Key Takeaways:
- ENS DAO approved an eight-member Security Council with two-year veto power
- The council requires five of eight signatures to cancel malicious proposals
- The move follows the $20 million BonkDAO treasury drain and other DAO exploits
Key Takeaways:

ENS DAO approved an eight-member Security Council with two-year veto power to cancel malicious governance proposals during the timelock period, following a series of high-profile DAO exploits including the $20 million BonkDAO treasury drain.
"The council acts as an emergency brake for cases where a malicious proposal has already passed a DAO vote but has not yet executed," ENS said in its announcement. The group requires five of eight signatures to block a queued transaction.
The council operates under a 5-of-8 multisig structure, up from the outgoing council's 4-of-8 threshold. Its authority is limited to canceling pending transactions inside the two-day governance timelock — it cannot move treasury funds, create proposals, or replace canceled transactions with alternative actions. The mandate covers attacks involving stolen governance credentials, vote buying, flash loans, and other methods used to gain voting power outside ordinary market participation. Controversial policy decisions alone do not give the council grounds to intervene.
The move adds a final security check after voting closes but before onchain execution takes effect. ENS cited the July 2025 BonkDAO attack, where a malicious proposal drained roughly $20 million worth of BONK from the treasury, as well as the 2022 Beanstalk exploit and the 2023 Tornado Cash governance takeover, as examples of threats the council is designed to address. The new council's term runs until July 16, 2028, after which ENS DAO must approve an extension through another governance vote.
Council composition and selection
The eight members were chosen through a ranked-choice election under governance proposal EP 6.50. They include ENS founder Nick Johnson, Hudson Jameson, Pablo Sabbatella, Colton Liberacki, Kevin Gaspar, Alex Van de Sande, Griff Green, and Alex Netto. Candidates needed a record in ENS governance or professional experience in smart contract security, incident response, governance design, or multisig operations.
Members must follow a public charter, sign appointment agreements with the ENS Foundation, and complete identity and background checks. ENS said the framework includes a process for removing council members who knowingly operate outside their approved authority.
How the veto mechanism works
Successful proposals do not execute immediately after voting closes. They enter a two-day timelock period, giving the community time to inspect queued transactions. The council can intervene during that window only when a proposal meets defined emergency conditions set out in the council charter.
The outgoing council's cancellation authority expires on July 24. ENS activated the replacement before the previous authority ended to avoid leaving the DAO without an emergency cancellation mechanism during the transition.
Implications for DAO governance security
The ENS model addresses a structural weakness exposed by recent DAO attacks. In the BonkDAO case, the attacker acquired enough voting power to pass a malicious proposal while low participation left the treasury exposed to governance capture. The Beanstalk exploit used a flash loan to temporarily gain voting power. The Tornado Cash attack involved a proposal that appeared legitimate during review but changed behavior after approval.
ENS said stronger delegation and voter participation can make some governance attacks more expensive, but those measures cannot fully address compromised credentials, coordinated token purchases, bribery, or proposals containing hidden malicious code. The Security Council adds a separate review window after voting ends — a safeguard that BonkDAO, Beanstalk, and Tornado Cash all lacked.
This article is for informational purposes only and does not constitute investment advice.