Executed

Enhanced Security Measures for Risy DAO Governance


ID 675720...8543

ID 675720...8543

Proposed on: Nov 24th, 2024

Proposed on: Nov 24th, 2024

Votes

Actions

Type

Address

Details

Custom

0xD74E...E11A

updateQuorumNumerator(..)

Custom

Account

0xD74E...E11A

Method

updateQuorumNumerator(..)

Custom

0xD74E...E11A

setVotingDelay(..)

Custom

Account

0xD74E...E11A

Method

setVotingDelay(..)

Custom

0xD74E...E11A

setVotingPeriod(..)

Custom

Account

0xD74E...E11A

Method

setVotingPeriod(..)

Custom

0xD74E...E11A

setProposalThreshold(..)

Custom

Account

0xD74E...E11A

Method

setProposalThreshold(..)

Proposal

Executive Summary

This proposal aims to implement three critical security enhancements to the Risy DAO governance structure in response to the project's rapid growth and increased visibility. The proposed changes will strengthen the DAO's resistance to potential manipulation while maintaining its decentralized nature.

Current State

Proposed Changes

Increased Quorum Requirement

  • From: 10% (100B $RISY) ≈ $14,680
  • To: 20% (200B $RISY) ≈ $126,000
  • Purpose: Enhance resistance to governance manipulation

Higher Proposal Threshold

  • From: 1B $RISY ≈ $84
  • To: 10B $RISY ≈ $870
  • Purpose: Prevent proposal spam and ensure quality governance discussions

Extended Voting Timeline

  • From: 4 days (1 day delay + 3 days voting)
  • To: 10 days (3 days delay + 7 days voting)
  • Purpose: Allow adequate time for community response, especially considering the 10% daily transfer limit

Rationale

Security Against Manipulation

  • The current quorum requirement of 100B $RISY (≈$14,680) has become relatively accessible due to RISY's rapid growth
  • A malicious actor could potentially acquire enough tokens to manipulate governance decisions
  • The new quorum requirement of 200B $RISY (≈$126,000) significantly raises the barrier for potential attacks
  • This increase maintains decentralization while providing enhanced security

Spam Prevention

  • The current proposal threshold of 1B $RISY (≈$84) is too low, making the governance interface vulnerable to spam
  • Malicious actors could flood the DAO with invalid proposals, making it difficult for community members to focus on legitimate governance matters
  • The new threshold of 10B $RISY (≈$870) deters spam while remaining accessible to serious proposals
  • This balance ensures quality governance discussions without compromising decentralization

Enhanced Response Time

  • The current 4-day period (1+3) is insufficient considering RISY's 10% daily transfer limit
  • In case of malicious proposals, token holders need adequate time to respond
  • The extended 10-day period provides:
  • 3 days for community awareness and discussion
  • 7 days for informed voting and potential exit if needed (aligned with 10% daily transfer limit)
  • Better protection against time-based attacks

Technical Implementation

If approved, this proposal will require three function calls to the governance contract:

// 1. Update quorum to 20%
function updateQuorumNumerator(uint256 newQuorumNumerator) external {
    // Only callable by governance
    _updateQuorumNumerator(20); // 20% of 100 (denominator)
}

// 2. Update proposal threshold to 10B RISY
function updateProposalThreshold(uint256 newThreshold) external {
    // Only callable by governance
    // 10B RISY = 10_000_000_000 * 10^18
    _updateProposalThreshold(10000000000000000000000000000);
}

// 3. Update voting delay and period
function setVotingDelay(uint256 newVotingDelay) external {
    // Only callable by governance
    // 3 days = 259200 seconds
    _setVotingDelay(259200);
}

function setVotingPeriod(uint256 newVotingPeriod) external {
    // Only callable by governance
    // 7 days = 604800 seconds
    _setVotingPeriod(604800);
}

Security Considerations

Attack Cost Analysis

  • New quorum requirement increases attack cost by ~760%
  • The proposal threshold increase of 1000% deters spam
  • The extended timeline provides better protection against time-based attacks

Impact on Legitimate Users

  • Higher thresholds remain accessible for serious governance participants
  • The extended timeline allows better community participation
  • Maintains decentralization while improving security

Conclusion

These changes represent a necessary evolution of Risy DAO's governance parameters in response to its rapid growth and success. The new parameters will significantly enhance security while maintaining the democratic and decentralized nature of the DAO.

Voting Options

  • For: Implement all three security enhancements
  • Against: Maintain current governance parameters
  • Abstain: Formally register participation without taking a stance

We encourage all RISY holders to carefully consider these critical security enhancements and participate in this important decision for the future of Risy DAO.

Additional Resources

Votes
Status