticapture , on-chain events that stand out - and, on the same platform, locate the answer to their cause.
3
215
On July 27, Uniswap approved a proposal enabling the fee switch across multiple networks, including Robinhood Chain. The fee switch uses fees charged to LPs to buy and burn $UNI. Since the proposal passed, Uniswap has burned $6.4M worth of $UNI driven by volume on Robinhood Chain alone. That already makes it the third-largest network for $UNI burns, accounting for 70% of all fees accumulated toward the burn, and it's closing in on Base. All of that in just a month and a half. The DAO's timing on this proposal let Uniswap tie the fee switch activation directly to Robinhood Chain's traction, turning the network's early success into a burn number $UNI holders can see.
2
1
5
341
DAOs continue to be targeted by attackers seeking dormant treasuries. These attacks affect not only the idle assets of these projects but, as in the case of @YamFinance, everything under the governance system's control: from users' staked tokens to the issuance of new coins. Governance is still the weakest layer in most decentralized protocols, and the industry keeps treating it as an afterthought.
A wallet funded by an address Blockscout flags as a scam bought roughly 504,000 YAM this week, about 3.3% of supply, enough to clear @YamFinance 200k-vote governance quorum by itself. It's now sitting behind proposal #45. The setup ran in six moves: - fund the wallet - buy the YAM through an on-chain aggregator - self-delegate - submit a proposal on YamGovernorAlpha V3 with an empty description - then vote FOR in the very next block so the snapshot locks in before anyone can react. - the attacker then sold most of the position, keeping back roughly 80k votes worth of YAM, just above the 50k threshold that lets anyone call a public cancel(). Proposal #45 does one thing: setPendingAdmin on Timelock V3, naming the attacker's address. Pass it, and that address controls the Reserves treasury, the YAM V3 token's gov and mint functions, and the Incentivizer and Migrator contracts, all without a second vote. The same play failed in July 2022 on the same Governor V3 because the attacker sold below threshold and anyone could cancel. This time the position was sized to stay above it, and the Guardian multisig, which can still cancel(45) with 3 of 8 signers, hasn't signed anything since November 2022. Flash loans don't help either way, since voting power is checkpointed at the proposal's start block. If you hold delegated YAM, vote against #45 before block 25,897,343.
4
209
On Compound,only two addresses increased their $COMP voting power over the last 30 days. One belongs to the @Compound_xyz (0xb06DF4dD01a5c5782f360aDA9345C87E86ADAe3D). The other has no clear label (0x3B6431fb5C71105cB3EaB2Cf058B135d4cCFc9C5). That unlabeled address has ties to Humpy, known for a past attempt to attack Compound, and connects to $dCOMP, a contract that wraps $COMP and delegates it to 0x3B64. $dCOMP is now accepted as collateral on Morpho, in a vault curated by API3, the same team behind the $dCOMP contracts.
5
190
Yesterday, Term Finance governance was attacked and $8.5M was stolen. The most curious part is that the attack did not target the Term Finance DAO or the protocol's code, but the governance of the project's vaults. But how? Many vaults, popularized by the ERC-4626 standard, have their own governance systems: contracts that grant certain addresses the power to change allocations, parameters, add assets, restrict deposits or withdrawals, and even move all capital to a new contract. Few people know this, but anyone who deposits money into a vault seeking returns in USDC or ETH, for example, can participate in that vault's governance. In most cases, all it takes is "wrapping" their position into a token that represents voting power within that vault. This way, investors become part of governance, not just curators and the protocol itself. However, like any governance system, there are risks if it is not well designed. In the Term Finance vault attack, the attacker deposited 0.5 ETH and 25 USDC into the respective vaults. Armed with tmvETH and tmvUSDC (vault shares) they wrapped them and converted them into voting power in the ETH and USDC vaults. In these vaults, total voting power (Votable Supply) only counts those who have wrapped their shares into voting tokens. This meant the attacker held nearly 100% of the voting power in both vaults, because almost no one participates in it or even knows this feature exists. With full control over both vaults' governance, the attacker submitted proposals that would supposedly move the funds into a new "strategy." In reality, all the money would go directly to an address controlled by the attacker. Term Finance's vault governance model is optimistic, meaning that blocking a proposal requires a minimum level of opposition to veto it. Since the attacker controlled nearly all the voting power, there was no way to block the malicious proposals. Even though both vault governance systems had timelocks with a delay before executing proposals - 6 days for the ETH vault and 2 days for the USDC vault - the administrators would themselves need to pass a proposal through the same governance process to stop the attack. And that is exactly what they tried: shortly after the attacker's proposal was submitted, curators submitted a counter-proposal to shut down the vault. However, since it also had to wait out the delay before being executed, the attacker had enough time to drain all the funds before the administrators could protect them. Today, the vault sector holds over $7 billion in AUM. Many of these vaults have governance systems and could face the same type of attack carried out against Term Finance. It is up to the industry and its participants to understand the importance of auditing and properly maintaining the infrastructure used to manage billions of dollars.
1
5
231
We're proud to join the new Encrypt the Mempool Coalition! Alongside industry leaders, we're pushing to integrate an EIP to encrypt the mempool in Ethereum's I* Hardfork - to stop toxic MEV & real-time censorship in a decentralized & credibly neutral way. Join the coalition 👇
1
1
4
332
Help make Ethereum private and credibly neutral - a place where normies, degens, institutions (& everyone else) can transact without toxic MEV & real-time censorship. encryptedmempool.org/
38
anticapture retweeted
Going live today: ENS Delegation Incentives Space. Learn how ENS holders can: - delegate their voting power gaslessly - earn rewards from the ENS DAO for doing it - help make ENS governance stronger With @alexnetto, @theZeugh & @Sim_Pop. Set a reminder: nitter.net/i/spaces/1mGPaaYblMXJN
1
6
18
1,284
anticapture retweeted
Most ENS just sits in wallets doing nothing. The ENS Delegation Incentives Program changes that: delegate to an active delegate and you earn rewards from the ENS DAO while making ENS governance stronger. And the more holders join, the bigger the reward pool gets for everyone. 🧵
2
12
48
22,484
anticapture retweeted
How it feels when using the @anticapture dashboard
ensteward.eth became the 2nd top ENS delegate Who is it? Someone to help keep the protocol neutral? Let's have a look at @anticapture's tracker - It's a clean addy funded by coinbase with 200k ENS. - Right before that, a Labs funded addy deposited 200k ENS to coinbase 🤔😮‍💨🤦
1
2
22
1,348
anticapture retweeted
One of the features I like the most on @anticapture and ens.gov.blockful.io proposals tabs is the display of non-voters. Seeing who hasn't voted on this proposal makes it clear that if everyone else voted, results still wouldn't change. It can also help you map who to talk to when you are the one proposing something that can get approved. That info is available on our dashboard, over API, and MCP, for all DAOs indexed on anticapture.
4
15
1,162
anticapture retweeted
Your ENS has been sitting idle in your wallet. Starting today it can do two things at once: > make ENS governance stronger > and earn you rewards from the ENS DAO The ENS Delegation Incentives Program is live.
8
25
90
15,788