Compound operates as a crypto lending protocol overseen by holders who delegate their COMP tokens, a structure widely recognized as a decentralized autonomous organization, or DAO. The system functions like an online republic, where token holders debate proposals, cast votes, and rely on software to execute the outcomes.
In July 2024, this digital republic came close to transferring a substantial sum to a small group of voters. Proposal 289 requested that Compound move 499,000 COMP tokens, valued at approximately $24 million at the time, into a yield-generating vehicle controlled by those voters. Two earlier iterations of the proposal had failed, and the third appeared to be heading toward another rejection.
However, during the final 34 minutes of voting, addresses supporting the proposal cast 563,591 votes, representing 82% of all support for the measure. The last major voting block arrived eight minutes before the deadline, and the proposal ultimately passed with 682,191 votes in favor against 633,636 opposed.
While the outcome sparked significant controversy and remains contested, the underlying code performed exactly as designed.
Yet this was precisely the issue: the participating wallets had accumulated sufficient COMP and delegated their voting power before the voting window closed, but Compound lacked any emergency mechanism capable of pausing the software. Several individually reasonable rules had aligned to create a viable path for draining the treasury.
Compound eventually reached a settlement that nullified the allocation and subsequently introduced a veto role, effectively installing a brake within a system originally designed around automatic token-holder governance.
This scenario illustrates the fundamental DAO dilemma, as most defenses against rushed or hostile governance actions inevitably grant someone additional control over participation or final outcomes.
Two 2026 studies conducted by the Max Planck Institute for Software Systems and Vrije Universiteit Amsterdam identified similar patterns across 48 major Ethereum DAOs. One study examined how registration, staking, and delegation concentrate voting power, while the other catalogued attacks executed through legitimate governance procedures.
Governance Thresholds Shape Participation
Describing a governance token as a straightforward vote oversimplifies the reality. Depending on the specific DAO, a holder may need to register a wallet, lock tokens, delegate them, maintain a minimum balance, or pay for an on-chain transaction before actually casting a vote.
Proposals themselves encounter barriers, since advancing an idea typically requires sufficient tokens or delegated backing, and the proposal may need to pass through a forum discussion and informal poll before reaching a binding vote either on the blockchain or via an off-chain platform like Snapshot.
Once a proposal clears the required quorum and approval thresholds, a smart contract, multisignature wallet, or designated individual carries the decision into effect.
Although each of these checkpoints addresses legitimate concerns, they inherently advantage particular participants or categories of participants.
Proposal thresholds discourage spam and malicious code, but they simultaneously reserve proposal authorship for wealthy holders and established delegates. On-chain voting ensures enforceable outcomes, yet transaction fees favor those with sufficient capital and conviction to participate. Free off-chain polls attract broader engagement but ultimately depend on a smaller group for execution.
The researchers observed an even distribution: 24 DAOs employed on-chain voting while 24 utilized off-chain systems.
Uniswap demonstrated how distinct electorates can emerge within a single organization: more wallets participated in its free off-chain polls, while substantially larger concentrations of voting power materialized during the paid on-chain phase where proposals could become binding.
Turnout represents only a small piece of this dynamic, since a protocol may have thousands of token holders while a handful of addresses control proposals, votes, and execution. By the time public results appear, the rules have already determined the electorate.
Security Mechanisms Concentrate Influence
DAOs frequently store tokens in treasury contracts, and founding teams or investors may hold allocations that have not yet vested, making registration useful for separating circulating tokens from balances that currently carry voting rights.
Among the 48 DAOs examined, 36 required some form of registration, and only four had registered more than half of their total outstanding supply. Across those 36 organizations, the average registered share was just 21%, indicating that the practical electorate typically represented a small fraction of all tokens.
A significant portion of the unregistered supply belonged to users whose coins were custodied by exchanges or deposited into DeFi protocols. Centralized exchanges held more than 10% of outstanding tokens on average across the sample, while DeFi contracts held an additional 3.5%.
In 14 registration-based DAOs, these intermediary wallets controlled more tokens than the entire registered electorate.
This creates a distinctive custody challenge, since an exchange wallet can represent thousands of customers while the blockchain recognizes only a single address with one large balance.
Permitting the exchange to vote elevates a custodian into a political heavyweight, whereas excluding it deprives customers of governance rights attached to tokens they legitimately own. Most DAOs also allow a single wallet to transfer all its voting power to one delegate, making it difficult to split votes among the underlying beneficial owners.
Staking addresses a different vulnerability by increasing the cost and time required to build voting power. A potential attacker might purchase or borrow a substantial position, approve a favorable proposal, and sell once the vote concludes, while a lockup requirement keeps that voter financially exposed to the outcome for an extended period.
Fifteen DAOs required staking, with a median of 27.4% of tokens locked. Some imposed withdrawal waiting periods of one or two weeks, while Curve, Angle, and Frax offered enhanced voting power for lockups extending up to four years. The system rewards patience and transforms liquid wealth into a prerequisite for meaningful political influence.
The crypto ecosystem subsequently developed intermediaries for individuals seeking influence combined with trading flexibility. These services maintain extended lockups, issue tradable substitute tokens, and retain the original voting rights. According to the researchers’ measurements, this arrangement concentrated substantial voting blocs within a few services:
| DAO | Service controlling the votes | Share of voting power | Maximum native lock |
|---|---|---|---|
| Curve | Convex | 53% | 4 years |
| Frax | Convex | 46% | 4 years |
| Angle | StakeDAO | 57% | 4 years |
| Balancer | Aura | 65% | 1 year |
Delegation operates similarly because most holders have limited interest in engaging in forum debates about collateral ratios. Entrusting votes to a professional participant is practical, and repeated delegation establishes enduring political blocs.
The ten largest holders controlled more than half of voting power in 39 of the 48 DAOs, while delegated voting typically proved more concentrated than direct voting.
Registration protects treasury balances, staking increases the cost of rapid attacks, and delegation provides passive holders representation through engaged participants. Combined, these mechanisms ensure that individuals with the most capital, time, technical expertise, or control over customer assets tend to govern the organization.
Legitimate DAO Votes Can Still Constitute Raids
The second paper defines a governance attack as an actor employing the authorized process to achieve an outcome that damages the broader organization.
Among 28 DAO incidents, researchers classified 16 as attacks that an alternative mechanism could have prevented. Six involved contract vulnerabilities, while ten relied on acquiring or borrowing sufficient tokens to influence a vote.
Compound represents the clearest example, as the wallets associated with Proposal 289 accumulated more than 680,000 COMP over four months.
Researchers traced 563,790 tokens through four centralized exchanges and an additional 118,089 borrowed through Compound itself, despite those addresses having held only 853 COMP before the buildup and having minimal prior involvement in the protocol’s governance.

The late-stage voting surge exploited a community that anticipated the third proposal’s failure. Compound could have extended the voting period when a large bloc appeared near the deadline, required longer staking durations, or authorized a trusted council to pause execution.
Each alternative would have shifted power toward reactive voters, committed holders, locking services, or a small emergency body.
Compound ultimately selected the emergency brake approach, and among the 2024 configurations researchers reviewed, seven other DAOs shared similar exposure to readily available voting power and late-stage vote accumulation: Uniswap, Radicle, Gitcoin, Silo, Ampleforth, Hop, and Cryptex.
These systems can evolve through governance, meaning this list reflects a specific moment in 2024, and a current security assessment would require fresh analysis.
Meaningful decentralization demands more sophisticated measurement than token distribution alone. A comprehensive governance report would detail how much supply can actually vote, how much power the largest delegates wield, which intermediaries hold staked tokens, and who possesses the ability to introduce, execute, or veto proposals.
Smart contract audits already evaluate whether governance code adheres to its specification, while a constitutional audit would examine where that specification ultimately directs authority.
DAOs can distribute ownership across thousands of wallets while simultaneously channeling practical control toward a few dozen professionals, custodians, and large holders, all while the underlying software executes flawlessly throughout the process.

