Skip to main navigation Skip to search Skip to main content

Understanding Security Issues in the DAO Governance Process

  • Junjie Ma
  • , Muhui Jiang
  • , Jinan Jiang
  • , Xiapu Luo
  • , Yufeng Hu
  • , Yajin Zhou
  • , Qi Wang
  • , Fengwei Zhang

Research output: Journal article publicationJournal articleAcademic researchpeer-review

Abstract

The Decentralized Autonomous Organization (DAO) has emerged as a popular governance solution for decentralized applications (dApps), enabling them to manage their members across the world. This structure ensures that no single entity can arbitrarily control the dApp without approval from the majority of members. However, despite its advantages, DAOs face several challenges within their governance processes that can compromise their integrity and potentially lead to the loss of dApp assets. In this paper, we first provided an overview of the DAO governance process within the blockchain. Next, we identified issues within 3 key components of the governance process: the Governance Contract, Documentation, and Proposal. Regarding the Governance Contract, malicious developers could embed backdoors or malicious code to manipulate the governance process. In terms of Documentation, inadequate or unclear documentation from developers may prevent members from effectively participating, increasing the risk of undetected governance attacks or enabling a small group of members to dominate the process. Lastly, with Proposals, members could submit malicious proposals with embedded malicious code in an attempt to gain control of the DAO. To address these issues, we developed automated methods to detect such vulnerabilities. To investigate the prevalence of these issues within the current DAO ecosystem, we constructed a state-of-the-art dataset that includes 3,348 DAOs, 144 documentation, and 65,436 proposals across 9 different blockchains. Our analysis reveals that many DAO developers and members have not given sufficient attention to these issues. For the Governance Contract, 176 DAOs allow external entities to control their governance contracts, while one DAO permits developers to arbitrarily change the contract's logic. In terms of Documentation, only 71 DAOs provide adequate guidance for their members on governance processes. As for Proposals, over 90% of the examined proposals (32,500) fail to provide consistent descriptions and code for their members, highlighting a significant gap in transparency within the DAO governance process. For a better DAO governance ecosystem, DAO developers and members can utilize the methods to identify and address issues within the governance process.
Original languageEnglish
Pages (from-to)1188 - 1204
Number of pages17
JournalIEEE Transactions on Software Engineering
Volume51
Issue number4
DOIs
Publication statusPublished - Apr 2025

Keywords

  • Decentralized governance
  • language models
  • program analysis
  • smart contracts

ASJC Scopus subject areas

  • Software

Fingerprint

Dive into the research topics of 'Understanding Security Issues in the DAO Governance Process'. Together they form a unique fingerprint.

Cite this