[Draft] [Executable] Next Era of ENS DAO: Empowering the ENS Foundation

[Draft] [Executable] Next Era of ENS DAO: Empowering the ENS Foundation

Status Active
Votes Cactus
Author katherine.eth
Temp check [Temp Check] Next Era of ENS DAO: Empowering the ENS Foundation

Abstract

This executable proposal establishes the ENS Foundation as an operating foundation, led by a full-time Executive Director and staff, and governed by a five-seat board ratified by the DAO, as set out in the temp check posted June 19. It follows public discussion of that temp check and tightens the scope of the Foundation’s mandate in several areas in response to community feedback: the DAO’s ENS tokens stay under tokenholder control, the operational wallet stays where it is, and Endowment transactions gain a timelock with Security Council oversight.

Main changes from Temp Check in detail:

(1) ENS tokens stay exactly where they sit today, under the same onchain mechanism and the same tokenholder control they are subject to now, and this proposal transfers no general authority over them. There is one exception: a single transfer of 1,000,000 ENS, restricted to Foundation employee compensation to support the Foundation in funding future employee compensation as the Foundation matures. Any future use of DAO-held tokens beyond this transfer, including for ecosystem programs, will be decided by the DAO as its own proposal through the standard governance process.

(2) The operational wallet (wallet.ensdao.eth, approximately $16 million in ETH and stablecoins as of July 2026), which the temp check proposed delegating, stays with the DAO in its current place, with existing streams continuing to draw from it.

(3) Treasury management is implemented with a dedicated security layer: the Foundation Board, acting through approved signers, assumes administrative control of the Endowment Safe (endowment.ensdao.eth, approximately $65 million in ETH and stablecoins as of July 2026), with all Endowment transactions passing through a timelock by default, and an ability for the Security Council to cancel any timelocked transaction.

Tokenholders will retain protocol control along with the authority over appointment and removal of Foundation directors. Every modification made from the original temp check moved in the direction of was done in consideration of maintaining tokenholder control and security.

This proposal addresses Foundation governance and operational stewardship only. It does not transfer protocol control. For clarity, Foundation governance means the Cayman foundation company’s board, Executive Director, staffing, grants administration, budget process, and Endowment stewardship. DAO governance means the public forum process, temp checks, Snapshot votes, executable proposals, delegation, and tokenholder voting. Protocol control means smart contract upgrades, ENS pricing and fee structures, root key and registry control, DAO-held ENS tokens, constitutional amendments, and director appointment, renewal, and removal. Protocol control remains exclusively with ENS tokenholders.

Motivation

The full problem statement, the research on comparable open-source foundations, and the reasoning behind this structure are in the temp check and its discussion thread. Onchain tokenholder governance is best suited for protocol-level decisions, constitutional authority, director appointment and removal, and other matters requiring broad legitimacy. Day-to-day operations, budgeting, staff management, grants administration, policy engagement, and vendor oversight require accountable execution within a legal entity that remains answerable to tokenholders. This proposal maintains protocol control, ENS tokens, and director appointment and removal with tokenholders, and moves operational and budgetary stewardship into a Foundation that remains structurally accountable to the DAO.

For the sake of clarity, ENS Labs remains a separate Singapore-based entity with its own leadership and board. Participation by ENS Labs personnel in developing this proposal does not grant ENS Labs any governance right over the Foundation, the Endowment, DAO-held ENS tokens, protocol upgrades, fee structures, or director appointment and removal.

The Foundation Structure

The ENS Foundation becomes a fully operational foundation, led by a full-time Executive Director and staff, stewarding the ENS mission and values. The Foundation will hold the ENS trademarks, brand assets, and other intellectual property. ENS Labs continues to operate independently under its own leadership and its own board, with the Foundation licensing the ENS trademarks to Labs and funding Labs through the existing grant relationship. The Foundation is responsible for its mission, grants program, and stewardship of the protocol’s revenue and Endowment.

The Foundation represents ENS where policy and standards are made: active participation in ICANN, IETF, W3C, and adjacent forums, pursuit of recognition and stewardship of the .ens TLD at ICANN, regulatory engagement on policy questions affecting ENS and decentralized naming, the institutional and legal-process counterparty role for the protocol layer, and trademark and brand enforcement. The full advocacy mandate is described in the temp check. Staffing needs will be projected once the Foundation is stood up, and job applications will be made public.

Protocol Control Remains with Tokenholders

Protocol control such as smart contract upgrades, ENS pricing and fee structures, root key and registry control, the DAO’s ENS tokens, and constitutional amendments remain exclusively with tokenholders. The Foundation has no role in protocol governance decisions. Director appointment, term renewal, and removal also remain with tokenholders, under the Foundation’s Articles of Association, unchanged by this proposal.

Foundation Leadership and Board

The Foundation Board has five voting seats:

  • One voting seat for the Founder of ENS, Nick Johnson, with succession to a designated ENS Labs representative in the event of the Founder’s resignation or departure from the Board.
  • One voting seat for the Foundation’s Executive Director.
  • Three voting seats for independent directors.

The Executive Director (ED) is a full-time Foundation employee and voting Board member who leads Foundation operations and the grants program, with day-to-day authority subject to Board oversight, approved budgets, conflict-of-interest requirements, and the onchain controls in this proposal. The ED cannot unilaterally transfer Endowment assets, alter protocol control or ENS token permissions, or bind the Foundation outside approved authority. The Board holds exclusive authority over the ED’s employment, with compensation set annually by the three independent directors, the ED and Founder recused. Independent directors serve two-year terms renewable by the DAO and are compensated at 40,000 USDC per year, donated to a non-profit or public good of their choosing if declined.

Following a search process led by the existing ENS Foundation Board with input from ENS Labs leadership, the proposed inaugural slate is:

  • Executive Director: Alexander Urbelis
  • Director: Nick Johnson
  • Independent Director: Kartik Talwar
  • Independent Director: Brett Sun
  • Independent Director: Anthony Leutenegger

Bios for each nominee, including baseline disclosure of material affiliations requiring recusal, are in the temp check.

Furthermore, this proposal adds a documented process for exercising Director removal authority so that removal is legible and follows a clear process. The Foundation’s bylaws will set out a standard process for tokenholder removal petitions: (i) a petition states the grounds for removal with supporting evidence; (ii) the petition is filed with the Foundation Board, which has a defined window to respond before a tokenholder vote is called; (iii) a 30-day period applies between petition and vote; and (iv) the director under petition may publish a written defense alongside the petition. These steps are designed to create notice, a documented record, and a fair opportunity to respond. They do not condition or limit tokenholders’ removal authority under the Foundation’s Articles: a removal vote validly conducted under the Articles is effective whether or not this process was followed, and no Board action or inaction under this process can delay or prevent it.

Conflicts of Interest

The Foundation will adopt, as Exhibit A to this proposal, an interim Conflict of Interest Policy effective upon adoption of this proposal. The interim policy requires written disclosure of actual and potential conflicts, recusal from deliberations and votes where appropriate, public recording of disclosures and recusals, and independent-director approval for ENS Labs funding. Within 90 days, the Executive Director will present a refined policy for Board approval and public publication.

Revenue and Treasury

Stewardship of the DAO’s operating capital, meaning the Endowment and the Endowment Manager relationship, is delegated to Foundation governance consistent with Article III of the DAO Constitution. This proposal changes administrative control of the existing Endowment Safe so the Foundation Board, acting through approved signers and subject to the timelock and Security Council cancellation right described below, oversees execution of Endowment transactions. This means no ETH or stablecoins are transferred by this proposal; the assets remain in the existing Endowment Safe at the same address.

Alongside this change, a timelock is added to all Endowment transactions by default, and the Security Council can cancel any timelocked transaction. The Security Council cancellation right is included as a technical safeguard against unauthorized, erroneous, malicious, or mandate-inconsistent Endowment transactions. It is not a general governance veto over Foundation policy, Board judgment, approved budgets, or ordinary implementation of a ratified DAO proposal. The Security Council’s cancellation function over Endowment transactions is conferred by this proposal and the Safe configuration, and does not amend the Security Council Charter.

The Endowment Manager’s existing investment-management permissions remain unchanged. Any permission to transfer funds from the Endowment Safe to the Foundation multisig without timelock will be limited to approved budget funding and subject to recipient restrictions, Board approval, public reporting, and any technical controls specified in the Transactions section. The Foundation will not receive any general, uncapped, or discretionary non-timelocked withdrawal authority. The DAO operational wallet remains in its current place, with existing streams continuing to draw from it.

The Foundation will receive no operating funding under this proposal until the Executive Director has presented a projected budget to the Board and a high-level version has been published to the DAO forum. Pending that publication, aggregate transfers from the Endowment to the Foundation may not exceed USD 500,000, covering standup costs only. The first annual budget will be published within 60 days of adoption, and annual Foundation spending thereafter is bounded by the published budget.

The ~54.6 million ENS tokens the DAO owns stay under the existing onchain mechanism and tokenholder control. The single exception is the 1,000,000 ENS transfer for Foundation employee compensation, administered under a Board-approved compensation framework published before any grant is made: multi-year vesting, independent-director approval for any grant to the ED or a director, annual public reporting of aggregate token compensation, and reversion to the DAO treasury of any tokens ungranted at wind-down or recalled by DAO vote. Pending grants, the tokens will not be voted, delegated, lent, pledged, transferred to ENS Labs, or used to compensate ENS Labs personnel. Any other use of DAO-held tokens comes to the DAO as its own proposal through the ordinary governance process.

For the avoidance of doubt, this proposal does not transfer beneficial ownership of ETH, stablecoins, or DAO-held ENS tokens to any director, officer, employee, ENS Labs, or other private party. The Endowment remains dedicated to the ENS mission and subject to the Foundation’s obligations, approved budgets, reporting commitments, technical controls, and tokenholder-retained protocol authority.

Grants & Working Group Transition

Any grant-making is consolidated under the Foundation’s Grants program, focused on public goods and core infrastructure benefiting the ENS protocol and the broader Ethereum ecosystem. The Foundation works alongside the SPP Committee on SPP3, and going forward, SPP is absorbed into the Grants program, and reporting requirements for SPP recipients do not change. Existing stewards, active streams, and current-term commitments are honored through their natural conclusion, with a transition plan covering SPP3 disbursements, Endowment Manager continuity, and the working group wind-down developed collaboratively with all parties once the Foundation is stood up. No existing stream, award, or current-term commitment may be reduced, paused, or re-conditioned except per its own terms or with the recipient’s consent.

Specification

The only ENS token transaction in this proposal is a single one-time transfer of 1,000,000 ENS to the Foundation, restricted to Foundation employee compensation. No other transaction moves, delegates, or re-permissions ENS tokens held by the DAO.

Transactions

Edited 08/03/2026 to add in contract addresses:

We’ve deployed new instances of two existing audited contracts:

  • OpenZeppelin’s Timelock Controller to 0x0bcC3dA6aD796F59288C0961602675E88A2B406C
  • Blockful’s Security Council to 0x0A9387643ce6291f8C545286675D76bCd0Ba3EdD

The new Security Council contract is owned by the existing Security Council Safe at 0x7101B78638e34444F0a5AdE9e1149fbEeC029931, and targets the new Timelock Controller listed above.

This proposal updates the signer of the existing Endowment Safe at 0x4F2083f5fBede34C2714aFfb3105539775f7FE64 to be the new Timelock Controller. The Timelock has a 9 day delay, during which the Security Council can veto the Foundation’s proposals to the Endowment. The exception is existing permissions approved by the DAO in previous proposals.

Separately, this proposal transfers 1 million ENS tokens directly to the Foundation Safe. These are not subject to the Timelock delay.

Calldata below:

Target: 0xC18360217D8F7Ab5e7c516566761Ea12Ce7F9D72 (ENS token)

Function: transfer(address recipient, uint256 amount)

Arguments:
- 0x9C7dB6B1085ec4D07f75c0BD91AD3FcD368fA19E (Foundation Safe)
- 1000000000000000000000000

$ cast calldata "transfer(address,uint256)" 0x9C7dB6B1085ec4D07f75c0BD91AD3FcD368fA19E 1000000000000000000000000
Target: 0x4F2083f5fBede34C2714aFfb3105539775f7FE64 (Endowment Safe)

Function: execTransaction(address to, uint256 value, bytes data, uint8 operation, uint256 safeTxGas, uint256 baseGas, uint256 gasPrice, address gasToken, address refundReceiver, bytes signatures)

Arguments:
- to: 0x4F2083f5fBede34C2714aFfb3105539775f7FE64 (Endowment Safe self-call)
- value: 0
- data: 0xe318b52b0000000000000000000000000000000000000000000000000000000000000001000000000000000000000000fe89cc7abb2c4183683ab71653c4cdc9b02d44b70000000000000000000000000bcc3da6ad796f59288c0961602675e88a2b406c (swapOwner calldata)
- operation: 0 (Call)
- safeTxGas: 0
- baseGas: 0
- gasPrice: 0
- gasToken: 0x0000000000000000000000000000000000000000
- refundReceiver: 0x0000000000000000000000000000000000000000
- signatures: 0x000000000000000000000000fe89cc7abb2c4183683ab71653c4cdc9b02d44b7000000000000000000000000000000000000000000000000000000000000000001

$ cast calldata "execTransaction(address,uint256,bytes,uint8,uint256,uint256,uint256,address,address,bytes)" 0x4F2083f5fBede34C2714aFfb3105539775f7FE64 0 "$(cast calldata "swapOwner(address,address,address)" 0x0000000000000000000000000000000000000001 0xFe89cc7aBB2C4183683ab71653C4cdc9B02D44b7 0x0bcC3dA6aD796F59288C0961602675E88A2B406C)" 0 0 0 0 0x0000000000000000000000000000000000000000 0x0000000000000000000000000000000000000000 0x000000000000000000000000fe89cc7abb2c4183683ab71653c4cdc9b02d44b7000000000000000000000000000000000000000000000000000000000000000001

Exhibit A:

Interim Conflict of Interest Policy

1. Purpose and status

This interim policy takes effect on adoption of this proposal and governs the ENS Foundation Board and Executive Director until the Board approves the detailed Conflict of Interest Policy contemplated within the first 90 days. That later policy refines this one; it does not replace it with anything weaker. Any material change to this policy is published before it takes effect.

2. What counts as a conflict

A conflict exists when a director’s or the ED’s personal, financial, or professional interests could reasonably appear to influence their judgment on a Foundation matter. This includes, without limitation: a current role, employment, or compensation at an entity that receives Foundation funding; a financial interest in a grant applicant, service provider, or counterparty; a family or close personal relationship with any of the foregoing; and any matter concerning the person’s own compensation, employment, or removal. Appearance matters: if a reasonable community member would question the person’s impartiality, it is treated as a conflict.

3. Disclosure

Each director and the ED discloses actual and potential conflicts in writing: (a) on appointment, as a baseline disclosure of material affiliations; (b) at each Board meeting, as to any agenda item; and (c) promptly when a new conflict arises. Disclosures are recorded in the Board minutes and published with them.

4. Recusal

A conflicted person does not vote on the matter and does not participate in the Board’s deliberation of it, beyond answering questions the non-conflicted directors ask. Recusals are recorded in the minutes and published. The following recusals are standing and automatic:

¡ Any director or the ED, on any matter involving an entity in which they currently hold a role, employment, compensation, equity, or other financial interest.

¡ The Founder seat, on any matter concerning ENS Labs funding, for so long as the seat carries succession to an ENS Labs representative.

· The ED on all matters concerning the ED’s own employment, compensation, or performance.

¡ Any director on their own compensation, renewal, or removal.

Prior roles or employment that have ended are disclosed in the public register under Section 6 but do not by themselves require recusal.

4A. Related-party decisions

Any decision concerning ENS Labs funding, in addition to any Board majority, requires the affirmative vote of a majority of the independent directors voting on the matter.

5. Quorum and decision on conflicted matters

A matter on which one or more members are recused is decided by majority of the non-recused directors, provided at least two non-recused directors participate. If recusals leave fewer than two, the matter is deferred until the Board has obtained independent advice on the matter, and the advice and the ultimate decision are recorded in the published minutes.

6. Public record

All disclosures, recusals, and votes on conflicted matters are recorded in the minutes and published. The Foundation maintains a public register of each director’s and the ED’s material affiliations, updated at least quarterly.

7. Gifts and personal benefit

No director or the ED may accept any gift, payment, or benefit offered to influence a Foundation decision, or use Foundation position, information, or assets for personal benefit. Gifts above a nominal value connected to Foundation business are disclosed and declined or surrendered to the Foundation.

8. Attestation

Each director and the ED signs an annual written attestation of compliance with this policy, published with the Foundation’s annual reporting.

14 Likes

Labs Aura Farming:

This proposal makes no serious concessions; ie; Board composition, treasury control or accountability structures haven’t been addressed or considered at all

Our assumption is this is the same proposal refactored to incorporate feedback from internal ENS Labs conversations, not with the wider ENS community or delegates.

Given Nick’s recent delegation this updated proposal is just a formaility before the executable is voted through.

Edit: These theatrics are ultimately unnecessary given the direction ENS Labs is moving. Just be upfront about this takeover and the community dissolution.

5 Likes

It is highly worrying and saddening to see the direction ENS DAO is taking.

ENS Labs has been the DAO’s largest and most important funding recipient for years, while also holding almost 4 million ENS that is enough to represent a majority of active voting power. From the beginning, I found it deeply concerning that a nonprofit organization receiving substantial recurring funding from the DAO also held this much practical governance power.

ENS Labs has also been the dominant executive party throughout this period. Yet every major operating and governance trend I track has moved in the wrong direction: revenue has declined, expenses have increased, profitability has weakened, protocol adoption has deteriorated, and active voting power has become more concentrated.

Against that background, this proposal increasingly looks like a gambler who has been losing continuously and now wants control of the remaining capital, supposedly to solve the problem.

I am also increasingly concerned that this stopped being a purely rational governance discussion a long time ago and became partly driven by emotion, control, and ego. What we are seeing now may be the end result of that direction.

I genuinely hope my assessment is wrong. But unfortunately, my concerns in situations like this have usually proven justified.

3 Likes

I really can’t see how you can honestly believe that this proposal is taking into account any of the feedback given to you by all of us.

It is not.

The foundation is still a pet foundation owned by ENS Labs.
You removed the previous security council, as they did not agree with you and considered ENS Labs an attacker against the DAO.
You set up a new security council that will do ENS Labs bidding.
The foundation / ENS Labs controls the funds.
ENS Labs controls the majority of the voting supply and is in fact the DAO.
In any case the DAO is powerless at this point and controls nothing but “protocol updates” which is whatever ENS Labs wants to do anyway.

Look I get it. You wanted full control over everything. You got it. You killed you community in the process. ENS is now just ENS Labs.

Drop the theatrics with foundations, DAOs and the like. You are just burning money on useless theatrics that you should probably focus on development.

This will be my last post in this forum.

1 Like

ENS Labs has not delegated these tokens except for the interim veto contract before a proper security council was established, and I don’t think that’s likely to change.

You write this as if ENS Labs simply happened across the DAO and started offering its services, when in fact ENS Labs is the entire reason ENS exists in the first place. The metrics you are complaining about - which largely reflect the state of the overall crypto ecosystem - would all be 0 if ENS Labs hadn’t been here to build it.

4 Likes

Responding to a few things here:

The proposal was materially revised in direct response to the treasury concerns raised during the temp check. The DAO’s ENS remains under tokenholder control, the operational wallet does not move, the Endowment remains in its existing Safe, and Endowment transactions are now subject to both a timelock and an independent cancellation mechanism. That is not “no serious concessions.”

The Security Council was elected by the DAO through EP 6.47, following an open process with 14 voluntary nominees, including half of the previous Security Council, a ranked-choice Snapshot vote, and a published methodology. I believe the commenters in this thread also participated in that vote.

I also think the claim that “the entire community is dead” is vague and unsupported. Independent service providers are active, and new teams continue to build on ENS standards. Labs is working with external builders and integrators at a higher volume than at any prior point. People who are not directly involved in that work should be cautious about declaring that it does not exist.

I fully agree that Labs should focus on development rather than remain mired in politics. My hope is that this new structure will enable exactly that. I’m also looking forward to working constructively with the Foundation and the new Meta-Governance Working Group to rebuild a functional relationship across the ecosystem.

7 Likes

ENS Labs has not delegated these tokens except for the interim veto contract before a proper security council was established, and I don’t think that’s likely to change.

“I don’t think that’s likely to change” is not a governance safeguard. It is a trust-based assumption.

ENS Labs’ almost 4 million ENS remains unused governance power. The fact that it has not been delegated so far does not remove the possibility that it could later become a final line of defence against losing institutional control.

ENS Labs deserves full credit for creating ENS, but past success does not remove the need for accountability or guarantee future sustainability.

I could accept professional execution through the Foundation if ENS tokenholders retain ultimate onchain authority over both the protocol and its capital. Legal rights to appoint or remove directors are valuable, but they are not equivalent to direct control over the Endowment. An executable governance vote should be able to revoke Foundation permissions and return Endowment control to the DAO without depending on Foundation cooperation or offchain legal enforcement.

Anthony Leutenegger, as CEO of Aragon and a proposed independent Foundation director, should understand this distinction particularly well. Lido DAO uses Aragon as its onchain governance framework, through which LDO holders can execute contract changes and treasury transfers. Its professional Foundations request funding from the tokenholder-controlled DAO Treasury instead of receiving control over the treasury itself.

I hope ENS preserves the same fundamental separation. Anyone can remain in the executive seat, but ultimate ownership authority over the protocol and its capital must remain with the DAO through onchain-enforceable rules.

1 Like

Does the timelock apply to transactions executed by @kpk through the Zodiac Roles Modifier, or only to owner-level transactions such as permission updates and disbursements?

Concerned that swap order expirations won’t survive a timelock, and actions that de-risk during volatility would sit in queue before executing. This would make active management of the endowment unworkable.

It would only affect operations based on regular multisig ops, not via the zodiac roles modifier.

1 Like

Thanks, Katherine,

for all the work you’ve put into this proposal and for taking the time to revise it based on the discussion. Regardless of where everyone ultimately lands on the details, it’s good to see the community’s feedback reflected in the latest draft.

First of all, I wanna emphasize that I haven’t followed every detail of the proposal, and I don’t feel qualified to comment on the structural design choices themselves. Many others in this discussion have spent far more time evaluating those details than I have.

My perspective is therefore from a higher level and focused on the long-term direction of ENS rather than the specific governance mechanics.

IMHO, the bigger question is not “DAO vs Foundation”. If ENS is truly evolving into critical infrastructure for identities, organizations, AI agents and digital assets, then it also needs institutions that can operate effectively in the real world - whether that’s engaging with ICANN, standards bodies, enterprise partners or other Web2 ecosystems. A DAO alone is not designed for all of those responsibilities. An operationally capable Foundation therefore seems like a natural step in ENS’s evolution.

Regarding governance and voting power: I personally don’t see the existence of highly influential contributors as the core issue. In the early stages of almost every successful protocol, founders and key builders naturally accumulate significant influence because they earn the community’s trust through execution. The more important (longterm) question, in my view, is whether ENS is building institutions that will remain effective long after today’s leaders have stepped aside.

And there is another aspect that I believe will become increasingly important if ENS wants to become globally accepted infrastructure: the relationship between ENS and existing legal frameworks.

In my experience with trademark disputes and litigation, intellectual property rights can‘t simply be ignored. Different jurisdictions take different approaches, but globally operating infrastructure will ultimately need a credible way to interact with established legal systems, especially around trademarks, naming rights and other IP-related claims.

I don’t think the long-term answer can simply be, “they should’ve acted earlier” or “they should pay a lifechanging amount”. That may work for a decentralized community discussion, but it‘s unlikely to be sufficient when governments, enterprises and major brands evaluate ENS as critical infrastructure.

Finding a balanced approach that respects decentralization while acknowledging legitimate legal rights may become one of ENS’s biggest challenges over the coming years.

If we can combine decentralized governance, a professionally operating Foundation, strong institutional checks and balances, and a thoughtful approach to real-world legal interoperability, ENS has a much better chance of becoming durable public infrastructure rather than remaining an interesting governance experiment…. and that’s ultimately the direction I’d like to see ENS continue moving toward….

2 Likes

This is now live for voting onchain.

Just lol. Great political language here.

The reality is any ‘material’ changes you think this proposal represents is only in the heads of you and ENS labs.

But as my above post states “These theatrics are ultimately unnecessary given the direction ENS Labs is moving. Just be upfront about this takeover and the community dissolution.”

Excited to see another crypto foundation burn hundreds of millions of dollars for the enrichment of themselves. Long live Ethereum and love live Ethereum’s many naming services.

1 Like

The same people who’ve proven themselves to be incompentent to engage/build ENS for the past 5 years (outside of building the protocol 9 years ago) are now power hungry to double down on contributing to the further decline of ENS (outside of the general decline in crypto sentiment) by rigging every side to be in the favor of Labs, who are only but a few people… when the “goal” of getting hundreds of millions and billions of people to utilize the tech.

Do you think rigging it as such is suppose to invite more people to contribute? Because in reality it does the exact opposite. This will further showcase how little Labs cares about the input of it’s community and outside contributers and how centralized the decisions (very poor decisions at that in the past 5 years) have effected and will continue to effect the growth of ENS and it’s legitimacy.

You guys build incredibly slow, create bad UI + constant problems with registering .eth domains on your website for years now where txns error out, and don’t do a lick of marketing/advertising with all the money the community has given you. You guys should be marketing HEAVILY towards having people registering an .eth domain be the first thing they do when coming into crypto. You guys could be a adoption behemoth yet you’ve AFK’d for the past 5 years hiding in the shadows or going to events where the reach for adoption is very small. ENS could be global infra, yet you only try and get adoption at small events without even doing marketing online where 99.9%+ of people that we aim to onboard will never go to these events… Don’t you realize the more adoption from USERS the higher likely hood a App/Dapp/Platform will want to integrate ENS resolution?

You’ve ignored the community (those who funded you) and went straight to niche and ineffective ways to capture adoption. You cannot just get platforms to resolve ENS domains and call it a day (yes, that’s why you go to the events, we know) . What’s the point in that if hardly anyone uses ENS domains? It’s a theatrical front of “adoption”…

If Taylor Swift has a concert and utilizes a giant stadium, but there is zero marketing, then that is just a complete waste and no one will go because they have no idea it’s even happening. Sure, she got the stadium, but it served no legitimate purpose…. This further puts into question the “front” that seems to be at display, instead of legititmately trying to curate adoption.

ENS could be a global standard, but it’s overtaken by the power and selfcentered righteousness of very, very few, who again have showed us for years they are incompetent to do even the most very basic of necessities while avoiding the outsiders who could have the perfect counter balance in perspective to help further ENS adoption by covering every field of operation that ENS Labs continues to lack..

I know this will fall and deaf ears because “pft, what does he know”… Right? But the rainbow colors on your website can’t mask the true color of grey within Labs.
Enjoy the funds we all gave you. :+1:

1 Like

Thanks for the updated proposal.

While I don’t think it’s perfect, I want to differ from colleagues who argue it hasn’t addressed the previous criticisms. It has, in several meaningful ways, and I came into this vote leaning toward support. I spent time verifying the deployed contracts before voting, and what I found is why I ultimately can’t — I’ll show my work below so anyone can check it.

Board process. I would have preferred the board be elected in a separate discussion rather than appointed and ratified in one vote — likely a formality given vote distribution, but better process. Terms should also be staggered so all three independent seats don’t expire simultaneously, and I’d note the Founder and ED seats carry no terms at all: the seats with the most structural weight are the only ones exempt from any renewal cycle. So this is really more a complaint than a blocker.

Endowment ownership (or “what the code actually does”). This feels like it should have been a social proposal but is already an executable, and the second transaction swaps the sole owner of the Endowment Safe (1-of-1, ~$65M) from the DAO’s governance timelock to a new EndowmentTimelock (0x0bcC…406C). That timelock’s only proposer is the Foundation’s 3-of-5 Safe; the only check is an EndowmentSecurityCouncil contract (0x0A93…3EdD) that lets the 5-of-8 Security Council cancel queued transactions — and which expires on Aug 7, 2028, after which anyone can strip its role. To their credit, the safeguard is real and correctly built on the audited Blockful pattern. But note two things: none of these addresses appear in the proposal text (voters are approving a swapOwner to an undocumented destination), and after 2028 the veto can only be reinstated if the Foundation itself queues the grant — the watched party controls the renewal of its own watchdog, while the custody transfer has no expiration.

After execution, the DAO appears nowhere in the control chain: not as Safe owner, not as proposer, not as admin. The draw limits, budget bounds, and the $500k standup cap exist in prose only — the executable enforces none of them. The conflict-of-interest recusals likewise have no onchain existence; the Foundation Safe is a flat 3-of-5 that will process any transaction three keys sign, whatever the COI policy says.

Role confusion. This also inverts the manager relationship. Karpatkey’s Roles permissions are untouched and the 9-day timelock applies only to owner-level transactions — so day-to-day management of the full $65M continues outside the timelock, while the Foundation inherits the principal’s powers: rescoping, replacing, or removing the Endowment Manager, decisions that today belong to the DAO.

A better model keeps the parties independent:

  • The DAO owns and controls the Endowment, with hard-coded and constitutional limits on outflows.

  • The DAO chooses both the Foundation’s board and the Endowment Manager.

  • The Endowment Manager (currently Karpatkey) pursues long-term growth of the funds.

  • The Foundation’s board makes an annual budget, seeks DAO approval, and withdraws only that amount to its wallet.

  • The Foundation uses that budget to pick providers and fund development.

  • Providers make technical decisions for the protocol.

The current proposal collapses this: the Foundation becomes owner, principal, and budget-setter at once, and given the Founder seat’s succession to an ENS Labs representative, a structural majority on that board sits within reach of a single stakeholder needing only two of the remaining four votes.

I came to this really wanting to vote for it. I think the proposal text addresses a lot of the issues respectfully. I was even going to criticize but ultimately was ok with the idea of legal ownership of the Endowment sitting within a Cayman framework – but having the onchain ownership of the whole endowment be moved to a 3 of 5 multisig plus timelock – that’s clearly a step back IMHO.

1 Like

Live calldata security review

The executable proposal is now live. The manually derived calldata matches the on-chain bytes, and the full governance lifecycle (vote → queue → execute) simulates successfully with the expected effects.

What the two transactions do:

  1. Transfer 1M ENS from the DAO treasury to the Foundation Safe
    (0x9C7dB6B1085ec4D07f75c0BD91AD3FcD368fA19E, 3-of-5: nick.eth, alexurbelis.eth,
    kartik.eth and two addresses without ENS records).
  2. Replace the DAO timelock as owner of the Endowment Safe (endowment.ensdao.eth)
    with a new EndowmentTimelock (0x0bcC3dA6aD796F59288C0961602675E88A2B406C).

What we verified on-chain:

  • The EndowmentTimelock is identical to OpenZeppelin TimelockController v4.3.2,
    with a 9-day minimum delay. Its deployer renounced admin.
  • Only the Foundation Safe can schedule transactions. Execution is permissionless
    after the delay. The DAO holds no role on the new timelock.
  • The Security Council can cancel queued transactions through a veto-only wrapper
    (0x0A9387643ce6291f8C545286675D76bCd0Ba3EdD, bytecode identical to the audited
    security-council contract). The test exercises this: the SC cancels a queued
    transaction, and a non-cancelled one executes only after the delay.
  • The veto cannot be removed and the delay cannot be shortened, since role changes
    pass through the same delayed, vetoable path.
  • The Endowment’s existing modules are untouched. The treasury manager continues
    operating as is.

Notes for voters:

  • The three new addresses above are not in the proposal text. They can only be
    verified from the calldata or this review.
  • “All Endowment transactions pass through a 9-day timelock” applies to the owner
    path. Two pre-existing module paths bypass it and survive the swap: karpatkey’s
    Roles v2 module and a Safe Allowance Module granting the MetaGov WG multisig
    30 ETH per 25 days for treasury management fees.
  • The Foundation Safe becomes the only key able to initiate Endowment transactions.
    Its signers should use dedicated hardware wallets, keep signer addresses isolated
    from other applications, and set an ENS name or subdomain on each wallet, publicly
    confirmed by the board member behind it.

If the Foundation multisig is compromised:
The 1M ENS can be moved immediately, since it sits in the Safe and not behind the
timelock. The Endowment cannot be drained while the Security Council cancels what
the attacker schedules. The risks are the Council missing a 9-day window, or its
veto expiring in August 2028 without renewal. KPK’s only transfer permission is USDC pinned to
the DAO timelock, so managed funds can still be returned to the DAO.

All simulations and assertions are available here.

To verify locally:

  1. Clone: git clone https://github.com/blockful/dao-proposals.git
  2. Checkout: git checkout 6ab60a3
  3. Run: forge test --match-path "src/ens/proposals/ep-empowering-ens-foundation/*" -vv

I appreciate your comments and vote, Avsa. I’ve tried to address your concerns below in what I hope is a constructive and forward-looking manner for the rest of our constituents.

#

1. Address Documentation & Independent Verification
Agreed about the addresses. They should have been named in the proposal text, not left to be decoded from calldata, and blockful’s own review says as much. We will edit the proposal to make sure that they are front and center. In the meantime, blockful has posted a plain-English decode of the executable: [Draft] [Executable] Next Era of ENS DAO: Empowering the ENS Foundation - #15 by blockful. It walks through both transactions and names the contracts they touch, the EndowmentTimelock, the Security Council veto wrapper, and the Foundation Safe, with their parameters and roles: the 9-day delay, the Foundation Safe’s schedule-only power, and the 3-of-5 signer set. With that decode public, anyone can now check the calldata against it, as was done for the Security Council executable. We welcome that scrutiny.

2. Staggered Board Terms
Agreed, and we will codify it. The bylaws will stagger the three independent director terms so they do not all expire at once, starting from the first renewal cycle.
On the Founder and ED seats: While they are not under a renewal cycle, they are in fact subject to removal power, and that power never sleeps. As with any director, Tokenholders can remove them at any time under the Articles, and as the proposal states, no Board process can delay or prevent that vote. Everyone is accountable.

3. The Watchdog Renewal
I appreciate you raising this. And there is a mechanism to address it. The Foundation will commit, in its published treasury policy, to queue the renewal of the Security Council’s cancellation role no later than six months before its expiry. Queued at that point, the renewal passes through the timelock while the cancel power is still alive. So, in other words, the watchdog oversees its own renewal. And if the Foundation ever missed that deadline, you would have precisely the documented, evidenced grounds for which the removal process was written.

Clarifications

The DAO & the Control Chain
What you addressed was the onchain custody path. But I want to highlight are the bulwarks behind the custody change. Unlike before, every owner-level Endowment transaction now waits nine days and can be cancelled by the DAO-ratified Security Council. This is an onchain protective measure that the DAO has never had over this money. The second bulwark is familiar: the DAO appoints and removes, at will, every person who controls the proposer Safe. In this sense, the DAO is not absent from the control chain. It is rather at the top of it, one vote away from replacing everyone below.

The current state of affairs is a 1-of-1 Safe owned by the governance timelock. Today, the entire Endowment is one passed proposal and a two-day fuse away from going anywhere a majority sends it, and nothing outside that majority can stop it. T hus, with respect, I submit that every failure mode you’ve describe for the new structure already exists in a sharper form in the current one.

The Manager Relationship
Under the proposal, replacing, rescoping, or removing the Endowment Manager is an owner-level action: that means nine days in the timelock, cancellable by the Security Council.

Today, that would take only an ordinary vote and a two-day timelock, with no veto over this action available anywhere.

So yes, the principal’s powers move to the Foundation, the proposal says so openly, but they arrive under way more oversight than they have ever had.

Karpatkey’s day-to-day latitude stays untouched on purpose; that continuity, bounded by a Roles configuration that cannot send funds to arbitrary destinations, is (as I understand it) the same type of function your own rate-limit proposal set forth. It is also what Coltron’s question in this thread was making sure we kept.

Prose v. Code
The budget isn’t encoded onchain in large part because of your own thread on this topic. Encoding budget math onchain means valuation feeds or oracles, and those become their own attack surface. So we split the work. Code creates custody chokepoints: i.e., the timelock, and the cancellation power.

Law, on the other hand, is what keeps the Foundation true to its commitments, e.g., the $500K standup gate, the draw limits, backed by directors who owe fiduciary duties under Cayman law and hold their seats at tokenholder pleasure. Breaching those commitments creates a case for removal and liability, and for directors in regulated professions (like myself), there could be consequences outside of the board room.

#

Your vote is cast. I respect your position and I thank you for your criticism, all of which has been considered, and I believe has made the proposal stronger.

2 Likes

Thanks for the reply @Alexu

I understand the Endowment is still legally bound to the DAO, but not technically and that is the crux of my issue. I have a simple proposal that would turn my vote around.

Will the Foundation Safe publicly queue grantRole(PROPOSER_ROLE, wallet.ensdao.eth) on the EndowmentTimelock before the vote closes? It’s one transaction, verifiable on Etherscan, requires no change to the live proposal, and turns this from ‘the DAO is removed as owner’ into ‘the Foundation is added alongside the DAO.’ This can be done today and while it would not be executed before the vote ends, it would go a long way to show good will towards the community.

2 Likes

Thanks @katherine.eth and team for the revisions. The changes from the temp check are real and we want to acknowledge that. We came into this wanting to get to a yes. but after reviewing at current state we decided to vote against, and here’s why.

The crux for us is the same as @AvsA after execution, the DAO holds no role on the new EndowmentTimelock. Not owner, not proposer, not admin. Only the Foundation’s 3-of-5 Safe can schedule transactions. The $500k cap, the budget bounds, and the COI policy all live in prose and Cayman law, none of it onchain. And per blockful’s review, the Security Council’s veto expires in August 2028 with renewal queued by the Foundation itself.

We get the argument that legal accountability plus director removal is meaningful. But “the DAO can remove directors” is not the same as “the DAO controls its Endowment.” One is a legal claim that takes months to exercise; the other is a transaction.

AvsA’s ask seems like the right fix: queue grantRole(PROPOSER_ROLE, wallet.ensdao.eth) on the EndowmentTimelock so the Foundation is added alongside the DAO rather than replacing it. One transaction, no change to the live proposal. If the team commits to that, we would revisit our vote.

Until then, this is an against from us. Professionalizing operations: yes. Removing the DAO from its own treasury’s control chain to get there: no.

2 Likes

For what it’s worth, the Foundation would be able to cancel transactions from the DAO in this setup so it’s not really useful. Also, it would take 18 days for the DAO to make a transcaction to the Endowment Safe which is inefficient.

A potential better solution is updating EndowmentSecurityCouncil to separate some permissions so the DAO could extend or replace it. This requires code change, and therefore an audit, which likely cannot happen before this proposal concludes.

1 Like

Thanks for the reply. I’m sure other solutions can be thought of, like adding the DAO as a signer of the foundation, maybe more than once. Reinforces the idea that this is a very big onchain change that is not ready to be executed and shouldn’t be an executable yet. Will not change my vote.