The ENS Security Council is an eight-member group with limited veto power to cancel malicious governance proposals before they're executed. With its new members selected, ENS DAO has now approved the onchain proposal activating the council's authority for its next two-year term.
The ENS DAO governs the ENS protocol and treasury. Through proposals and tokenholder votes, it can approve changes to DAO-controlled contracts, allocate funding, and authorize other onchain actions in line with the ENS Constitution.
These powers allow the DAO to maintain and develop ENS, but they also mean that a malicious proposal could have serious consequences if it passes. The Security Council acts as an emergency brake: eight members who can collectively cancel a malicious proposal after it wins a vote but before its transactions are executed.
The new council's eight members were selected through EP 6.50. ENS DAO has now concluded the onchain vote, approving the final step that activates the contract controlled by the council's five-of-eight multisig. Its term will run for the next two years.
An executable ENS proposal doesn't take effect as soon as voting ends. Instead, it enters a two-day waiting period, known as a timelock, before its transactions can be carried out.
This delay gives delegates and the wider community time to inspect what the proposal will actually do. It also creates a final window in which the Security Council can intervene if the proposal is part of an attack.
Under EP 6.50, ENS DAO approved a five-of-eight signing threshold for the new council. This means at least five of its eight members must agree before a proposal can be canceled. The outgoing council operated with a four-of-eight threshold.
Within the ENS governance timelock, the council can only cancel a proposal that is waiting to be executed. It can't submit proposals, edit something tokenholders have approved, move funds from the DAO treasury, or initiate another governance action.
The outgoing council was also given two separate emergency permissions through EP 6.33. These allow its multisig to disable a compromised TLD or .eth registrar controller during a protocol emergency. Those permissions were granted separately and weren't included in the proposal that activated the new council.
The Security Council exists to stop malicious, coercive, or exploitative governance attacks against ENS DAO.
The original mandate, approved through EP 5.7, covered proposals that violate the ENS Constitution, deliberately threaten the DAO's long-term sustainability, are approved by voters who have been financially incentivized to act against the DAO, or exist primarily to benefit an attacker at the DAO's expense.
Controversial governance decisions fall outside this mandate. The council has no role in resolving ordinary disagreements over budgets, organizational structure, protocol direction, or DAO policy. Those decisions remain with delegates and token holders, even when the result is thoroughly debated.
Cancellation overrides the outcome of a completed vote, so the council can't use its power whenever its members oppose a proposal. The new council is intended to act only where one or more of the following emergency conditions apply:
(a) The proposal violates a specific article of the ENS Constitution.
(b) The proposal transfers treasury assets to an address controlled by a person or entity who obtained the right to receive the transfer through fraud, theft of governance credentials, exploited vulnerability in the proposal mechanism, or other unauthorized means.
(c) The proposal modifies, removes, or disables protocol-level smart contracts (root key control, registry control, smart contract upgrades, fee structures), and the DAO vote authorizing the proposal was procured through bribery, vote buying, or exploited flash loan, supported by documentary evidence published alongside the Council action.
(d) Either:
(i) the proposal was passed using voting power acquired through fraud, a flash loan, a short position, an undisclosed pre-coordinated token acquisition, a vote-buying arrangement, or other means not generally available to public market participants, and would not have had majority support without those acquired votes; or
(ii) the proposal transfers a significant portion of the treasury, endowment, or DAO-held ENS tokens to an account that is not accountable, technically or legally, to the ENS DAO for the use of the assets, except for reasonable compensation of services the DAO has previously authorized.
A proposal being controversial or unpopular would not, on its own, meet these conditions.
The new council operates under a more formal version of this mandate. Members must affirm a public charter, sign an Appointment Agreement with the ENS Foundation, and complete KYC and background checks. The new framework also provides a route for removing members who knowingly act outside their authority.
Governance gives a DAO the ability to make consequential decisions, including moving treasury assets and changing the contracts it controls. That same authority can become an attack surface if someone is able to manipulate a vote or conceal what a proposal will actually do.
There are several ways this can happen.
These patterns describe deliberate governance attacks. Legitimate governance changes authorized through the DAO's ordinary voting process, even when contested or unpopular, are outside this pattern and are matters for delegates and tokenholders to resolve.
In 2022, an attacker used a flash loan—a large loan borrowed and repaid within a single transaction—to temporarily gain enough voting power to control Beanstalk governance. The attacker passed proposals that transferred approximately $77 million in non-Beanstalk user assets to a wallet they controlled. The voting power only needed to exist long enough to approve and execute the proposals. Beanstalk later published an account of the exploit.
A more recent incident at BonkDAO showed that this remains a live concern. In July 2026, BonkDAO confirmed that a malicious governance proposal had drained an estimated $20 million in BONK from its treasury.
Tornado Cash faced a different type of governance attack in 2023. An attacker submitted a proposal containing a contract that appeared legitimate during review. After the proposal passed, the contract's behavior changed, allowing the attacker to take control of governance. A technical proof of concept demonstrates how the contract could change after approval.
This kind of attack can be difficult to catch through ordinary voting alone. Delegates may support the proposal described to them without realizing that its executable code contains another path.
ENS tokens must be delegated before they can participate in governance. The practical security of any vote depends on the tokens actively delegated and participating, not on the total ENS supply. Increasing delegation and voter participation makes acquired-vote attacks materially more difficult, more expensive, and less likely to succeed.
That defense is powerful but not complete on its own. It does not fully address scenarios involving borrowed voting power, undisclosed pre-coordinated token acquisitions, vote-buying arrangements, compromised credentials, or malicious proposal code. The Security Council provides an additional safeguard for those cases: a final check after a proposal has passed but before its transactions take effect. During the two-day waiting period, five council members can agree to cancel a proposal that meets the emergency conditions set out in the council's charter.
Giving eight people the ability to cancel a DAO vote creates another security problem: the council itself could be compromised or misuse its authority.
Several limits are intended to reduce that risk.
The new council requires five signatures for any cancellation, meaning a majority of its members must agree to intervene. Its contract can only cancel transactions waiting in the timelock. It has no ability to replace those transactions with something else or make a different decision on the DAO's behalf.
The authority is also time-limited. The new contract is scheduled to expire after two years. At that point, anyone can call a function that removes its cancellation power unless the DAO has already approved an extension through another governance proposal.
Members are bound by the public mandate they affirmed during the election and by their Appointment Agreements with the ENS Foundation. The new structure also gives the DAO a defined process for removing someone who knowingly acts outside that mandate.
These controls can't eliminate trust entirely. They make the council's role observable and difficult to expand without another DAO vote.
ENS DAO held a ranked-choice election under EP 6.50 to fill the eight seats.
Candidates had to show either a strong record of participation in ENS governance or professional experience relevant to the council's responsibilities, such as smart contract security, governance design, incident response, multisig operations, or applicable law. Each candidate also had to affirm the new charter before appearing on the ballot.
The members selected were:
- Nick Johnson (nick.eth)
- Hudson Jameson (hudson.eth)
- Pablo Sabbatella (pablito.eth)
- Colton Liberacki (coltron.eth)
- Kevin Gaspar (validator.eth)
- Alex Van de Sande (avsa.eth)
- Griff Green (griff.eth)
- Alex Netto (netto.eth)
The group includes long-standing ENS contributors and delegates alongside people with experience in operational security, incident response, multisig management, and security councils elsewhere in Ethereum.
The member election was completed first. ENS DAO has now also approved the executable proposal that handles the onchain implementation.
The proposal grants the required role in the ENS DAO TimelockController to a new Security Council contract. That contract is controlled by the elected members' five-of-eight multisig. It allows them to cancel a pending timelock operation and perform no other governance action.
The proposal implements the result of EP 6.50. It doesn't reopen the election or change the council's mandate.
The onchain vote has now concluded and passed. The new council's term will run until July 16, 2028.
The outgoing council's cancel authority expires on July 24, 2026. Activating the new council before then allows the two terms to overlap briefly, avoiding a period in which no Security Council can cancel a malicious proposal.
Most ENS proposals will pass or fail without any involvement from the Security Council. Delegates debate them, tokenholders vote, and successful proposals move through the timelock into execution.
The council becomes relevant in a far less ordinary situation: a malicious proposal has already won the vote, its transactions are queued, and the DAO has two days left to stop them.
Five members must agree to cancel it. The contract can't redirect the funds, rewrite the proposal, or substitute another outcome. Its cancellation role expires at the end of the term unless the DAO votes to extend it.
The members have already been chosen, and delegates have now approved the onchain proposal activating their emergency authority for the next two years.
This article explains the Security Council and the activation proposal recently approved by ENS DAO. It does not address other governance discussions, proposals, or debates in the community forum. Ordinary policy or organizational disagreements remain matters for delegates and tokenholders to resolve through the usual proposal and voting process.