Risk analysis and mechanism design to secure governance | @anticapture

Onchain
Most ENS just sits in wallets doing nothing. The ENS Delegation Incentives Program changes that: delegate to an active delegate and you earn rewards from the ENS DAO while making ENS governance stronger. And the more holders join, the bigger the reward pool gets for everyone. 🧵
2
12
48
22,477
Yesterday, @Scroll_ZKP held its first governance call in months. During it, the team outlined a series of changes planned for the end of 2026. They include: - A full shift in focus toward AI, aiming to compete with OpenRouter - $SCR staking to participate in this ecosystem, and $USX for payments - No longer permissionless, but now permissioned
We’re getting the Scroll DAO conversation moving again. Following our September monthly call, we shared an update on Scroll’s consumer AI direction, Compass, and what the proposed changes could mean for the network, SCR, USX, and the DAO.
5
298
As an @ENS_DAO Service Provider, we've published our plan for Year 2 of our work with the DAO. Our goals range from improving ENS's governance contracts to bringing new features to the community, including 1 and 2 character .eth names and a referral program for ENS. Here's our full plan and what we'll keep doing at ENS 👇
3
3
20
1,440
We'll also keep maintaining every item from our original proposal, including: - Anticapture, to monitor the security and health of ENS governance - The ENS governance front-end, making it easier for delegates to vote on ENS proposals - The Incentives Program, aiming to bring more delegated $ENS to active governance participants, making the DAO more secure
1
4
65
blockful thanks every delegate and @ENS_DAO @ensdomains for their trust, and we remain committed to delivering the best for ENS.
4
49
Another abandoned governance is under attack - this time it's Rarible's. @rarible was a well-known NFT marketplace between 2020 and 2022. It moved millions of dollars during the NFT frenzy. The protocol and its treasury are governed by $veRARI holders - locked $RARI - using veNomics to set voting power in the DAO, just like Curve does. On September 20, a wallet bought 3.5 ETH worth of $RARI and locked it in Rarible's contracts, receiving 132,576 veRARI in voting power. Moments later, the same wallet submitted a proposal from a supposed activist investor called Falcon. According to the proposal text, they would "unlock veRARI's value for its holders." In practice, if approved, the proposal transfers ownership of all contracts to "Falcon." The voting period ends on September 25 at 08:53 UTC. Rarible DAO has a Security Council, so it is able to block the attack, if it manages to get the multisig signers who control the Council to act in time. The strangest part of this attack is that Rarible has only $368 in its treasury, yet the attackers spent $9,311 to capture its governance. Like other attacks, they don't want money - they want control over what Rarible can do, such as: - The ability to mint unlimited $RARI tokens on the market and sell them on the secondary market (while shorting it on an exchange) - Stealing users' funds via $WETH, $USDC, and other token approvals (including NFTs) granted to Rarible's marketplace - Draining all the tokens locked in the veRARI contract These are just simple possibilities that let attackers extract profit without needing a treasury to steal from. Over time, these attacks are getting more sophisticated, and the pool of potential victims keeps growing - even projects with no money worth stealing. We recommend that anyone holding an address with approvals granted to Rarible revoke them, to avoid any trouble in case governance is indeed captured.
🚨 @rarible - Attempted governance takeover (2026-09-20) Token: $RARI @ $0.1066 Network: Ethereum Type: Access Control (malicious governance proposal / DAO takeover) Attacker "Falcon" (0x94223fcC…F04Ca, ~132.5K veRARI votes, above the 5,000 proposalThreshold) submitted proposal 3648869205…835338 to RariGovernor (0x859e1c00…2edca). The single action calls the DAO's delegatecall-executor 0xb23BCD4F…C5b5 with execute(0x36224b869…a722, write(slot,1)). Contract 0x36224 is a 4-line backdoor whose only function e2e52ec1 (write(uint256,uint256)) does a raw SSTORE; invoked via the executor's DELEGATECALL it writes 1 into an AccessControl role slot of the executor — granting Falcon a privileged role and full control of the DAO. The proposal text openly states YES "grants full control of the DAO to the activist investor group Falcon." No funds moved yet (vote open); execution would hand the DAO/treasury to the proposer. TX: etherscan.io/tx/0xeaef75813c… Attacker: etherscan.io/address/0x94223… Victim: etherscan.io/address/0x859e1… ⏱️ Real-time alerts: defimon.xyz
2
3
19
1,208
A pool of 8K $ENS will be distributed among those who hold $ENS and delegate their tokens to Active Delegates. If delegations and participation grow, this pool can reach 10K $ENS. If you're a delegate, vote. And if you hold $ENS, delegate your tokens to someone who participates in governance. Pick an Active Delegate and delegate to them using the link below 👇 incentives.ens.blockful.io/
1
6
16
578
41 addresses were drained after an Access Control flaw in Bonfire allowed an attacker to move tokens sitting in users' wallets to their own address. The amount stolen isn't the kind of headline figure we're used to: $50K was taken in the exploit. What stands out is the vulnerability exposed in Bonfire's contracts. When someone bought $BONFIRE, they approved the contracts (the router) to move tokens in their wallet. That approval was infinite by default. The problem was in the function that transfers user funds: it was a public function. Anyone could interact with Bonfire's contracts and transfer users' tokens to any other address 0 in other words, steal every $BONFIRE. The flaw is attributed to the protocol's Access Control, because this is clearly a permissions issue: the function should never have been public, and it should have had limits on how it could be called. Worth noting that Bonfire's contracts had been inactive for 4 years. The attacker went hunting for flaws in abandoned contracts - a pattern we've seen repeat over the past few months.
🚨SlowMist TI Alert🚨 💸 @Bonfiretoken Loss: ~ $50k 🔍 Root Cause: Access control missing in BonfireSwap router's `transfer`. The function does not check `msg.sender == from` nor verify the caller's allowance on `from`, letting anyone set a victim as `from` and themselves as `to`. The router drains the victim's TOKEN using its pre-approved allowance (victim → router) and forwards funds via same-token pool swap. 📌 Attacker: 0x2b5bf7d9d9dc1eec68f40c6b7a8f197e65f9731a → attack contract 0x28E976Ea7b83553d6D1D45CE81334156A2632127 📌 Victim: 41 TOKEN holders who approved the router (largest: 0xefF2FC4E3145f58F534d68A36Bcd3085Be6a4096, −5289.1 TOKEN) 📌 Vulnerable Contract: 0x17e801e17cefc6334059189c178d4783830e03d3 (BonfireSwap router) Powered by SlowMist.AI Tx: bscscan.com/tx/0xb4c00e8f3ba…
2
3
214
blockful.eth retweeted
After receiving a 3M $ENS delegation and voting on 2 proposals with that voting power, nick.eth withdrew the delegation and now has only 151K $ENS delegated to his address. The tokens are still held in wallets he controls, but they are not currently being used to vote in ENS DAO governance.
New major governance change detected: nick.eth received a 3M ENS delegation. To put in perspective, the quorum is 1M ENS and average turnout ~1.4M ENS.
1
1
3
525
The final round of the $ENS delegation incentives ends on 30 September. If you hold $ENS and delegate to an Active Delegate, you earn more $ENS just for handing voting power to someone who shows up for governance. Small balances count too. Rewards under 1 $ENS go into a draw: wallets are grouped into 10 $ENS pools and one wallet takes each pool. That's how every kind of holder gets rewarded, from 1 $ENS to 10,000 $ENS 🏆 Hold $ENS and haven't delegated? Find an Active Delegate on the page now and become eligible for rewards 👇 incentives.ens.blockful.io/
2
7
273
Unfortunately, the attack succeeded. The attacker stole $121K (48 ETH), funds controlled by Yam Finance's governance contract. Governance attacks on abandoned contracts are common, but this one stands out for how precisely it targeted what it took. @YamFinance had a product that let traders get exposure to gas fee volatility on Ethereum through a synthetic token called uGAS. To make trading possible, it supplied liquidity to the uGAS/WETH pair. Since Yam Finance controlled the funds used in the uGAS/WETH pool, gaining access to its governance contract and Timelock let the attacker drain the 48 ETH sitting in the contracts of a product that hadn't been used in years. Note what happened here: the DAO's treasury had nothing left to steal - what it still controlled did. This is a more advanced type of attack, and unfortunately one we expect to see more of in the coming months.
A wallet funded by an address Blockscout flags as a scam bought roughly 504,000 YAM this week, about 3.3% of supply, enough to clear @YamFinance 200k-vote governance quorum by itself. It's now sitting behind proposal #45. The setup ran in six moves: - fund the wallet - buy the YAM through an on-chain aggregator - self-delegate - submit a proposal on YamGovernorAlpha V3 with an empty description - then vote FOR in the very next block so the snapshot locks in before anyone can react. - the attacker then sold most of the position, keeping back roughly 80k votes worth of YAM, just above the 50k threshold that lets anyone call a public cancel(). Proposal #45 does one thing: setPendingAdmin on Timelock V3, naming the attacker's address. Pass it, and that address controls the Reserves treasury, the YAM V3 token's gov and mint functions, and the Incentivizer and Migrator contracts, all without a second vote. The same play failed in July 2022 on the same Governor V3 because the attacker sold below threshold and anyone could cancel. This time the position was sized to stay above it, and the Guardian multisig, which can still cancel(45) with 3 of 8 signers, hasn't signed anything since November 2022. Flash loans don't help either way, since voting power is checkpointed at the proposal's start block. If you hold delegated YAM, vote against #45 before block 25,897,343.
1
8
428
A proposal submitted by @Marcus_Balancer outlines a plan to cease @Balancer DAO's operations. The main argument is the difficulty of rebuilding trust, bringing back volume and, consequently, revenue, after the November 2025 attack - in which $120M was stolen. However, in the proposal, Marcus states that a group of contributors is discussing submitting a proposal to keep the protocol's infrastructure alive. Now, it remains to be seen whether the proposal will be approved and whether there will be a fork with contributors maintaining the protocol.
A proposal to wind down Balancer and distribute the treasury to BAL holders is live on the forum, authored by Marcus Hardt. Discussion is open; a Snapshot vote is expected to happen from 25 to 29 September. Nothing changes today: pools and withdrawals work as they do now. Any wind-down action waits for the vote.
6
351
This month, anyone who delegates their $ENS to an active delegate will share a pool of 8K $ENS🏆 September marks the final round of incentives for delegating $ENS to active delegates. You delegate your voting power to someone who participates in governance, and in return, you receive more $ENS tokens in your wallet. Out of the 3 months of incentives distributed, this will be the month with the highest amount of $ENS distributed. If you have $ENS, don't miss this opportunity: delegate your $ENS now and earn tokens. If you want to find out who you can delegate your tokens to, click the link below 👇 incentives.ens.blockful.io/v…
1
3
18
616
With @anticapture we can assess ENS DAO's revenue and identify the main activities that generated income for the protocol. The main revenue sources are (1) new registrations, (2) renewals, and (3) premium sales. Revenue from new registrations has currently been declining, but revenue from premium sales has increased over the past 3 months - in August alone, it reached $113K. Premium sales are ENS domains that have already expired and passed the 90-day grace period. After that period, the domain goes into a 21-day descending auction. Its price starts at $100M and drops to 0 by day 21. The DAO charges a premium in this auction for whoever wants to claim the domain. The difference between the premium paid in the auction and the cost of registering the ENS name is an additional revenue source for the DAO - today, just as important as renewals or new registrations.
3
9
317
The latest round of rewards for $ENS holders who delegate to Active Delegates has arrived. This month, thanks to 17% growth last month, a surprise: 3,000 more $ENS to incentivize more delegations. A pool of 8K $ENS will be distributed to those who delegate their $ENS and help improve ENS DAO's security. If this growth keeps up, incentives could increase: from 10K ENS up to 30K $ENS 👀 Start delegating your $ENS NOW and check out Active Delegates, link below 👇 incentives.ens.blockful.io/
1
5
19
712
An attacker funded a wallet through Tornado Cash, registered the ENS name autonolas-deployer.eth to impersonate Autonolas's deployer, then filed a proposal titled "Owner migration" to a Safe updater. The calldata called Treasury.changeOwner(), naming an attacker EOA. A second address copied it a day later, naming itself owner. Both targeted the same Treasury, about 40,196 ETH. @DefimonAlerts flagged the funding trail and fake ENS before either vote opened. Two veOLAS holders voted AGAINST both, about 2.46M and 2.51M veOLAS each, 20x quorum. A proposal now raises the threshold from 5,000 to 250,000 veOLAS and quorum from 3% to 10%. @autonolas team was active, blocking the attack with its own tokens and proposing this hardening. But unfortunately, this is the exception, not the rule.
1
1
15
1,092
blockful.eth retweeted
On July 27, Uniswap approved a proposal enabling the fee switch across multiple networks, including Robinhood Chain. The fee switch uses fees charged to LPs to buy and burn $UNI. Since the proposal passed, Uniswap has burned $6.4M worth of $UNI driven by volume on Robinhood Chain alone. That already makes it the third-largest network for $UNI burns, accounting for 70% of all fees accumulated toward the burn, and it's closing in on Base. All of that in just a month and a half. The DAO's timing on this proposal let Uniswap tie the fee switch activation directly to Robinhood Chain's traction, turning the network's early success into a burn number $UNI holders can see.
2
1
5
341
The rewards for the first month of ENS Delegation Incentives have been distributed! A total of 5,000 ENS was distributed to 541 participants. If you delegate to an active voter, go check your wallet. If you missed August, September is open now. A quick reminder of how the pool works: each month the ENS DAO distributes rewards to voters, and holders who delegate to an active voter. The pool grows as more people take part, so the more people join, the bigger the pie. Thank you to everyone who delegated in August. Spread the word, grow the pool!
3
13
595
A wallet funded by an address Blockscout flags as a scam bought roughly 504,000 YAM this week, about 3.3% of supply, enough to clear @YamFinance 200k-vote governance quorum by itself. It's now sitting behind proposal #45. The setup ran in six moves: - fund the wallet - buy the YAM through an on-chain aggregator - self-delegate - submit a proposal on YamGovernorAlpha V3 with an empty description - then vote FOR in the very next block so the snapshot locks in before anyone can react. - the attacker then sold most of the position, keeping back roughly 80k votes worth of YAM, just above the 50k threshold that lets anyone call a public cancel(). Proposal #45 does one thing: setPendingAdmin on Timelock V3, naming the attacker's address. Pass it, and that address controls the Reserves treasury, the YAM V3 token's gov and mint functions, and the Incentivizer and Migrator contracts, all without a second vote. The same play failed in July 2022 on the same Governor V3 because the attacker sold below threshold and anyone could cancel. This time the position was sized to stay above it, and the Guardian multisig, which can still cancel(45) with 3 of 8 signers, hasn't signed anything since November 2022. Flash loans don't help either way, since voting power is checkpointed at the proposal's start block. If you hold delegated YAM, vote against #45 before block 25,897,343.
Community alert: Defimon detected a governance takeover attempt of @YamFinance Attacker self-delegated ~504K $YAM (~3.3% of supply, just over the quorum) and submitted YamGovernorAlpha proposal #45 with an empty description ("0x"). The single action calls setPendingAdmin(attacker) on the YAM Timelock. If the vote passes and executes, the attacker becomes pendingAdmin and can acceptAdmin to seize full control of the Timelock - admin of all YAM protocol contracts and the DAO treasury. There is ~$337K at risk. The protocol is dormant, so if you hold YAM vote against before block 25897343 (around 34 hours left). TX: etherscan.io/tx/0xf3c9b1d709… Attacker: etherscan.io/address/0x26881…
1
1
10
2,284