[1IP-106] Establish the 1inch DAO Security Council and Ratify a Rotation of the DAO Treasury Multisig Signers

Simple Summary

This proposal establishes the 1inch DAO Security Council as the formally ratified signer set of the DAO Treasury multisig and ratifies the replacement of 7 of the 12 current signers with the slate listed below, voted on as a single slate.

Abstract

The 1inch DAO Treasury is controlled by a 7-of-12 Safe whose signers were selected in 2021. This proposal:

  1. Constitutes the treasury signer set as the 1inch DAO Security Council, with a defined mandate, duties, and disclosure policy

  2. Ratifies a 7-seat rotation as one slate

  3. Requires that this rotation and every future signer change be executed on-chain through the DAO’s SafeSnap module, so signer changes demonstrably flow from governance.

  4. Establishes signer protections: a DAO-ratified good-faith safe harbor and liability cap now, with contractual indemnification, defense-cost advancement, and insurance to follow upon adoption of a DAO legal wrapper.

Motivation

Every comparable DAO :Arbitrum, Optimism, ZKsync, ENS, Aave, Polygon, Compound, Lido — subjects its security council or guardian multisig to token-holder ratification. 1inch DAO does not: the current signers were appointed five years ago, there is no charter, no removal procedure, no liveness requirement, and past signer swaps bypassed governance entirely. Ratifying the signer set by DAO vote closes the single largest legitimacy gap in 1inch DAO’s structure and follows the industry standard whole-slate ratification model used by Optimism, ENS, and Aave.

Specification

1. Establishment of the Security Council

The Council’s powers are limited to:

  • executing transactions approved by DAO vote via the SafeSnap module;

  • vetoing malicious or faulty payloads during the 72-hour timelock at the existing 7-of-12 threshold

  • emergency response to protect treasury assets.

  • The Council has no discretionary spending authority

  • Composition. 12 members; threshold unchanged at 7-of-12.

  • Term. Until further notice: members serve until they resign, are removed, or are replaced by DAO vote. Any change to the signer set or threshold requires a Snapshot vote and execution via the SafeSnap module; owner-executed signer changes are prohibited.

    • If required, the full Council composition is will be submitted for re-ratification by a single confirm-or-replace Snapshot vote every 12 months from execution. Re-ratification does not interrupt Council operations.
  • Removal. Any member may be removed by a standard Snapshot vote. A member who fails two consecutive liveness checks, or is unreachable for 30 consecutive days, is deemed inactive and will be scheduled for replacement . A removed member may only return through a subsequent DAO vote.

2. Incoming members

The incoming team consists of delegates, core contributors and an external contributor. They are: aegis, ampheatmin, bob, bonaci,faradaemon, spindoctor & tonet. The remaining 5 seats are held by continuing signers of the existing multisig, whose seats are ratified as part of this proposal.

3. Member requirements and key management

  • Suspected key compromise is reported to the Council immediately; the affected member abstains from signing and a replacement process begins.

  • Members maintain baseline proficiency in secure key management and signing standards

4. Liveness and accountability

  • Members acknowledge and act on signing requests within 72 hours in normal operations and within 24 hours during a declared emergency.

  • The Council performs a scheduled liveness check at least once per year: a signed message or test transaction proving key access for every member.

  • Failure to satisfy a scheduled liveness check feeds the inactive-member process defined under Removal above, mirroring the automatic-removal standard of the Optimism Security Council charter.

5. Disclosure and transparency

  • Members disclose material conflicts of interest on any transaction they are asked to sign and abstain where conflicted.

6. Emergency actions

  • Emergency response is limited to actions strictly necessary to protect treasury assets from imminent loss, such as vetoing a malicious or faulty payload during the timelock.

  • Emergency powers exclude discretionary transfers, investments, and any action that can safely wait for the standard governance process.

  • Within 72 hours of any non-drill emergency action, the Council publishes an incident report on the governance forum covering the threat, the action taken, and the rationale. The DAO may review and, where applicable, reverse the action by Snapshot vote.

7. Compensation

  • Council seats are not compensated under this proposal. Any future compensation requires a separate 1IP with a defined budget and funding source.

8. Signer protection and indemnification

  • Charter protections. The protections in this section are adopted by the DAO through this vote and bind through governance rather than through any legal entity. Each member acknowledges the charter in writing before activation; upon adoption of a DAO legal wrapper, the protections convert into contractual agreements per the Wrapper handover below.

  • Good-faith safe harbor. A member who in good faith signs, or declines to sign, a transaction pursuant to a valid DAO vote and this charter incurs no personal liability to the DAO or token holders for losses that later result. Council service is ministerial execution of DAO decisions and creates no fiduciary or trustee relationship beyond this charter.

  • Carve-outs. No protection under this section, and no wrapper-stage indemnification, advancement, or insurance, applies to fraud, deliberate misconduct, or knowing breach of this charter.

  • Wrapper handover. Upon the DAO adopting a legal wrapper, the wrapper executes uniform signer agreements with each member providing contractual indemnification, advancement of defense costs, and, where available on commercially reasonable terms, directors-and-officers insurance, supplementing the protections in this section.

  • Survival. These protections survive resignation, removal, or replacement in respect of acts and omissions during service.

9. Execution

  • Upon a passing Snapshot vote, the rotation is executed on-chain through the SafeSnap module against the DAO Treasury Safe (eth:0x7951c7ef839e26F63DA87a42C9a87986507f1c07) using atomic swapOwner calls. The Safe never leaves its 7-of-12 configuration during execution.

  • Execution passes the standard reality.eth escalation period (minimum 72 hours) and the 72-hour Timelock before taking effect.

  • Within 7 days of execution, the Council completes a verification signing exercise confirming every member has key access, and the published roster is updated.

Rationale

Slate ratification and overall process follows industry standards and precedent set from other DAOs. Open-ended terms avoid election overhead.

A single-slate vote is atomic, it avoids partial outcomes in which some seats rotate and others do not, leaving the Safe in an unratified hybrid state. The 7-of-12 threshold is retained because it matches the existing veto quorum and is battle-tested for this treasury; changing composition and threshold in the same vote would confound the result. The annual re-ratification checkpoint preserves token-holder control without standing election machinery, as a lighter-weight alternative to the six-month cohort elections used by Arbitrum, proportionate to a treasury-scope council.

Consideration

Alternatives considered: (1) per-seat elections on the Arbitrum model, with staggered cohorts and standing election infrastructure, rejected at this stage as disproportionate for a treasury-scope council and adoptable later by amending this charter; (2) retaining appointment of signers, rejected because it perpetuates the legitimacy gap this proposal closes.

This proposal supersedes selected signer arrangement described in the 1inch DAO Guidelines. The DAO governance documentation is updated to reflect the Security Council within 7 days of execution.

As a standard proposal, this vote requires the 10 million Unicorn Power quorum on a 7-day Snapshot vote. Delegates are encouraged to signal voting intentions during the temperature check so quorum coverage is visible before the Snapshot opens.

The signer protections in Section 8 involve no legal entity and no treasury spend: the safe harbor and liability cap are adopted by this vote and bind through governance; contractual indemnification, advancement, and insurance follow at the wrapper stage through uniform signer agreements. Until then, the protections operate as a governance commitment rather than a contract.

Security Considerations

The rotation replaces a majority of a signer set whose key liveness is currently unverifiable. During execution, the Safe never drops below its 7-of-12 threshold because swapOwner replaces members atomically.

The SafeSnap question for this rotation must be actively monitored throughout the escalation window: fraudulent and spoofed questions have been observed across DAOs, and the bonding mechanism plus the 72-hour escalation period are the defense.

2 Likes

Do you support this proposal

  • Yes
  • Abstain
  • No
0 voters