GnosisDAO Treasury: Independent Risk Teardown

Hi all, necessary disclaimers first: I’m part of the team behind Sentralis, a cryptocurrency portfolio risk- and scenario-analysis tool, with which this analysis was produced. Nobody at Gnosis asked or paid for it.

Everything below is built from publicly disclosed positions (covering ~84%, about $137.7M, of the treasury by value; data basis and limitations are spelled out at the end). It’s descriptive, not advice. If you spot an error in the data basis, say so and it will be corrected. And if the treasury WG would rather see this with their own assumptions (off-chain positions, custom scenarios), I would be happy to re-run it. Hope it’s useful input for the community.

TL;DR (five model estimates, each conditional on the assumptions and data coverage spelled out at the end; none of them is independently verified, a prediction, or advice):

  1. Economically (and obviously), the Gnosis treasury is one large ETH position. ~66% of covered value is ETH or an ETH wrapper, and the wrappers moved at correlation ≈ 1.0 with ETH over the measurement window. The sector split (37% liquid staking vs 26% L1/L2) doesn’t capture that overlap.

  2. That position (again, obviously) depends on one protocol. Lido holds 52% of covered value. In the modeled incident (temporary freeze plus a mild depeg), the estimated loss is roughly 19% of covered value.

  3. It moves slowly. Under the liquidity model’s crisis assumptions (5% of daily volume, order books only), roughly $18.5M is exitable to cash within a week. If those assumptions hold, that figure, not the $137.7M headline, is the scale GIP-151 redemptions would draw on.

  4. The volatility follows from the composition. A 20%+ intra-year drawdown occurs in 97–99.8% of simulated paths, and the simulated 1-in-20 bad year lands between −41% and −64% depending on model choice.

  5. The scenarios agree on magnitude. Run independently, the engines put modeled stress losses in a $20–90M band, an order of magnitude above the ~$5M one-day VaR.


Snapshot date: 2026-07-10/11 (prices as of 2026-07-10 daily close; analysis run 2026-07-11)

Data basis: publicly disclosed treasury positions (token holdings, protocol allocations, and vesting as published on the community treasury dashboard), tracked-asset subset

Covered value: $137.7M across 17 assets, approximately 84% of the on-chain treasury by the July-10 snapshot. Not covered: bridged/regional stablecoins (USDC.e, EURe, GBPe, ZCHF, BRZ, BRLA), the Bakkerland RWA tokens (bCSPX/bIB01/bIBTA), the Centrifuge RWA pool, the Frankencoin ZCHF debt leg, HOPR/PNK/OLAS/GIV/small caps, and the off-chain TheDAO loan.


Intro and Backdrop

A risk check seems warranted given three recent events:

  1. GIP-151 approved pro-rata treasury redemptions, turning “how liquid is the treasury, really?” from a theoretical question into a targeted practice.

  2. The April hack wave (Drift $295M, KelpDAO $293M) demonstrated cascade risk: Aave’s TVL fell ~46% without any direct exposure. Protocol dependencies transmit stress even when code doesn’t fail.

  3. The Gnosis ecosystem’s own incidents (Safe SquidRouterModule, May 25; Gnosis Pay delay module, June 1) were a reminder that infrastructure risk includes module and patch-velocity risk at home.

Five scenarios were run against the treasury’s public book. Each section reports one; the last section consolidates the assessments. Throughout, headline figures are model outputs under stated parameter choices; where a different defensible choice would move a number materially, that sensitivity is noted inline.


1. Sector concentration

Sector Value Weight
Liquid staking (stETH, wstETH) $51.3M 37.2%
Infrastructure L1/L2 (ETH, OP, ZK, ALT) $36.1M 26.2%
Stablecoins (DAI/sDAI, USDC, USDS, USDT, GHO) $25.7M 18.7%
DeFi (COW, BAL, WETH*) $12.6M 9.2%
Other (SAFE, WBTC) $11.9M 8.7%

Concentration math: the sector HHI comes out at 0.258, above the 0.25 “concentrated” threshold, with an effective sector count of just 3.9. The single largest sector (liquid staking) is 37% of the book, and once you note that LSTs are ETH exposure, the economic picture is starker than the sector table: ETH-complex assets (ETH + WETH + stETH + wstETH) are ~66% of covered value.

Stress applied, “stablecoin crisis” preset (stablecoins −15%, DeFi −40%, LSTs −20%, cross-sector propagation on):

Modeled loss: −$22.1M (−16.0%), of which LSTs contribute −$10.3M, DeFi −$5.0M, stablecoins −$3.9M. On top of that, −$2.4M propagates into the L1/L2 sleeve despite zero direct shock. The shock sizes are preset choices, not forecasts; the propagation term is the model’s way of expressing that correlated neighbors don’t leave “unshocked” sectors untouched.

* Classification per CoinGecko category data; WETH lands in DeFi rather than L1/L2, a taxonomy quirk that slightly understates the true ETH-complex weight shown above.

2. Protocol concentration

With holdings attributed to the protocols that actually hold them (Lido, sDAI, Spark, Sky, Aave, Safe locked allocation, Balancer, Uniswap, Rocket Pool, CoW vesting):

  • Lido holds $71.3M, 51.8% of the covered treasury (69.5% of the protocol-attributed sleeve).

  • Protocol HHI: 0.502, an effective protocol count of 2.0. The engine flags Lido as a single point of failure (>50% of sleeve).

  • Next largest dependencies: sDAI $11.8M, Spark $5.4M, Safe locked $4.5M, Aave $2.9M, Sky $2.7M.

Stress applied, Lido incident (temporary freeze with 80% eventual recovery + a mild 20% stETH depeg during the event):

Estimated loss: $25.7M, or 18.7% of covered value, from a single protocol event whose severity assumptions are deliberately moderate (compare: stETH traded ~7% off peg in June 2022 without any protocol failure). Different recovery and depeg assumptions scale this number up or down roughly proportionally.

If the diversification debate wants a number to anchor on, this scenario offers one. The point isn’t whether Lido is safe (historically it has been); it’s that in the modeled event a single protocol moves about a fifth of the covered treasury while the second-largest dependency moves ~3%. Whether that concentration is acceptable is a judgment for GNO holders; the scenario only puts a number on it.

3. Exit liquidity in two regimes

Modeled as disciplined liquidation (fixed participation in daily volume; slippage from venue depth), including per-holding lock status (vested COW, locked SAFE) and DeFi unwind delays:

Normal market (10% participation, 14-day horizon) Crisis (5% participation, 7-day horizon)
Exitable within horizon $32.6M (23.7%) $18.5M (13.5%)
Un-exitable within horizon $105.0M $119.1M
Weighted avg. days-to-exit 43 days 198 days
Full-liquidation slippage bill $46.9M (34%) $69.8M (51%)
Hard-locked (vesting/locked) $6.3M $6.3M

Position-level structure (crisis-model estimates): the model puts the fast sleeve at USDC (~half a day), WETH (~2 days) and USDT; ETH at ~6 days for its liquid portion and ~27 days for a full exit; and the ecosystem positions as effectively frozen at disciplined participation: SAFE ~93 days, USDS ~330 days, COW ~6.7 years. These day-counts scale roughly inversely with the participation assumption: allow 10% of daily volume instead of 5% and they halve; accept more market impact and they shrink further.

GIP-151 relevance: the redemption mechanism gives GNO holders a claim on “liquid treasury assets.” Under this model’s crisis assumptions, that phrase corresponds to ~$18.5M inside a week without heavy market impact; beyond that, the model has redemptions either waiting weeks-to-months (the ETH/LST complex) or paying a slippage bill measured in tens of millions. Both figures are conditional on the participation and volume-data assumptions above; the point is the order of magnitude, not the third digit.

Important fairness note: these figures measure market-exit liquidity (order books only). They do not model redemption paths: Lido’s withdrawal queue converts stETH→ETH 1:1 in days, and sDAI redeems near-instantly. Read the stETH/wstETH/sDAI lines as “time to exit to cash through markets,” which is the relevant measure in a redemption or depeg scenario where everyone uses those same redemption queues.

4. Correlation under a crisis regime

Baseline (365-day correlations): 1-day 95% VaR $4.9M (3.5%), expected shortfall $6.1M, annualized portfolio volatility 41.1%, diversification ratio 1.47.

Applying crisis-regime correlations: VaR rises to $5.0M, a change of just +2.2%.

That non-result is the finding. Crisis correlation stress barely moves this portfolio because there is almost no diversification left to destroy: ETH, WETH, stETH and wstETH already sit at pairwise correlation ≈ 1.00 in the baseline. Economically, the covered book behaves like one large ETH position (~66%), a stablecoin sleeve (~19%), and ecosystem tokens that were themselves 0.65–0.71 correlated to ETH over the measurement window. The usual crisis mechanism, where assets that looked independent suddenly start moving together, has nothing to grab here, because the book never looked independent.

5. Monte Carlo, two models

Two deliberately different simulation models, same portfolio, same seed. The gap between them is itself a finding:

  • Model-based (GBM): lognormal paths on the full 365-day covariance matrix, zero drift. Pure volatility structure, no market view.

  • Empirical bootstrap: resamples blocks of the portfolio’s actual daily returns from the last 365 days, which inherits the real fat tails and the realized drift of what was a bear-market year for the ETH complex.

Terminal value (1 year) GBM vs. today Bootstrap vs. today
5th percentile (bad year) $81.1M −41% $48.9M −64%
25th $117.0M −15% $68.0M −51%
Median $155.1M +13% $89.0M −35%
95th percentile (good year) $335.2M +143% $192.4M +40%
Risk metric GBM Bootstrap
1-year 95% VaR $56.5M (41%) $88.7M (64%)
Expected shortfall (95%) $66.6M (48%) $93.6M (68%)
Probability of a down year 39% 83%
Median intra-year max drawdown 35% 51%
Paths breaching a 20% drawdown 97% 99.8%

How to read the two columns: GBM answers “what does 41% volatility do to a portfolio with this correlation structure, with no view on direction?” Its +13% median is a lognormal artifact, not a forecast. The bootstrap answers “what if next year statistically resembles the last one?” Its −35% median simply replays the fact that the trailing year was deeply negative for two-thirds of this book. Neither column is a prediction; the real distribution sits somewhere in between. Which column a treasury plans should plan against is a risk-appetite choice for the DAO. The width of the band is itself the finding:

  • A 20%+ intra-year drawdown occurs in 97–99.8% of simulated paths under either model. That counts as near-certain but only within the models: both extrapolate from the trailing year’s volatility regime, and a calmer regime would lower the frequency.

  • The simulated 1-in-20 bad year sits between −41% and −64% depending on model choice. The spread is model risk, and a concrete illustration of why any single-model VaR figure for a book like this deserves skepticism.


The combined picture

The five scenarios describe the same treasury from five angles, and the findings point the same way. As throughout, these are model estimates conditional on the stated assumptions and on the public data being complete and correctly attributed:

  1. It behaves as one position. ~66% of covered value is the ETH complex, and the measured correlations treat the wrappers as the same asset (ρ ≈ 1.0). The sector split (37% LST vs 26% L1/L2) doesn’t capture that overlap.

  2. That one position lives mostly in one protocol. Lido holds 52% of covered value; effective protocol count 2.0. The modeled Lido incident (freeze + mild depeg) prices out at ~19% of covered value.

  3. The position is slow to exit through markets. In the model, even in normal markets 76% of the book can’t exit within two weeks at disciplined participation; under the crisis parameterization, seven-eighths can’t exit within a week. On those assumptions, GIP-151’s “liquid treasury assets” corresponds to ~$18.5M of crisis-liquid value.

  4. The volatility follows from the composition. At 41% annualized vol, both simulations make a 20%+ intra-year drawdown the dominant outcome (97–99.8% of paths), with the simulated 1-in-20 bad year between −41% (model-based) and −64% (empirical bootstrap of the actual trailing year). On these numbers, the ~19% stablecoin sleeve is the buffer between the DAO’s operating budget and that distribution.

  5. The stress scenarios agree on magnitude. Stablecoin-crisis: −$22M. Lido incident: −$26M. 1-year 95% VaR: −$57M to −$89M depending on model. Taken together, and only as far as their assumptions hold, the engines describe stress losses in the $20–90M band, against a one-day VaR of ~$5M.

Please note: none of this says the composition is wrong. A DAO whose mission is Ethereum infrastructure holding staked ETH is a coherent strategy, and the hard-lock share is small (4.6%). What the numbers describe is a risk profile that is deliberate, concentrated, and slow-moving. If the community finds these estimates useful, three quantities lend themselves to being tracked on a standing basis instead of argued once:

  • Crisis-liquid coverage: liquid-within-7-days value ÷ plausible redemption/operating demand (today, under this model’s assumptions: ~$18.5M against whatever GIP-151 may summon)

  • Single-protocol exposure: Lido share of the covered treasury (today: 52%; in the scenario’s arithmetic, each 10pp held at a second staking venue would reduce the modeled single-event loss by ~$5M)

  • Stablecoin runway: stablecoin sleeve ÷ monthly operating spend, read against how common a 20%-drawdown year is in the simulations (97%+ of paths)

Method & limitations

  • Every headline figure in this document is a model output, conditional on (a) the public data being complete and correctly attributed and (b) the stated parameter choices (participation rates, shock sizes, recovery/depeg assumptions, correlation windows). Different but defensible parameter choices move the results materially; treat the numbers as orders of magnitude, not point facts.

  • Public on-chain positions only; ~84% coverage of the July-10 snapshot by value. Bridged/regional stables, RWA positions, the ZCHF debt leg, and the off-chain loan are excluded. The missing sleeve is mostly stability-adding, so concentration findings here are, if anything, slightly overstated in the treasury’s favor on liquidity and slightly understated on diversification.

  • LP positions decomposed 50/50 into constituent legs (estimate). Protocol attribution follows the public dashboard’s protocol section, scaled to on-chain totals.

  • Liquidity model: fixed participation-of-ADV with venue-depth slippage; exchange volume only. Protocol redemption queues (Lido withdrawals, sDAI) are not modeled, and they materially improve real-world stETH/sDAI exit paths (see §3 note). Volume data for several assets uses aggregated market data rather than order-flow (flagged internally; treat thin-asset day-counts as order-of-magnitude).

  • Correlations from 365 days of daily returns; crisis regime estimated from a 5-year window. Monte Carlo: two models, 25,000 paths each, seeded and reproducible: GBM on the full covariance matrix (zero drift) and a block bootstrap of the actual trailing-365-day return series (which inherits that year’s realized drift). Distributional metrics, not forecasts; the inter-model spread is reported as model risk.

  • One classification quirk (a $20k position tagged to the wrong sector) was left as-is; immaterial at 0.01% of value.

  • All figures at 2026-07-10 prices. Snapshot-based; no protocol-code audit; nothing here is investment advice.


Analysis produced with Sentralis, a cryptocurrency portfolio risk- and scenario-analysis engine.

Yes, that’s correct. Independent. Thank you for your affirmation.

1 Like

You identified the risk → the response mechanism is too slow → the ecosystem already has the infrastructure for faster response → agent SAFEs are that infrastructure.

The liquidity gap under GIP-151 is the operational finding. ~$18.5M crisis-liquid against an unknown redemption demand is a number the DAO should probably maintain as a standing dashboard metric, not a one-off snapshot. If redemptions spike during a drawdown (when the treasury is least liquid) the community is making governance decisions against stale data.

The correlation non-result (§4) is actually the most useful model output. Crisis correlation stress barely moves the portfolio because there’s nothing left to correlate. That’s not a bug in the model; it’s an honest description of the book. The DAO owns one position. Own it deliberately rather than discovering it during a drawdown.

The missing piece in all five models is automation velocity. Every scenario assumes human governance cadence: proposal → discussion → vote → execution, measured in days-to-weeks. A 20% intra-year drawdown that hits 97%+ of paths doesn’t wait for a Snapshot vote. The same ecosystem that built Safe created the infrastructure for programmatic treasury agents — SAFEs controlled by autonomous agents with pre-authorized risk parameters, rebalancing bands, and liquidity targets that execute at machine speed rather than governance speed. The risk framework here is solid. The response framework is still DAO-timeline. That gap between “we can measure the risk in hours” and “we can respond to it in weeks” is the one this analysis doesn’t quantify, and it might be the largest number in the whole book.

1 Like

Fair point, and yes, it’s a real gap: all five models price the state of the book at a point in time, none prices the response path. Every scenario implicitly holds the portfolio static through the event, which amounts to assuming the response takes longer than the shock. However, given the time governance decisions get made, that assumption might well be justified for the fast events.

That said, we could still try to quantify it: running the same scenario set against the current book and the post-response book, and price the delay window between them at 0 days (agent execution), then e.g. ~7 days (expedited vote) and ~30 days (full proposal). This would give us the latency cost you’re describing as the spread. But there is one missing input: the post-response composition. I did not find an adopted rule that indicates the parameters you describe (bands, liquidity targets). GIP-151 defines redemptions, not the rebalancing.

Thus, if you or anyone in the thread names a concrete rule (e.g. “rebalance to an X% stablecoin floor, funded from the LSTs, once drawdown crosses Y%”), I can rerun the analysis.

One thing to note: picking X and Y is the diversification decision itself, and that part stays at governance speed no matter what executes it.

One caution: pre-authorized execution is a risk of its own, and the analysis already touches it. The backdrop lists the SquidRouterModule and Gnosis Pay delay-module incidents because a treasury agent is structurally a module with standing permissions over the assets, and it acts on bad inputs at the same speed it acts on drawdowns. So the honest comparison is latency risk against automation risk and both can be sized.

1 Like

I appreciate your thorough engagement with this and yes, “latency risk vs automation risk, both sized” is exactly the right comparison. Let me give you concrete parameters.

The rebalancing rule:

  • Trigger: If the stablecoin sleeve drops below 20% of covered treasury value, rebalance.

  • Source: Fund from the LST sleeve (stETH/wstETH).

  • Target: Restore stablecoin sleeve to 25% of covered value.

  • Execution: Single swap, single transaction. The agent reads on-chain treasury composition, compares it against the trigger, and if it is breached, submits the rebalance.

20% is a floor just above the current ~19% so the rule activates on any further deterioration, not a massive crash. 25% is a modest target, not a full de-risk. The goal isn’t to exit the ETH position; it’s to maintain a buffer that prevents forced redemptions during a drawdown.

On the automation risk: The SquidRouterModule and delay-module incidents you cited failed because they had broad permissions and no bound. An agent SAFE with three constraints doesn’t share that attack surface:

  1. The bound is set before the agent receives signing authority. The DAO votes on the trigger (20%), the target (25%), the funding source (LST sleeve), the single authorised contract, and the single authorised function. These are committed on-chain. The agent cannot change them, cannot approve new spending and cannot upgrade itself.

  2. Cooldown between actions. No two rebalances within 72 hours. A flash-crash trigger fires once, not repeatedly.

  3. Human override, no delay. The DAO multisig can revoke the module’s permissions in a single transaction, faster than the agent’s cooldown window. The agent can act quickly; the DAO can stop it completely.

The honest comparison you offered: 0-day (agent) vs 7-day (expedited) vs 30-day (full proposal) would be genuinely useful. If the models show that a 20% → 25% rebalance executed at T+0 preserves even $3–5M more than the same rebalance at T+7, the automation premium pays for the security audit with room to spare.

The framing: governance sets the parameters at its own pace. The agent enforces them at the speed the parameters were designed for. The DAO picks X and Y. The drawdown doesn’t wait for the vote.

Thanks for the input. Reran the analysis with the July-10 book and same seeds.

Two observations first.

  1. A drawdown pushes the stablecoin share up, away from the 20% floor, so a crash alone can’t fire the trigger; it fires on rallies, if the DAO spends stables, or on a stablecoin depeg (where it would sell stETH to buy stablecoins mid-depeg).

  2. And the tigger fires today: 18.7% is already below the floor, so this is one $8.7M stETH/wstETH→USDC swap, now vs T+7 vs T+30.

Across the trailing year’s windows, a 7-day delay cost $31k median, $2.5M worst week, never $3M; 30 days tops at $3.6M. The rebalance itself cuts 1-year 95% VaR $5–7M and lifts crisis-liquid to ~$27M (+47%), at any latency.

Stated differently, doing the rebalance at all improves the one-year risk numbers by $5–7M. Doing it seven days sooner saves about $31k in a typical week of the past year. The benefit comes from the decision, not from how fast it gets executed.

1 Like

riskypete, I appreciate the rerun. The median latency cost being $31k is actually more useful than a larger number would have been, because it isolates the real finding.

The trigger fires today. The rebalance cuts VaR by $5–7M and lifts crisis liquidity by 47%. Those benefits are sitting on the table, unclaimed, while the DAO discusses governance reform in another thread.

The argument for automation isn’t that governance is slow. It’s that governance is unreliable at the moment of action. The trigger fired. Nobody moved. An agent SAFE with ERC-8312 metering wouldn’t have saved 31k on execution timing, it would have executed the 8.7M swap already, and the treasury would be $5–7M safer right now.

Speed is the wrong metric. The metric that matters is whether the decision the analysis already endorses actually gets executed. Today, it hasn’t. That gap between “we know what to do” and “we did it” is what the execution substrate closes.


Small correction: the analysis endorses nothing. It priced a rule this thread proposed; adopting one is the DAO’s decision, and no rule has been adopted, so there was no trigger to fire. The numbers are there for whoever makes that decision.