In a world of ledgers, who holds the memory?
This question cuts through the latest governance tempest at the Ethereum Name Service (ENS) DAO. We are weeks away from the expiration of the current security council’s mandate on July 24—a council that was blocked from renewal by founder Nick Johnson earlier this year. Now, the community votes on a new eight-member council to restore emergency veto power. It is a moment that tests not just ENS, but the entire premise of decentralized governance.
Let me rewind the context for those who live in the deep protocol layers. ENS is not a mere domain registrar; it is the phonebook of Web3—the infrastructure that maps human-readable names to Ethereum addresses, content hashes, and metadata. When you send ETH to vitalik.eth, you rely on ENS’s smart contracts being secure and free from malicious upgrades. The security council holds a rare and powerful key: the ability to veto any DAO proposal that could compromise the protocol. Without that council, the protocol is one governance attack away from catastrophe.
Earlier this year, Nick Johnson—the brilliant, meticulous founder who built ENS from nothing—used his influence to block the renewal of the existing security council. The reasons remain opaque: some whisper about disagreement over council membership composition; others suspect a desire to retain unilateral control during a critical growth phase. Regardless, the effect was chilling. The emergency veto power lapsed, leaving ENS in a state of technical vulnerability. The founder’s action, though perhaps well-intentioned, highlighted the fragility of relying on a single point of moral and technical alignment.
Now, the DAO votes on a new structure: an eight-person council elected by ENS token holders, endowed with the same veto authority. The proposal, submitted by Johnson himself after community pressure, is now on-chain. It is a classic dialectic—thesis: founder protects the protocol; antithesis: founder becomes a central point of failure; synthesis: a distributed council that balances speed and accountability.
Core: The Audit of Trust
From my experience auditing DAO governance structures, I see this vote as more than a procedural fix. It is a referendum on whether a protocol can mature from benevolent autocracy to resilient democracy. The technical mechanics are straightforward—a multisig wallet, likely 5-of-8 or similar, whose members can veto proposals via a time-locked smart contract. But the human mechanics are far more complex.
We code the trust, but we must audit the soul.
The security council’s effectiveness hinges on three variables: member diversity, key management, and incentive alignment. The original council, according to sources, was composed of long-standing ENS contributors—technical, but insular. The new council, if elected, must include voices from different parts of the ecosystem: wallet providers (MetaMask, Rainbow), DeFi protocols (Uniswap, Aave), and independent security researchers. Without diversity, the council becomes a echo chamber. With it, it becomes a true circuit breaker against groupthink and malicious proposals.

Key management is another unglamorous but existential detail. Hardware-based wallets with geographic distribution, regular rotation, and no single point of compromise—these are not abstract ideals. They are the difference between a council that can withstand a targeted attack and one that folds under pressure. I have seen multisigs fail because three signers used the same cloud-based seed phrase. The ENS council must set a gold standard, and the community must demand transparency on custody practices.
Incentives are trickier. Council members serve voluntarily or with small stipends. But the real reward is influence—being at the table where the most critical decisions are made. This creates a moral hazard: members may be reluctant to veto proposals that benefit their allies or token holdings. The solution, as I argued in my 2020 paper “Liquidity as Liberty,” is a binding code of conduct with slashing conditions. If a council member votes against the protocol’s long-term interest (e.g., approving a proposal that drains the treasury), they forfeit their reputation and any token reward. We are not moving money; we are moving belief.
Contrarian: The Illusion of Decentralization
Here is the uncomfortable truth that the narrative rarely admits: a security council, no matter how well-designed, is a form of centralization. It concentrates veto power in eight hands. The founder blocking the council was a single point of failure; the council itself is an eight-point failure surface. What happens if three members are compromised simultaneously? Or if a coordinated social attack forces them to approve a malicious upgrade?
The protocol is neutral, but the user is human.
Moreover, the council’s existence can breed complacency. If the community believes that the council will catch every bad proposal, they may stop paying attention to governance. We saw this in 2022 when a DAO approved a “harmless” parameter change that inflated a founder’s voting power. The council was asleep. True decentralization requires every token holder to be a vigilant auditor, not just for themselves, but for the entire network.
Another blind spot: the council’s powers usually exclude the ability to upgrade the protocol itself. That remains with the core team and the DAO. But the council can veto upgrades. This creates a political bottleneck. A founder who disagrees with the council’s philosophy can stall progress. Or a council that becomes too powerful can become a “guardianship” that resists change. The tension between security and innovation is real. ENS needs to evolve—into Layer 2, into cross-chain interoperability, into richer identity features. A veto-happy council could freeze the protocol in amber.
Proof is binary; meaning is fluid.

I also question the timing. The current council’s mandate expires July 24—just days away. Rushing a vote under time pressure might lead to poor candidate selection. The community should demand a thorough vetting process, possibly extending the current council’s term via a temporary proposal to avoid a gap. Every day without the veto power is a day of elevated risk. But a poorly chosen council is a risk that lasts for years.
Takeaway: The Future Is a Balancing Act
This vote is a microcosm of the entire crypto governance experiment. We are trying to build systems that are resilient, but not brittle; democratic, but not inefficient; founder-led, but not founder-controlled. ENS, as the naming substrate of Ethereum, carries an outsized responsibility. If it fails, the entire Web3 address book becomes untrustworthy. If it succeeds, it offers a blueprint for every protocol that struggles with the founder-to-community handoff.
We are not moving money; we are moving belief.
The question is not whether the council will be elected—it almost certainly will. The question is what kind of council emerges. Will it be a rubber stamp for the core team? A political battlefield? Or a thoughtful, independent, technically competent body that guards the protocol while respecting the DAO’s will?
To the ENS token holders casting their votes: remember that you are not just choosing eight individuals. You are choosing what decentralization means for the next decade. The ledger will remember. But will the soul?
In a world of ledgers, who holds the memory?