MakerDAO stakeholders vote down security proposal to address ETH collateral risk

Quick Take

  • MakerDAO stakeholders failed to approve an executive vote on a security proposal intended to help address a previously reported exploit risk.
  • Mariano Conti, head of smart contracts at MakerDAO, told The Block that the vote came close but ultimately did not pass.
  • Conti added that there will be another vote on the GSM in the future.
Advertisement

The MakerDAO community – for now, at least – has declined to activate a security feature that seeks to prevent the possible loss of all of its ether (ETH) collateral to would-be exploiters. 

One element of the MakerDAO system is the Governance Security Module (GSM), which is designed to give MKR token holders – who vote on changes to the overall system – a chance to review things that will go into the system, and act accordingly if those changes are deemed to be malicious.

The GSM is currently set at 0 hours, and the proposal would have seen the GSM raised to 24 hours.

A public sentiment poll was held last month that then set the stage for the executive vote. But according to Mariano Conti, head of smart contracts at MakerDAO, the vote came close to passing but it didn’t, likely because of two reasons. 

“It was very close to the holidays; and once people understood better why the GSM [Governance Security Module] was set to 0 initially, some decided it was the right decision," he said.

Conti said the GSM is currently set at that level because MakerDAO's engineering team felt that there were two possible attack vectors, a bug in the new system or a governance attack – and that the "possibility of a bug in the new system was much more likely than a governance attack."

"If we had set the delay to 24 hours at first, and there was a bug, we'd have at least 24 hours before being able to implement a fix. As the system continues to run correctly, the probability of a hack to the system decreases, and we can consider implementing the governance delay," Conti explained.

Conti went on to say that "this does not mean that there won't be another vote."

"The GSM code is part of the Maker Protocol, it's in the whitepaper and it was always expected to be activated,” Conti told The Block, adding that the community discussed on yesterday's call what to do when a vote "fails.”

“This is still a learning process where everyone, the Maker Foundation, community, MKR holders, are always learning and trying to improve,” he continued.

Risk warning

The process that led up to to the vote began with a warning from a developer.

Freelance developer Micah Zoltu published a blog post in early December that warned about a security vulnerability in the MakerDAO protocol, which could result in a possible theft of $340 million worth of ETH collateral.

According to Zoltu, anyone with a substantive amount of MKR tokens (around $20 million) could simply create an executive contract programmed to transfer all collateral from Maker to their account, immediately vote on and activate the contract, and effectively steal all of the system's collateral.

In the blog post – entitled "How to turn $20M into $340M in 15 seconds" –  Zoltu further explained that, typically, to mitigate malicious attacks like this, there would be a delay period before a new executive contract is activated for community members to flag and shut down the contract. But since the delay is currently set at 0 seconds, there is no safeguard against such thefts.

In response to Zoltu’s warning, MakerDAO initiated the executive vote to increase the GSM delay to 24 hours as a countermeasure. In the December 9 blog post, the MakerDAO team contended that "the probability of this exploit grew due to potential publicity from the aforementioned blog" and that "[f]or this reason, the community is being presented with a poll to mitigate this hypothetical exploit in advance of our typical debate and consensus-seeking processes."

Last year, the project moved to shift away from the single-collateral system. To that end, MakerDAO launched the Multi-Collateral DAI (MCD) protocol on Nov. 18.

 


© 2026 The Block. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.