Who can actually change the rules of a protocol?
"Decentralised" is not a vibe. It is a claim about where authority sits, and unlike most claims in this industry it is checkable in about fifteen minutes from public data.
Every protocol has an answer to five questions: who can upgrade the contracts, who can change the parameters, who can pause it, who controls the treasury, and how fast any of that can happen. The documented answer and the operative answer are frequently different documents.
The layers of authority
Admin keys. The most common real answer. A 3-of-5 multisig that can upgrade the implementation behind a proxy is, functionally, five people who can rewrite the protocol — including rewriting what it does with your deposits. Check the threshold, the number of genuinely independent signers, and whether anything stands in front of it.
Timelocks. A mandatory delay between a passed proposal and its execution. This is the highest-value governance control in existence, because it converts a silent change into a public one and gives users a window to leave. A 48-hour timelock with a publicly queued transaction is a materially different risk from instant execution by the same signers.
Token-weighted voting. One token, one vote — with three consequences that follow immediately. Whoever accumulates tokens accumulates control. Participation is typically low, so effective control requires far less than a majority of supply. And tokens can be borrowed.
That last point produced the clearest case in the field. In April 2022 an attacker submitted two malicious proposals to Beanstalk, waited out the protocol's roughly 24-hour governance delay, and only then used a flash loan to acquire a supermajority of the governance tokens and execute — vote and execution inside a single transaction. Roughly $182m was drained, netting on the order of $76m after repaying the loan. Nothing was hacked. The governance mechanism executed exactly as specified. The specification assumed that acquiring voting power takes time, and flash loans had removed that assumption years earlier.
Read that case against the timelock paragraph above, because it complicates it. Beanstalk had the delay. The malicious proposal sat publicly queued for about a day, and nobody looked. A timelock does not stop an attack by existing; it buys a window that someone has to be watching. And note precisely which assumption failed: the delay ran between proposal and execution, while the votes were bought at the moment of execution. Snapshotting voting power at proposal time, not the delay alone, is what closes that door.
Delegation and quorum. Where delegation is used, a handful of large delegates usually decide outcomes. The published rule may say "the community votes"; the operative rule is the top ten addresses.
Off-chain dependencies. The front end, the domain name, the hosting account, the oracle, the relayer, the sequencer. A protocol can be genuinely immutable on chain and still be unusable if a centrally controlled front end disappears — or genuinely dangerous if it is replaced. Front-end and DNS compromises redirecting users to draining contracts have happened repeatedly, and no contract audit touches them.
The treasury. Who signs, what it holds, and whether it is denominated in the protocol's own token — which returns you to the circular-collateral problem from the FTX lesson, now with governance attached.
What checking it looks like
A protocol describes itself as immutable and community-governed. Fifteen minutes of public data show that:
- the proxy admin is a 2-of-3 multisig controlled by the founding team,
- there is no timelock, so an upgrade executes immediately, and
- 61% of circulating voting power sits with five addresses.
All three facts are public. None contradicts the marketing copy in a way a lawyer would object to. Together they describe a system in which two people can change the rules today.
This is not an accusation against any particular protocol — it is a description of how often the checkable answer differs from the stated one, and of how cheap the check is relative to the exposure.
Try it now
- Pick a protocol and find its proxy admin address on a block explorer. If it is a multisig, record the threshold and the number of distinct signers, and note whether the signers are publicly identified.
- Check whether a timelock contract sits between governance and execution, and find the delay in seconds. Then decide whether that delay is long enough for you to notice and act.
- Open the governance token's top holders, add the top ten, and compare the total with the quorum and majority needed to pass a proposal. Write the two numbers side by side.