✨Anticapture Framework

[FRAMEWORK] The Anticapture Framework //

The Anticapture Framework evaluates DAO governance security by mapping common attack vectors and defining protective metrics. It translates complex risks into measurable indicators, enabling DAOs to anticipate vulnerabilities before they escalate.

By assigning risk levels (low, medium, high), it categorizes each DAO into stages of security maturity. This structured approach makes governance security visible, comparable, and actionable across the ecosystem.

circle-exclamation

Metrics we analyze

The Anticapture framework was designed with different types of attacks in mind.

From our knowledge base of past attacks on DAOs, we see what the most common attack vectors are – and check which metrics can help anticipate them.

  1. Proposal Flash Loan Protection

  2. Voting Flash Loan Protection

  3. Timelock Delay

  4. Voting Delay

  5. Proposal Threshold

  6. Veto Strategy

  7. Proposer Voting Power Retention Check

  8. Voting Period

  1. Vote Mutability

  2. Voting Subsidy

  3. Spam Resistance

  4. Audited Contracts

  5. Interface Hijack

  6. Extractable Treasury Value

  7. Security Council

  8. Timelock Admin


Stages

Our stages are based on the highest risk point in the DAO.

A DAO stage will always be equal to the worst metric they have. That means that any metric matching Stage 0 will make the DAO Stage 0, while to be Stage 1 the DAO can’t have any stage 0 metrics and has at least one that doesn’t match the criteria for Stage 2

  • Half of Active Power Supply and delegated supply ≀ DAO treasury assets – except gov tokens

  • Half of delegated supply ≀ DAO treasury assets – except gov tokens

  • There is no Proposal Flash Loan Protection

  • There is no Voting Flash Loan Protection

  • No timelock

  • Voting Delay < 2 days

  • Proposal Threshold < 0.5% market supply

  • Veto Strategy managed by external entity

  • There is no Proposal Threshold Cancel

  • Voting Period ≀ 3 days

  • No subsidy for voters/delegates

  • There is no limit for submit proposals

  • Governance contract were not audited

  • DAO Domains and third parties don’t follow protection standards

  • Half of Active Power Supply and delegated supply ≀ DAO treasury assets – except gov tokens

  • Has a Security Council, but with insufficient security measures

  • Governor controlled by entity outside of DAO/Foundation

The Anticapture Framework is still evolving to adapt to more types of organizational structure. See something that doesn’t make sense for your DAO? Reach outarrow-up-right!

Last updated