TL;DR
- ENS DAO activated a new eight-member Security Council with authority to cancel malicious governance proposals before their execution.
- The council operates through a five-of-eight multisig wallet and will remain active until July 16, 2028, when its mandate expires.
- Members include ENS founder Nick Johnson, Hudson Jameson, Alex Van de Sande, and Griff Green, among others.
The Ethereum Name Service (ENS) DAO formally activated a Security Council composed of eight members with deliberately limited authority to intervene against malicious governance proposals.
The measure aims to shield the protocol against attacks that, after gaining majority support through fraud or manipulation, manage to advance to the stage immediately before execution. The activation of the Security Council was the result of a ranked-choice election that determined the group’s final composition.
The council does not function as a parallel governance body. It can only act during the two-day waiting period —known as the timelock— that separates the approval of a proposal from its on-chain execution.
ENS DAO has approved the proposal activating its new Security Council for the next two years.
The council is an eight-member group with veto power to cancel a malicious proposal after it passes, but before it executes.
Here’s how it works ↓ pic.twitter.com/JsrbnpsQFc
— ens.eth (@ensdomains) July 20, 2026
Its only available tool is cancellation, and it can only exercise it against transactions involving fraud, bribery, vote buying, manipulation through flash loans, compromised credentials, or other documented forms of coercion. Ordinary decisions on budget, protocol policy, or organizational structure fall outside its scope, even when the vote is controversial.
ENS Security Council: The Limits of Action
The council’s architecture is designed to maximize transparency and minimize the risk of internal abuse. Unlike the outgoing council, which required four signatures from eight members, the new threshold demands five of eight approvals for any intervention, making it harder for a minority within the council itself to exercise a veto unilaterally.
Each member must publicly sign the council’s charter, execute a designation agreement with the ENS Foundation, and undergo identity and background checks.
Its term is limited to July 16, 2028, a feature that is central to the design. If the DAO does not explicitly approve an extension through a new on-chain vote, the council’s authority expires automatically. The outgoing council’s authority expires on July 24, 2026, creating a brief overlap that will prevent any protection gap.
The Reason Behind the New Council
The most cited precedent to justify this type of structure was the Beanstalk attack in 2022, when a malicious actor used borrowed voting power to approve fraudulent proposals and withdraw approximately $77 million in assets. ENS also documented cases in which the code of legitimate proposals concealed dangerous functionalities that only activated after approval.







