en

ENS DAO activates two-year veto council after $20M BonkDAO attack

image
rubric logo Altcoins
like fud 7

$ENS DAO has activated a new eight-member Security Council with limited power to cancel malicious governance proposals before they execute.

The council will operate for two years under a five-of-eight multisig structure, meaning at least five members must agree before blocking a transaction.

The move creates a final security check during $ENS governance’s two-day timelock. Successful proposals do not execute immediately after voting closes. Instead, they enter the waiting period, giving the community time to inspect the queued transactions and allowing the council to intervene when a proposal meets defined emergency conditions. The council’s term runs until July 16, 2028.

The new Security Council cannot move funds from the $ENS DAO treasury, create governance proposals or change proposals that token holders have approved. It also cannot replace a canceled transaction with another action. Its contract only allows the members to cancel operations that remain pending inside the governance timelock.

$ENS described the council as an “emergency brake” for cases in which a malicious proposal has already passed a DAO vote but has not yet executed. Its mandate covers attacks involving stolen governance credentials, fraud, vote buying, flash loans and other methods used to gain voting power outside ordinary market participation. Controversial policy decisions alone do not give the council grounds to intervene.

$ENS DAO has approved the proposal activating its new Security Council for the next two years.

The council is an eight-member group with veto power to cancel a malicious proposal after it passes, but before it executes.

Here’s how it works ↓ pic.twitter.com/JsrbnpsQFc

— ens.eth (@ensdomains) July 20, 2026

The structure also raises the threshold required for intervention. The outgoing Security Council used a four-of-eight approval requirement. The new group needs five signatures before it can stop a proposal. Its authority will automatically expire after two years unless $ENS DAO approves an extension through another governance vote.

Members must also follow a public charter, sign appointment agreements with the $ENS Foundation and complete identity and background checks. $ENS said the framework includes a process for removing council members who knowingly operate outside their approved authority.

BonkDAO attack puts governance security back in focus

$ENS announced the council shortly after a major governance attack on BonkDAO. As crypto.news reported, BonkDAO said a malicious proposal drained about $20 million worth of BONK from its treasury in July. The organization later contacted law enforcement and began efforts to trace the funds.

A later crypto.news analysis of the BonkDAO attack found that the DAO lacked several safeguards now built into the $ENS model, including a timelock and an emergency multisig veto. In the BonkDAO case, the attacker acquired enough voting power to pass a valid proposal, while low participation left the treasury exposed to governance capture.

$ENS cited the BonkDAO incident when explaining why governance itself can become an attack route. It also pointed to the 2022 Beanstalk exploit, where an attacker temporarily gained enough voting power through a flash loan to pass proposals that transferred assets. The new $ENS mandate specifically allows intervention when documentary evidence shows that a proposal passed through an exploited flash loan or similar voting manipulation.

The $ENS approach does not prevent a malicious proposal from entering governance or winning a vote. Instead, it creates a two-day period between approval and execution. Five council members can act during that window if the proposal meets the emergency rules set out in the council charter.

Tornado Cash attack showed malicious code can survive voting

$ENS also pointed to the 2023 Tornado Cash governance takeover as another type of threat. In that case, an attacker submitted a proposal that appeared legitimate during review but later changed its behavior after approval. The attacker then gained control over the protocol’s governance system.

As crypto.news reported at the time, the malicious proposal gave the attacker control over Tornado Cash governance and allowed the withdrawal of locked voting assets. The incident showed that token holders can approve code without detecting hidden behavior before execution.

$ENS said stronger delegation and voter participation can make some governance attacks more expensive because attackers need greater voting power to control an outcome. However, those measures cannot fully address compromised credentials, coordinated token purchases, bribery or proposals containing malicious code. The Security Council adds a separate review window after voting ends.

That power remains restricted to the emergency conditions approved by $ENS DAO. Ordinary disputes over spending, protocol direction and organizational policy stay with token holders and delegates, even when council members disagree with the outcome.

Eight members take control until July 2028

The new council includes $ENS founder Nick Johnson, Hudson Jameson, Pablo Sabbatella, Colton Liberacki, Kevin Gaspar, Alex Van de Sande, Griff Green and Alex Netto. $ENS selected the members through a ranked-choice election under governance proposal EP 6.50.

Candidates needed a record in $ENS governance or professional experience in areas such as smart contract security, incident response, governance design and multisig operations. The DAO then approved the onchain proposal giving the new Security Council contract its cancellation role.

The outgoing council’s cancellation authority expires on July 24, while the new term runs until July 16, 2028. $ENS activated the replacement before the previous authority ended to avoid leaving the DAO without an emergency cancellation mechanism during the transition.

Under the approved structure, most governance proposals will continue through voting and execution without council involvement. The eight-member group only enters the process when a successful proposal remains inside the two-day timelock and meets the defined conditions for a malicious or exploitative governance attack.