FeedProjects
Developers
Settings
๐ŸŽ‰ A new chapter begins: Boardroom has joined Agora
Learn more
protocol logo
Explore / Projects
Ethereum Name Service

Proposals

Discussions

Members

Information

Create Proposal

Ethereum Name Service

ProposalsDiscussionsMembersInformation
Proposal
Back to Proposals
closedEnded a year ago ยท Snapshot (Offchain)

[EP 5.21] [Social] Governance Security Bounty

By 0x76A6...32BbB8

Summary

This proposal aims to compensate the blockful team for their work in identifying, analyzing, reporting and mitigating a severe vulnerability in ENS DAOโ€™s governance structure.

Background

In March 2024, blockful uncovered a critical vulnerability that could have led to a ~$150M theft and protocol capture. Their subsequent work led to the implementation of the Security Council, significantly enhancing ENS DAOโ€™s resilience against attacks.

Contribution Details

The team involved is a different squad than the one working on the scope of the ENS service provider. It was developed by 2 researchers, 1 smart contract engineer and 4 different auditors the team has worked with previously. Summing up to ~600 hours, the scope includes:

  • Comprehensive vulnerability assessment and risk analysis: Here is our detailed security report.
  • Data analysis of ENS governance metrics and study of past DAO attackerโ€™s behaviors.
  • Design, development and deployment of the Security Council contract and multisig.
  • The Security Council was thought with several key features to balance security and decentralization.
  • Smart contract implementation and testing (GitHub)
  • Governance proposal drafting and support [1, 2, 3]

More details can be found on the links above for past proposals and the report.

Compensation Rationale

As a team that is totally bootstrapped and never received any investment, this support us to keep it sustainable with the resources invested towards this initiative. The requested amount represents fair compensation for:

  • The potential loss prevention of ~$150M, capture of the DAO and protocol. The attack is anything but theoretical and there are actually many groups of investors who specialize in โ€œrisk free value raidersโ€. They have exerted the attack on other DAOs before. Currently there are unknown whales buying ENS for +450 days and have ~2M ENS, showing how feasible the scenario is, more than the average quorum, in one wallet.
  • A critical code bug bounty in ENS is $250k USDC. Our work was much beyond identifying and disclosing.
  • Significantly lower cost compared to standard rates charged by other security service providers in the DAO space, which typically demand liquid compensation. An example is that Open Zeppelin (one of the most reputable players in security) charges $4M/year at Compound, which recently suffered this type of attack.
  • Months of dedicated work by the team involved (researchers, devs and auditors).
  • The long-term value added to ENS through enhanced security.
  • Our commitment to ENSโ€™s long-term success and continued contribution, as evidenced by the 2-year vesting schedule.

Compensation Structure

  • Total amount: 100k USDC + 15k vested ENS tokens
  • Vesting period: 2 years
  • Vesting start date: April 8, 2024 (date of initial research disclosure)
  • Vesting schedule: Linear vesting

Benefits to ENS DAO

  • Sets a positive precedent that responsible vulnerability disclosure and correction are rewarded, encouraging future security contributions
  • Preserves DAO treasury liquidity by using part of the bounty in ENS tokens instead of USDC or ETH
  • Enhances governance security by increasing the number of engaged, security-focused token holders

Conclusion

By approving this compensation, ENS DAO acknowledges the critical importance of security research and proactive governance improvements. The vesting structure ensures ongoing commitment and aligns incentives for continued contribution to ENSโ€™s security and stability.

Success Criteria

For this social proposal to pass, the following quorum and voting requirements must be met:

Quorum: The proposal must receive a minimum of 1% of the total supply of $ENS (1 million votes) in the form of โ€œForโ€ and โ€œAbstainโ€ votes combined. โ€œAgainstโ€ votes do not count towards quorum.

Approval: Once the quorum is reached, the proposal requires a simple majority (>50%) of โ€œForโ€ votes among the โ€œForโ€ and โ€œAgainstโ€ votes to pass. โ€œAbstainโ€ votes do not count towards the approval calculation.

Continue Reading
Connect Wallet to Add Note
0
Votes 91
VoterCast PowerVote & Rationale
0x5BFC...418390
180,439

For

0x2B88...537d12
136,309

For

0x8393...6F0780
128,457

For

0x9831...1b6744
124,030

For

0x76A6...32BbB8
116,142

Abstain

SHOW MORE
VOTE POWER
0
Connect Wallet
Proposal Status
  • Wed October 23 2024, 08:10 pmVoting Period Starts
  • Mon October 28 2024, 08:10 pmEnd Voting Period
Current Results

1-For

1.185M

90.58%

2-Abstain

123,198.002

9.42%

3-Against

6.002

0%
DocumentationBrandingContact Us
Home
This Project is Currently Disabled

If you would like to enable it, please checkout below.

Boardroom Subscription

Sign up for an individual subscription (access all projects on the platform)

Subscribe
Enable Project

Enable the entire project for every user

Enable Project
Contact Us