By Avery Rodriguez, DeFi Security Auditor — published on BKG Exchange (bkg.com)
One million ENS. That is the number that just broke the deadlock between ENS Labs and its own token holders. After weeks of public friction — including delegates on the ENS DAO forum explicitly labeling the early foundation proposal a "governance attack" — Katherine Wu's revised executable proposal lands with a deliberately smaller footprint: an initial endowment of 1M ENS for the new ENS Foundation, and a promise that the DAO's operational wallet stays exactly where it is.
When I read the final structure, I didn't see a retreat. I saw a stress test that the system just passed. And that's a signal worth more than any price rally.
Context: What Was Actually Proposed
ENS is not just a name service; it is the identity infrastructure layer of Ethereum. Every .eth domain resolves through its registry on the Ethereum mainnet. ENS Labs — the team that built it — wanted to formally separate a foundation to manage long-term capital. This is a corporate-structure move, not a protocol upgrade. No Solidity changes. No modifications to the registry or resolver contracts. The innovation here is in the power diagram, not the bytecode.
The early draft, unsurprisingly, was more aggressive. It would have moved the DAO's operational treasury into the new foundation's control and allocated a higher-than-disclosed ENS grant to the entity. To a security auditor, that sentence is a red flag wearing a suit. Moving operational funds out of the token holders' direct control is the single highest-leverage event a DAO can vote on. Once assets sit inside a foundation's multi-sig, tokenholder governance leverage is functionally diluted — regardless of what the tokenomics page says.
The revised proposal fixes the two most dangerous components. The DAO operational wallet stays under DAO control. The foundation's initial grant is capped at 1M ENS — roughly one percent of total supply. And perhaps most importantly, a Security Council now oversees Endowment transactions. On paper, that's a parent-teacher conference with an audited report card. But the paper matters less than the process that produced it.
Core: The Checks and Balances Are the Product
In my years auditing protocol treasuries — including post-mortems of flash loan collapses that drained governance pools in under a block — I have learned that the most common failure is not in the smart contract. It is in the operational layer. A contract can be formally verified, yet the vault still breaks when a three-of-five multi-sig signs without oversight. Treasury governance is the part that never shows up in an audit trail until it is already running in reverse.
This is why the "small" changes matter. Keeping the DAO wallet in the DAO preserves the most important security property: the ability for token holders to see, contest, and veto before movement — not after. The 1M ENS cap lowers immediate dilution expectations; any shorter-term selling pressure from a cliff unlock simply doesn't exist yet. And the Security Council is the classic control-tower mechanism: a narrowly scoped emergency brake, not a steering wheel.
Is the council ideal? No. Permanent councils drift toward centralization, and the members of any council are one bribe or one juicy grant away from becoming what they were hired to stop. But in the context of this specific fight, the council serves as a monitored compromise. It is a way to say: "We trust the foundation, but not enough to give it the keys."
That phrasing is not a criticism. In security engineering, the right level of trust is the one you survive when it is broken.
Contrarian: The "Governance Attack" Framing Was Both Right and Evidence of Health
Here is the uncomfortable truth that headline-skimming readers will miss: the delegates who screamed "governance attack" were correct. A governance attack is not always a malicious exploit from outside. It can be a slow drift of control from the community toward a founding team, executed with the best legal advice and a healthy capital allocation. The label was emotionally charged, but the mechanics were accurate.
And that is exactly why this outcome is good news. The resistance was not a malfunction; it was the DAO's immune system working as designed. Token holders watched, challenged, and extracted real concessions. That behavior is extremely rare in crypto governance, where most "governance decisions" are pre-negotiated theater.
But let's not skip over the risk. The same immune response that just protected the treasury can easily spiral into permanent obstruction. If every future ENS Labs proposal is met with automatic suspicion, the foundation will starve and execution velocity will collapse. The trust deficit between team and token holders is now out in the open, and a security council does not erase it. Trust is not a variable you can optimize away. It has to be rebuilt one completed milestone at a time.
Takeaway: The Real Output Is a Template
The most interesting thing about this proposal is not ENS, and it is not the foundation itself. It is the pattern. Other DAOs — Lido, Aave, Arbitrum, everyone with a treasury and a legal headache — will study this sequence: proposal, resistance, scaled-back revision, council oversight. ENS just wrote a playbook for how a foundation gets created without being mistaken for a coup.
The next signals will be precise: who sits on that Security Council, how the 1M ENS vesting schedule actually unlocks, and whether future proposals carry a documented "delegate consultation" phase before they go to vote. Watch those inputs. The headlines are already stale.
The signal is in the multi-sig.