论去中心化自治组织中治理权力的行使
On Exercising Governance Power in Decentralized Autonomous Organizations
浏览论文内容
中文总结 AI 辅助
本研究分析48个基于以太坊的DAO,阐明其治理合约设计的信任与透明度权衡,揭示新型治理攻击,为DAO安全设计提供参考。
中文摘要 AI 辅助
去中心化自治组织(DAO)是一种治理实体,允许其利益相关者通过智能合约管理基于区块链的协议。DAO在智能合约中明确规定了利益相关者如何制定和执行与协议运营相关的决策,该智能合约被恰当地称为其治理合约。因此,治理合约的设计对DAO及其利益相关者管理的智能合约的安全性(信任)和隐私性(透明度)具有深远影响。本研究中,我们(i)阐明了DAO实现过程中设计选择的信任与透明度权衡,(ii)通过实际案例研究强调了不当选择如何引入关键漏洞。为此,我们分析了48个公开且活跃使用的基于以太坊的DAO,这些DAO控制着巨额资金。我们将设计选择归类为少数关键维度,这些维度简洁地体现了DAO利益相关者如何发起协议变更、对其投票,并根据投票结果执行变更。我们的分析关键地揭示了一类新型攻击,我们称之为治理攻击,这类攻击即使在假设实现无bug的情况下,也会直接利用DAO治理机制的基本设计。
英文摘要
A decentralized autonomous organization (DAO) is a governance entity that allows its stakeholders to manage blockchain-based protocols through smart contracts. The DAO explicitly specifies how stakeholders make and enforce decisions concerning a protocol's operation in a smart contract, aptly referred to as its governance contract. The design of this governance contract, therefore, has far-reaching implications for the security (trust) and privacy (transparency) of the smart contracts managed by the DAO and its stakeholders. In this work, we (i) explicate the trust and transparency trade-offs of the design choices in implementing a DAO and (ii) highlight how poor choices introduce critical vulnerabilities, using real-world examples as case studies. To this end, we analyze $48$ public, actively used Ethereum-based DAOs that control a vast capital. We classify the design choices into a handful of key dimensions that succinctly capture how a DAO's stakeholders initiate a protocol change, vote on it, and, based on the voting outcome, execute that change. Our analyses crucially uncover a new class of attacks, which we call governance attacks, that directly exploit the fundamental design of a DAO's governance mechanisms, even if we assume bug-free implementations.