A Framework for the Future

Framework for the Future: Proposal for Discussion

Thank you for your input during the consultation period.

Specifically, we recognize the contributions of @e3o8o for their tiered intervention framework, @odysseas for their explanation of the Phylax tool, @serenita_Luca for the validator perspective and @mrtdlogic, @mfw78 and @TheVoidFreak for their commitment to maintaining credible neutrality and clear communication.

Reflecting on the Balancer exploit, the community agreed that intervention was warranted, but were also clear that future interventions should be minimized and that processes and communications during and after any incident need to be improved.

With that in mind, I’d like to move the discussion to the next phase.

While the community was unanimous that any intervention must be minimized, some key tensions emerged that we’d like to start to tackle:

  1. Credible Neutrality: The debate highlighted the friction between Gnosis’s “Low-Risk DeFi” strategy and the desire for hard-line credible neutrality.

  2. Operational Ambiguity: It is clear that the current roles of the Gnosis DAO, Validators, and Gnosis Ltd are insufficiently defined during a crisis.

  3. Communication: We heard the community’s critique regarding the quality and frequency of updates and we commit to a more robust, single-spokesperson model moving forward.

We present the following as a starting point. We welcome input on the details, but in the interests of moving forward we believe we should consider this general approach to be settled.

1. Credible Neutrality

Censorship resistance was rightly at the heart of the debate surrounding the Balancer exploit.

It is one of our guiding principles, but our stance is that it is only meaningful if we are actually blind and not just wilfully blind. We remain fully committed to a future in which the Gnosis Chain is actually blind and are closely following developments in this space.

We will continue to monitor and will share updates with the DAO as it evolves.

Until then we are proponents of a low-intervention approach within clear parameters. We’re glad to see that the community agrees on this.

2. Operational Ambiguity

We took this opportunity to reflect on the way Gnosis Ltd and the Core Devs worked with the Gnosis DAO and with our validators during this time.

The situation was challenging for all involved and we are grateful to you for working with us.

In our opinion, the outcome was good but the process for getting there wasn’t.

We want to clarify roles, responsibilities and processes to make sure we avoid putting ecosystem participants in that position again. This needs to strike a balance between consulting relevant parties and acting quickly and responsibly in a dynamic exploit situation.

Here is a starting point for what that could look like.

Step 1: define the process

We propose a simple framework for determining when it is necessary to intervene in the standard operation of Gnosis Chain and Bridge.

Unfortunately it is challenging to remove all judgement from the assessment, but we should be transparent on the factors that would be considered as well as the roles of each of these actors in times of crisis.

Once an issue is flagged:

  1. A dedicated Crisis Response Team within Gnosis Ltd would assess the criticality based on:
  • Amount of funds affected (e.g., >3% of TVL might be moderately critical, while >5% of TVL could be severe).
  • Level of assumed user risk (e.g., services with robust audits AND over 3 years of operations might be deemed low risk; those with robust audits OR over 3 years of operations deemed medium risk; and those with neither deemed high risk). The higher the assumed risk, the less warranted an intervention.
  • Technical feasibility of intervention (e.g., actions like bridge pausing may be a relatively simple precautionary measure as opposed to chain interventions that could range from transaction censorship, to soft fork, to hard fork, right up to roll back).

These details are obviously critical and we would hugely value the community’s input.

  1. These assessments would be combined into a recommendation that would be provided to a Security Council (more details below). This council would approve or veto the decision based on a simple majority. Crucially, the Security Council acts only to ratify the recommendation, and has no responsibility for developing or implementing it.

While the recommendation would not be public at the time, it would be published within months of the resolution of the incident, along with the outcome of the Security Council’s vote. It may also be possible to publish an encrypted version of the decision at the time for later decryption, provided this does not slow down the process.

  1. If ratified, the official recommendation is communicated to the relevant parties so they can determine how to act. Depending on the specifics of the ratified recommendation, these parties might include core devs, validators, client teams, the bridge committee, and others.

Step 2: Confirm the role of Gnosis DAO

Security incidents create unique operational challenges that may be at odds with a DAO’s collective decision-making. This is because of the probable need for swift response without a malicious actor being forewarned via public discourse.

We suggest that decision making authority is delegated to a DAO-appointed Security Council. We could use a similar approach as GIP-129, for example.

The DAO remains the foundational governing body of the ecosystem, is responsible for establishing and updating the overarching incident response framework, and will remain informed of decisions/actions taken, having audit rights to hold stakeholders accountable.

Specific rights and responsibilities of the DAO in times of crisis could look as follows:

  1. Recovery Asset Steward: If an intervention is designed to intercept or recover assets that were compromised during an exploit/security incident, they may be sent to the DAO to hold, ensuring the community retains control over the final distribution of such assets;

  2. Strategic Accountability: within two months of any incident, the relevant stakeholders (Core Devs, Gnosis Ltd and the Security Council) commit to a formal retrospective with the DAO;

  3. Continuous Improvement: the retrospective will be the primary mechanism for the DAO to audit actions/decisions taken, identify learnings, and mandate improvements to the framework.

Step 3: Confirm the role of Gnosis Validators

While Chain Governance is the mandate of our validator community, the current mechanisms for consensus were designed for network stability and upgrades, rather than rapid response security interventions.

It is unreasonable to put the responsibility of decision making in extraordinary scenarios on our validator community.

In the event of a crisis or exploit, placing the burden of decision-making on the validator community presents significant challenges:

  1. Neutrality / Liability: By forcing validators to make subjective choices about freezing/diverting funds or enforcing state changes, it could compromise their “blind” neutrality and expose individual validators to undue legal risks / social pressures.
  2. Operational Constraints: The validator community is globally distributed and therefore reaching a timely consensus on a complex, evolving security threat is logistically / practically difficult and may not be achievable within the timeframes required to prevent asset loss.

Step 4: establish a Security Council

Rather than delegate these crisis decisions to the validator set, we recommend the creation of an independent committee, a Security Council, who would act as a check on power and ensure that the agreed framework guides actions in times of crisis.

The structure is designed to:

  1. Insulate the validator community: The Security Council takes on the technical and ethical burden of the immediate response, allowing validators to focus on their primary mission: maintaining the security and uptime of Gnosis Chain.

  2. Provide an expert check on power: By appointing a council of recognised experts and committed community members on the basis of their objectivity, integrity and experience, we ensure that intervention is guided by a rigorous, agreed-upon framework, rather than ad hoc pressure.

This could be a five-member council, with members chosen from outside of Gnosis Ltd on the basis of their objectivity, integrity, and experience. Gnosis Ltd could make recommendations for council members and we would welcome nominations from the community.

3. Communications

We will strengthen our crisis comms process to improve quality and timeliness of updates to the community and partners. A clear crisis comms plan will ease the decision making burden placed on the Crisis Response team, allowing them to focus on what matters while still keeping the community informed. However, it’s important to note that information may need to be withheld from the public domain while decisions are being made and implemented.

This includes making sure that there is a spokesperson defined in each case who will ensure timely updates.

Future Possibilities

As tools like Phylax evolve there is a possibility of managing risk tolerance at a dApp level but it is too early to rely on this entirely at this stage. We could look to bring tools like this into the Gnosis ecosystem to empower dApps building on Gnosis to define their own strategy.

If this rough framework seems agreeable, the next step would be for us to produce a more detailed proposal for the community to assess through the GIP process.

Next Steps

The next step is to produce a formal version of this proposal for DAO approval. This will include the assessment criteria for intervention, process commitments for communication and nominations for the security council. We welcome input on all these points and more.

I’ll be hosting a community call at on Thursday, 2pm UTC where I’ll look forward to your feedback and ideas.

Within about one month this proposal will be presented to the DAO as a GIP.

5 Likes