BanklessDAO Incident Report - Governance Sybil Attack

Hi @0xbaer , I really appreciate you trying to understand where I am coming from.

Just to extend on this a little bit…
b-DIP 08 was the reason that I thought it was important that I bring this to light so quickly.
This is because I find all of the current multi-sig holders (except for 1) ARE in the server. Just a quick search shows they have been active in our community within the last 10 days.
I have personally found 6 of the 7 signers are easily accessible and responsive to anything of importance.
If others do not feel the same, it is important to consider some of them may have notifications muted or only the @mention notification on.

For instance, during the time that everyone was in ETH Denver, I noticed abnormal activity with the token. I tried to tag the multi-sig signers, but somebody has changed the discord role tag, so that the tag could not revive @mentions. I reported this to ops
Like I reported to ops, I know that a few days prior it had been able to, because I was able to use it days prior to this.
I reached out to @frogmonkee via Twitter and gave him the link. He promptly responded and joined the thread.
@Grendel has been responsive via DM’s, even extending his calendly to chat with him. He is involved when needed and demonstrates he does what is best for the DAO and what being a multisig signer requires of him.
@Kouros is always reachable and responsive via tagging and is involved with issues concerning the DAO and as well has only demonstrated he wants what is best for the DAO and does what is required of him as a multisig signer.
While I have seen some mention that @0x_Lucas is unavailable via DM’s (consider that he may have them off or only open to friends) I have found that he is responsive and active within our server and when I had a question, I went to him directly in the HQ server and received a response.

While change and term limits are go[quote=“0xbaer, post:24, topic:5533, full:true”]
Hey @Sprinklesforwinners, I’m having mixed feelings before I reflect on mine! Let me try to understand where your line of thought is coming from!

From your recent posts both on the Mirror and on Froum, it seems like you think the DAO is corrupt; the power is held in the hands of a few. And the post that you thought you were highlighting this truth hasn’t got the expected result.
That’s where you have planned to exploit the system and prove your point?

I get your frustration;

for someone who is actively contributing to the system, you might feel that you are working on borrowed land.
Almost all of the key powers which connect the DAO to the web2 world are residing in the hands of a few, and these members aren’t anywhere to be found.

I do agree with you here! It is now concentrated in the hands of a few, And for new members of the system, they could feel that these members are kinda like the untouchable entities who run the world.

Others in the DAO aren’t that paranoid as they have worked with these members in the past and are trying to change that centralisation.
An example of that initiative is [bDIP-8]. There are also conversations on putting term limits for different roles etc.
Even Guest Pass holders had held a GC seat, proving that we are open and give value to reputation over anything else.

I value you as a contributor. Your Ops/ administrative skills are very valuable.

IMO the best path forward will be to voluntarily step down on all DAO-wide roles you hold in the DAO. and get your point let the projects decide how they what to handle this situation for themselves.
[/quote]
We are being told that the multi-sig signers aren’t active within the community and aren’t preforming their duties as signers. This simply is not true. we are just lead to believe it is true, and because trusted members of our community say something , we just believe them.

As I was writing this, I went to look back to see who changed the @multisig tag to not receive notifications. I can no longer see this, as my L2 was removed. So I am now no longer able to (view only - not change) anything.

I actually find that strange also. The L2 role tag (which only allows messages to be pinned, role tags assigned, the ability to delete others messages and to VIEW the server audit log) was simply taken away from me.
Was it because I am not deserving of the tag or because I am not wanted to see the audit log and changes made.
Either way, can 1 person decide this?

Does my simply showing how someone could attack our governance on 1 platform constitute not being able to view things on another platform?

I do know that the Governance Dept is working on a lot of issues. I have been offered to join their meetings. I can’t join at the times that their meetings are held, but I am also unsure of the exact meeting times, as they change frequently and there seems to be frequent unannounced meetings. I could add comments to the documents, but 1. I was explicitly told that they were not looking to change what is there in anyway 2. I simply am not in the position to volunteer a large amount of my time anymore. Even just reading and processing the new docs being worked on would take anyone hours.

So because I am unable to attend calls that aren’t announced, at a time that I am unavailable or because I cannot volunteer countless hours on something (where suggestions are not permitted) I am not able to participate in our Governance Department.
Again, to note anyone can put up a proposal. How can there only be “the right way”, when my way, your way and the governance Departments way may all be different.
I was under the impression that we our values include
” Decentralized Governance
We put decision making into the hands of the collective. We create legitimacy through an environment where the best ideas win.”
Culture
We reward action and embrace risk. We empower our community to continually drive new initiatives by providing a space to self-organize and quickly move from idea to action.

How does standardizing anything to 1 way fit in there?

I will resign from any roles that I currently have, if my fellow peers that hold the same or similar roles within the units would like me to.
For me, this means those that hold the Grants Committee role tag and the PM Guild role holders/multisig signers.

I have already had both projects that I was working on remove my role tags and block me from access to everything (including access to my work and content that I have created)

I really wonder what is in place to protect the contributors in general but also those that buy the L1 and subsequently works hard to become an L2. It seems like absolutely nothing.

1 Like