Unlike Meta, where Mark Zuckerberg maintains significant voting control due to its dual-class share structure, decentralized autonomous organizations (DAOs) often operate on a one-token, one-vote basis. This vulnerability was recently exposed when a large token holder, known as Humpy, and his affiliate group, the GoldenBoys, allocated $24 million worth of COMP tokens to a yield-bearing protocol called goldCOMP. The incident has been described as a governance attack, with some attributing it to voter apathy. However, OpenZeppelin, a security audit firm engaged with Compound's DAO, views it as an exploit of the governance model itself.
According to Michael Lewellen, OpenZeppelin's head of solutions architecture, token holder-dominant governance models are susceptible to such exploits. Lewellen emphasizes the need for checks on token holders and the introduction of accountability without compromising privacy, potentially through know-your-customer initiatives and zero-knowledge cryptography. To prevent similar incidents, Lewellen recommends that DAOs engage in threat modeling exercises, incentivize responsible token holder behavior, and adopt governance models that balance decentralization with safeguards for long-term sustainability.
Ultimately, DAOs may need to structure their governance more like traditional corporations, such as Meta, to ensure the secure and informed management of user funds and protocol security.