An audit describes a protocol as it stood on the day it was audited. Whether it still holds while your capital is inside depends on a question no audit answers: who is allowed to change the code, how quickly, and what stands in the way.
Our institutional threat model for DeFi gives governance one category out of nine, and states it plainly: "Governance that can act instantly can also be captured instantly." This piece enlarges that square of the map. Most of the answers can be read off the chain rather than taken on trust.
The upgrade authority is a short, named list
Start with the smallest number in the system: the signatures it takes to change it. Aave's governance documentation names two emergency multisigs. A Protocol Emergency Guardian, "a 4 of 7 multi-signature wallet", holds the emergency admin role over protocol markets. A Governance Emergency Guardian, "a 5 of 9 multi-signature wallet", is authorised to veto an onchain payload deemed malicious, with signers drawn from organisations including Zapper, Paraswap, Standard Crypto, Balancer, Lido and Certora. Lido publishes its own, including a 3-of-6 CircuitBreaker Committee able to pause designated core contracts for a bounded duration without waiting for a DAO vote.
Where documentation is thinner, read the contract. The Arbitrum Security Council Safe on Ethereum, 0xF06E95eF589D9c38af242a8AAee8375f14023F85, returned a threshold of 9 against an owner set of 12 when read live on 9 September 2026. Arbitrum's Constitution describes the same body as "a committee of 12 members who are signers of a multi-sig wallet", states that "performing any Emergency Action requires a 9-of-12 approval", and gives it power to "execute any software upgrade or perform other required actions with no delay".
Nine signatures, no waiting period. That is not a defect. It is a trade-off between response speed and unilateral power. The diligence question is whether you priced it, and whether the holders are independent in the ways that matter: separate organisations, separate signing devices and channels, no single vendor able to reach quorum alone.
A timelock is a notice period, and its length is a public integer
A timelock turns an approved change into a scheduled one, and the interval is the window in which anyone who disagrees can leave. Read from Ethereum mainnet on 9 September 2026: Uniswap's Timelock at 0x1a9C8182C09F50C8318d769245beA52c32BE35BC returns a delay of 172,800 seconds, exactly two days. Compound's returns the same. The ENS TimelockController returns a two-day minimum.
Not everything moves at one speed. Aave documents two executors, routing classes of change to a delay of "either one day or 7 days". Arbitrum spreads the idea across two chains: an L2 waiting period of three days for treasury actions and eight for an L2-to-L1 message, a three-day L1 waiting period, and the rollup challenge period in between. Its Constitution says a Constitutional proposal "will typically require at least 42 days from the beginning of the temperature check in Phase 1 until an AIP is finally executed in Phase 7".
A short timelock means short notice, not carelessness, and a long one is not free. In October 2021 Compound took seven days to ship the fix to a Comptroller upgrade whose distribution bug let users claim roughly $70 million in COMP: two days of review, three of voting and two more of timelock. Cointelegraph reported that the seven-day delay let a malicious entity exploit the same function and move $68.8 million out of the reservoir while the remedy waited. The delay that protects you from a hostile change also stops a protocol correcting its own error.
Some designs make the delay conditional on opposition. Lido describes its Dual Governance as "a dynamic timelock". Once stETH locked in the veto signalling escrow crosses 1% of Lido-on-Ethereum TVL the wait starts to grow, "from five extra days at 1% to a maximum of 45 days at 10%", and at that second seal a rage quit blocks execution until the locked stake has been withdrawn to ETH. That is control design, distinct from the yield question in institutional staking risk and reward.
The nearest published external benchmark is L2BEAT's Stage framework, which is research, not regulation. Stage 1 turns on one test: the only way to indefinitely block or push an invalid L2 to L1 message should be by compromising at least 75% of the Security Council, and upgrades initiated outside it are allowed only if they provide at least a seven-day exit window. Stage 2 adds a fraud proof system open to anyone rather than an allowlist, and at least 30 days to exit "in case of unwanted upgrades, including upgrades initiated by a DAO". On 9 September 2026, Base, Arbitrum One and OP Mainnet were all at Stage 1, and the Stage 2 list held Aztec, Facet, Ethscriptions and a Cartesi honeypot.
Voting concentration, and measuring the right object
Thresholds and delays describe the mechanism; concentration describes who can operate it. Uniswap's GovernorBravo returns a proposal threshold of 1,000,000 UNI, a voting period of 40,320 blocks or roughly 5.6 days, and a quorum of 40,000,000 UNI, 4% of the one billion supply. Compound's returns 25,000 COMP to propose and 400,000 for quorum. Those are the position sizes needed to propose, and to carry a proposal.
Measuring who holds that size is where methodology decides the answer. A study published in Frontiers in Blockchain on 5 August 2026 audited 52 token protocols from holder snapshots taken March–May 2026, computing a Herfindahl-Hirschman Index over the top 1,000 holders. The decisive step was subtraction: removing 133 protocol-controlled addresses across 38 protocols, plus 64 labelled centralised exchange deposit wallets, meaning staking contracts, treasuries and bridge custody. Skipping those exclusions inflated concentration by a median factor of 2.3, and at the extreme by roughly 18. Post-exclusion, measured concentration ran from about 0.005 at the dispersed end, where Hyperliquid, Bittensor and Lido sat, to 0.199 at the top, where Livepeer sat.
Two findings matter here. Initial insider allocation, the number most token reports lead with, was uninformative about current concentration, at a Pearson correlation of 0.09; current insider wallet retention was associated with it, at a Spearman rho of 0.44. Read the wallets as they stand, not the vesting chart from three years ago. On whether concentration matters commercially, ECGI Finance Working Paper 1119/2025 covers 570 DAOs that sponsored Snapshot proposals between July 2020 and September 2024, and reports that a one standard deviation increase in the concentration of voting power is associated with a 3.9 percentage point fall in weekly TVL growth. The authors present that as a correlation and then use airdrops as shocks to token distribution to push towards causality, which is an identification claim worth reading before you lean on the number.
Delegation and turnout decide most votes
Holdings are not votes. The same Frontiers study measured voting concentration separately for 18 protocols across Tally, Snapshot and Solana on-chain governance, and found delegation amplified concentration relative to holdings in 13 of the 18, by factors from 2.45 for Gnosis to 25.65 for Polkadot. Five dispersed instead, among them ENS at 0.48 and Jupiter at 0.12, the widest dispersion in the sample. Livepeer appears in both lists, the most concentrated protocol by holdings and a disperser once delegation is applied, which is the sharpest argument in the paper for measuring both rather than either. Delegation is a design variable, not a direction of travel.
Participation has a ceiling. A 2026 preprint covering 680 DAO-quarter observations across 135 DAOs, over ten quarters ending in the third quarter of 2022, estimated a capacity breakpoint at roughly 9.4 proposals per DAO-quarter: below it, participation rose with proposal count at a slope of 1.104; above it, at 0.601, about a 46% fall in responsiveness. That is reduced-form evidence on an ageing sample, with imprecise cutoffs. The implication still holds: governance throughput and governance attention are not the same resource, and a crowded calendar hands power to whoever is always watching.
Four cases fail in four different places. Beanstalk, 16 April 2022, $182 million lost: the emergencyCommit function read voting power at the instant of execution rather than from a historical snapshot, so an attacker could flash-loan over $1 billion, convert through Curve into whitelisted deposits, reach around 79% of staked voting weight and execute in one transaction. Borrowed capital parked for seconds was indistinguishable from stake held for months, which the Veridise analysis calls "not a mistyped line but a design that never priced in a hostile whale". Tornado Cash, 20 May 2023: a proposal presented as identical to an approved upgrade carried an extra function, which on passage granted the attacker 1.2 million fraudulent votes, and 483,000 TORN was taken from the vault. The voted artefact and the executed artefact were not the same code. Compound Proposal 289, 28 July 2024: a proposal moving 499,000 COMP, roughly $24 million, into a yield product controlled by its proposers passed 682,191 to 633,636 over the objection of the DAO's own contributors. Nothing was exploited; the mechanism worked as specified. BonkDAO, 6 July 2026, roughly $20 million drained by vote: seven addresses voted at all, and wallets controlled by the attacker held about 99.878% of the voting weight. The reported diagnosis names three absences, no meaningful quorum, no timelock long enough for anyone to notice and react, and no multisignature check on large treasury movements.
Foundation, labs company and DAO are three counterparties
These three are routinely spoken of as one, and they carry different balance sheets, jurisdictions and liability. The Uniswap Foundation's proposal of 11 August 2025 would wrap Uniswap Governance, which is neither the Foundation that proposed it nor Uniswap Labs, in a Wyoming DUNA, on the argument that doing so "would also reduce the potential specter of unlimited liability for participants".
This is not theoretical. On 8 June 2023 a United States district court entered default judgment for the CFTC against Ooki DAO, determining that the DAO is a "person" under the Commodity Exchange Act and imposing $643,542 in civil monetary penalties alongside permanent trading and registration bans. a16z crypto, which advocates the wrapper, notes that regulatory actions and class action lawsuits in the United States "have alleged that without a legal entity, a DAO is just a general partnership".
Two wrappers answer that. Wyoming's Decentralized Unincorporated Nonprofit Association Act, effective 1 July 2024, defines a DUNA as an unincorporated nonprofit association that "consists of at least one hundred (100) members", and provides that it "is a legal entity separate from its members for the purposes of determining and enforcing rights, duties and liabilities in contract and tort". The Cayman foundation company reaches a similar shield from the other direction, holding legal personality that lets it contract, hold assets and sue, while being capable of operating without shareholders and without members. Location is live: the ECGI sample found nearly 48% of the DAOs studied had no physical headquarters at all. Ask which legal person signs, in which jurisdiction, and who indemnifies you when it does not perform. It is the protocol-layer version of the custody question in who actually holds it.
No regulator has put a number on "sufficiently decentralised"
Status matters, on the discipline we used in what regulators actually permitted in 2026: a consultation question is not a rule, and a bill through one chamber is not law. On 21 February 2025 SEC Commissioner Hester Peirce asked whether the Commission "should define objective quantitative thresholds (such as percentage thresholds for ownership and control)" so third parties could verify whether a network is sufficiently decentralised. Eighteen months later, on 18 August 2026, the SEC proposed Regulation Crypto Assets, including a conditional safe harbour from the term "investment contract" available once an issuer "has completed or permanently ceased all essential managerial efforts that it represented or promised it would take". Sullivan & Cromwell reads the proposal as declining to fix a standard, with decentralisation judged on "how the issuer defined or otherwise described these terms, not a general market conception". Comments run for 60 days from publication in the Federal Register.
Europe asked the same question in the open, and that window has closed. The Commission's targeted consultation on the MiCA review, which took responses until 31 August 2026, asked which criteria should be used to assess "the degree of decentralisation", and the candidate list reads like a diligence checklist: an identifiable intermediary, control by an identifiable person or group "e.g. via admin keys" over key functionalities such as upgradeability, significant concentration of governance power, custody of user assets, and code that is not open source. IOSCO got there earlier by another route, publishing final policy recommendations for decentralised finance on 19 December 2023 addressed to market integrity and investor protection.
Legislation has drafted the only numbers, and it is not law. The CLARITY Act, passed by the House of Representatives on 17 July 2025 and not by the Senate, defines a "mature blockchain system" as one "not controlled by any person or group of persons under common control", which on its face sets no percentage. The criteria for establishing that condition do. Its system governance test fails if any person or group under common control "has the unilateral authority to direct the voting, in the aggregate, of 20 percent or more of the outstanding voting power" of the system, and its distributed ownership test requires that "no digital commodity issuer, digital commodity related person, or digital commodity affiliated person beneficially owns, in the aggregate, 20 percent or more of the total amount of units of the digital commodity". Twenty percent, twice, in a bill that has cleared one chamber. No regulator has adopted a figure, so the concentration limit binding on you is still the one written into your own mandate.
What the Paris programme showed, and what it did not
An honest note on our own record. Across the 77 sessions of the archived Paris edition at the Louvre Palace on 2–3 June 2026, no title contained the words governance, DAO or upgrade. The closest by name, "Banks, Exchanges, and Asset Managers: Who Controls Institutional Access When Markets Move Onchain?", ran on the Hecto Main Stage on day one with Amy Oldenburg of Morgan Stanley, Alex Kim of Upbit Global and Matthew Sigel of VanEck, moderated by Frank Chaparro of GSR. It was about control of market access, a different question from who holds an upgrade key.
What the programme did do was put the people who hold, build and audit these controls on stage without naming the control question. Stani Kulechov of Aave Labs spoke on "Aave V4: Scaling Onchain Lending", moderated by Jacquelyn Melinek, at a protocol whose one-day and seven-day executor delays are published. Jorgen Ouaknine appeared for the Canton Foundation board in "Building Canton: A Conversation with the Foundation Board", also moderated by Jacquelyn Melinek, the only title in the programme naming the legal-entity layer of protocol control. "DeFi Under Attack: Securing Onchain Finance and the Machine Economy" brought Kostas Chalkias of Mysten Labs, Charles Guillemet of Ledger, Rodrigo Coelho of Edge & Node and Jason Jiang of CertiK to the Hecto Main Stage, moderated by Nikola Stojanow of Bank Frick. Jacob Steeves of Bittensor spoke in a fireside moderated by Mark Jeffrey. The record sits on the sessions index and agenda. The gap between who was in the room and what was asked from the stage is one we would rather close than paper over.
The sequence a diligence team can run this week
- Enumerate every contract the position touches and record the owner or proxy admin of each.
- For every multisig on it, record threshold and owner set from the chain, map owners to legal entities, and flag repeats.
- Record the delay on every timelock in seconds, and reconcile it against the published constitution.
- Compute the top-three share of realised voting power over twelve months, excluding protocol and exchange addresses.
- Establish whether voting power is snapshot-based or live-balance, and whether the executed payload is verifiably the voted one.
- Name the legal counterparty, its jurisdiction and its indemnity, and confirm what emergency powers exist outside the vote entirely.
Every value here is public and can be re-checked next quarter, when several will have moved. Governance is not a static attribute but a set of live parameters, and a diligence file should carry a date against each.
The next edition is the inaugural Gulf edition at the Louvre Abu Dhabi, Saadiyat Cultural District, on 3–4 December 2026, capped at 2,000, admission by application and review, no paid speaking slot. Details at Proof of Talk Abu Dhabi, applications at request access.