New Ethereum talks, every Monday. The week's conference uploads by event, in your inbox.

Loading player…

Dark DAOs and Private Coordination by Sarah Allen | Devcon SEA

DevconTue, Oct 7, 2025, 12:00 AM

Dark DAOs allow for undetectable private coordination and are feasible to launch in Ethereum today. In this talk, I will introduce Dark DAOs, highlight applications that should be aware of their possibility, and point to the ways they can be harnessed as mechanisms for both prosocial and antisocial coordination. I will also discuss how the encumbrance of keys utilized by Dark DAOs can generalize. I will introduce Proofs of Complete Knowledge as an available countermeasure. Speaker(s): Sarah Allen Skill level: Intermediate Track: Coordination Keywords: Coordination, DAO, Privacy, dark Follow us: https://twitter.com/efdevcon, https://twitter.com/ethereum, https://warpcast.com/devcon Learn more about devcon: https://www.devcon.org/ Learn more about ethereum: https://ethereum.org/ Visit the https://archive.devcon.org/ to gain access to the entire library of Devcon talks with the ease of filtering, playlists, personalized suggestions, decentralized access on Swarm, IPFS and more. Devcon is the Ethereum conference for developers, researchers, thinkers, and makers. Devcon SEA was held in Bangkok, Thailand on Nov 12 - Nov 15, 2024. Devcon is organized and presented by the Ethereum Foundation. To find out more, please visit https://ethereum.foundation/

Transcript

[Music] all right hey everyone so I'm Sarah Allen and today I am going to talk about dark Dows and private coordination um so my goal today is that I will first introduce the technical Concepts that you need to know to understand dark Dows I'll give a state of knowledge on the research that's been done since they were identified in 2018 till present um I will introduce some recent research contributions and then I'll talk about active mitigations for projects that may want to proactively uh defend against dark D so first up let's talk about private keys so private keys are must be kept secret to be secure they're assumed to be held by one person or entity uh any signature given with a private key is assumed to be created by its owner and anything signed is assumed to be signed with that owner's consent so the Assumption here baked into many of our modern systems is that private keys are exclusively held and used by their owner um and because of this the assumption that a private key is equivalent to an identity is often made but what if an owner could share or rent the right to sign with their key uh in that case private key could no longer be used at instead of identity and this is the case with encumbrance so what is incumbrance um a secret key can be generated in a trusted execution environment and the key then continues to live in that te uh the te can then be used to apply complex policies to that private key and to its use going forward um so here you can see a user who's generated a private key within a trusted execution environment they then have access to that key but their access is going to be mediated by any programs that are being run by the te so in the presence of tees and encumbered accounts while the private key must still be kept secret to be secure that's the role of the trusted execution environment in the case of an encumbered key you can no longer assume that that key is held by one person or entity uh you can no longer assume that any signature that has been made was done by that person or with their consent so the single entity address ownership assumption is what's broken by encumbrance and given that that assumption is made in any current blockchain systems this has wide ranging implications the implications of this broken assumption were first identified toward Dow voting in this 2018 post onchain vote buying and the rise of dark Dows by Philip Diane Tyler Kell Ian Myers and Ari jwes and in this post they identified a dark Dow as a decentralized cartel that buys onchain votes opaquely so in the dark uh potentially nobody not even the creator of a dark Dow can determine the total number of participants the total amount pledge so the treasury of the dark Dow and the precise logic of that dark Dow so here you can see the model of a dark Dow you have a collection of Voters who've all generated encumbered accounts uh they've pulled their encumbered keys and now a program can be run across all of those keys together that's the dark Dow um the program can be this sort of automated vote buying in which an adversary can bid for the right to run the program across all of their votes so it is this coordination trustless done through trusted execution environments that could be coordinated to vote in Dow so that 2018 blog post uh suggested the concept of dark Dows but it became more Concrete in 2023 in Dow decentralization floating block entropy bribery and dark Dows uh this paper was co-led by James Austin and Andre FAA um I contributed as did kushall Babble MIM n kelar and Ari jwes and this paper had two main contrib tions so the first was a new concept of decentralization in Dows which we call Vibe or voting block entropy uh Vibe conceptualizes decentralization and Dows as the blocks of Voters with aligned utility functions and so that contribution uh aimed to model decentralization in Dows as something that would be sensitive to things like private coordination through dark Dows the second main contribution of the paper was this model of a dark Dow led by James Austin so we were able to create a prototype of a dark that could currently be used in ethereum Dows so we did two different prototypes this is the first one um and I'll provide a research list at the end of this talk and also share it on Twitter um if you're interested in checking out the repository um but this first one is a set of contracts so they're solidity smart contracts uh which could be applied to ethereum they use Oasis which is a trusted execution environment blockchain as their backend um and you can see here that they could be applied so the policy that I've highlighted here uh could be applied for voting in snapshot um secondly uh we created something called a dark Dow light um so this you can think of this as sort of liquid staking for governance votes and um this is more userfriendly because users wouldn't need to encumber their own Keys rather they would deposit their voting tokens in a smart contract which would then uh give them something we call the DD token which is a token that would have the value of their votes plus the value of any bribes paid to participants in the dark Dow um and we have a demo available here too that you can find in the research list and these two prototypes proved the sort of proximate and practical reality of dark Dows although we're not aware of any currently operating um we posit that this is because dark Dows are an effective coordination tool in a truly decentralized Dow um and so the the current means of sort of collusion and coercion um or private coordination in Dows haven't yet needed dark Dows to support them however um the goal in releasing these prototypes was to highlight that this is a threat that da should start thinking about and taking proximate steps against um and I'll point out those later in this talk um but in the creation of that sort of dark Dow light it occurred to us that actually what's happening here this encumbering of private Keys is has much broader imp than dark Dows themselves and so we call that liquifaction liquifaction is an encumbered wallet platform which allows users to attach Rich multi-use policies to accounts it enables the credentials and assets of a single-end user address to be freely rented shared or pooled and it accomplishes these things privately with no direct onchain traces so broadly it enables the transfer of things thought to be non-transferable so what is imp Ed by liquefaction this broader tool so first let's talk about private Dows and the important thing to note when going through these impacted areas is that liquefaction is this General tool that has both pro-social and antisocial consequences so this first one is a particularly pro-social one which is that you could create a dow that is privacy preserving so its treasury is not known and its participants are not known on chain um this would have been particularly helpful in the case of constitution da um so constit da was a dow that was coordinated to try to pull funds to participate in an auction for a copy of the US Constitution a constitution Dow did not win that auction it's not possible to know whether they could have won the auction had they had a privacy preserving Dow however participating in a public auction with your max bid known AKA your treasury size certainly put them at a disadvantage so had they incorporated as a private Dow um they may have been more competitive as a group Next Up quadratic voting and quadratic funding so liquefaction and encumbrance are important things to note for system designers who are considering doing quadratic voting or quadratic funding um even if they do have strong identity systems um this is important because so quadratic voting quadratic funding as I expect many of you in the room know since we're in the Dow track um these are systems designed to subvert tyrrany of the majority so they're they aim to empower many small voices as opposed a direct token voting um however the problem with empowering many small voices in the case where small voices uh are able to sell access to their accounts is that it would allow a whale um to potentially Square their voting power or their funding power so if a whale were to separate their account funds across many small accounts um and those accounts were encumbered so they're able to do that in a way that where they can trust that they can vote on behalf of those accounts and they can vote with their own token weight from those accounts and then return the funds to themselves after the election um that whale is able to command much more power than indirect token voting um so definitely something to be aware of for people designing those systems next up soulbound tokens so soulbound tokens are designed to be non-transferable nfts um by being non-transferable they're supposed to have this special sense of identity that sits with that user account for its whole lifespan however if a soulbound token is sent to an encumbered account then the user who owns that account is able to rent out fractionalize or potentially sell the access to that soulbound token while retaining the soulbound token in their initial account so they won't have broken the policy in any detectable onchain way for that soulbound token uh but that soulbound token will no longer be non-transferable in practice next up rights to aird drops and activity based Rewards so rights to aird drops um are often or can be predicted for accounts ahead of time um however the there has not been a way to my knowledge for this sort of Speculator class to arrive for individual airdrop rights um but if individuals encumber their accounts to which they may receive future airdrops then they could potentially sell the right to receive aird drops to their account in a way that is trust minimize for the um these speculators who might buy those rights um but would unlock liquidity for those users at an earlier date than the airdrop itself um and then similarly activity based rewards so decentralized exchanges and some other services provide for instance better trading fees for users who do a lot of volume who do a lot of trading have a long history uh an encumbered account could be shared across many users even those who don't know or trust one another and so they could sort of pool their activity to get these rewards like lower trading fees together on their accounts uh next up dusting attacks so dusting attacks are um the sending of potentially unwanted tokens to many addresses at least to current date there isn't a way to prove whether or not you have custody of those funds so they've been sent to you now your account is potentially tainted um however using an encumbered wallet you can prove whether or not you have accessed those tokens and whether or not you truly hold in custody them so you could provide a proof that you do not actually own or command those tainted tokens next up lock tokens so when projects issue tokens for Grants to investors to early project participants often those tokens are locked and have a vesting period and that can be automatically enforced however if they're deposited to encumbered accounts then individuals could credibly sell the right to to those future unlock tokens while not transferring them from their current accounts um this might be desirable for those who don't want to show an onchain transfer that they've done this um but do want to unlock liquidity or decrease their stake in a protocol earlier on next up onchain and offchain transacting so transactions among incumbered accounts could Bend what we currently think of in terms of what needs to happen onchain versus offchain so for instance a set of encumbered accounts could trade with one another um but send only a few transactions on chain or messages on chain that they are making transfers among themselves um so this would be an interesting strategy to minimize gas next up multi- sigs so in a a multi signature scheme if you encumber one member of that multisig you could do two interesting things so the first would be you could add additional security by creating this multisig of mul sigs that wouldn't be visible on chain um so you could have many signers not identifiable on chain um for this mulig who need to command each visible signature um but the second is also a more Sinister one so a an adversary could potentially write the rent the use uh the use of a signature as part of a multisig um and then lastly allow lists so it's much more complicated to think about what it would mean to create a binding allow list in a world where users can trustless share accounts through encumbrance um and there are more potential implications both pro-social and antisocial in our upcoming liquefaction paper um so stay tuned if you're interested in more so now that I've gone through the many potential implications of incumbrance um I'm sure many are wondering what should one do in settings where you don't want undetected encumbrance you want to be sure that these things are not possible so you'll need to use something called a proof of complete knowledge um this is a cryptographic technique that was created by m mahimna kelar kushall Babble Phil Diane James Austin vitalic buan and Ari jwes and a proof of complete knowledge is a way to show fully unencumbered knowledge of a secret uh it goes beyond proving that the key uh it does this by proving that the key has been leaked over an insecure Channel and it can done with either a te or an Asic um the te version of this is possible to do on the local Enclave in an Android mobile phone so uh that's the more likely one to be applied so where is this all taking us encumbrance in tees breaks assumptions underlying blockchain systems and additional measures like CK will need to be added to systems that want to ensure that Aigner is the account owner is also a single individ idual or entity and the most practical implementation of CK relies on tees so in summary undetectable incumbrance is already practical and the defense against undetectable incumbrance will likely rely on tees so what's next uh we'll need to crowdsource a more complete list of systems that rely on assumptions that are broken by encumbrance we'll need to spread awareness that the signer may not be the account owner in current systems and designed either accept this or take measures against it for those wishing to take measures against it they'll need to adopt CK and we need to focus Community effort on deep research on tees to develop an open te for our open systems um and this one's important it's a big project and we're just now starting so if you're interested in getting involved here I would suggest that you head to the flash Bots Forum we call this project trustless te um and there are some posts already available on the writings website where you can check out the sort of early understandings of what's going to be involved in developing truly open hardware and I have a resource list here with clickable links to all of the papers and posts that I've discussed today um I will also be sharing this on Twitter and I believe the organizers are sharing the slides as well all right thank you for your time and attention and thank you so much to the organizers [Applause] thank you so much s for all of this and people you haven't starting asking questions with the QR code so before someone start placing questions there's someone who wants to have the microphone and start breaking the eyes with the questions there cool uh I'm so sorry for the very basic question but um just to make sure encumbrance is basically like lending someone your ID like to get into a club or something and then just getting that ID back what what that is that about accurate you can think of it as lending somebody or that is like one policy that a a trusted execution environment could enforce here so you can think about it as sort of lending your credentials similarly to lending your ID except that it's trustless so you could lend anybody your ID anywhere in the world um in a way where you don't need to know or trust them and it's automatically enforced and you can be sure you'll get it back exactly when they've said they were going to give it back to you as opposed to having any doubt or trust nice we have the first question here in the qer so what are their most likely dark DS now so I'm not sure and I don't want to give an answer as though I am sure um my assumption is that there are not dark Dows currently operating the places where dark Dows might be more credible threats are places that are the most decentralized where coordinating voters to have a sort of overwhelming share of power would not be practicable to do personto person anymore so if you think about Dows that are centralized where a few whales might be able to coordinate personally to ensure that a vote goes in their Direction um I would expect that to be a good candidate for a dark Dow currently um if you think about a system that is truly and ideally decentralized where it becomes totally imposs to coordinate people individual to individual to get this overwhelming share of votes that you need to pass something that's when a dark Dow starts to become relevant so it's as our systems reach these ideals that we've set for them for decentralization is when we need to most be on the lookout for these fantastic and we have our next question is is is there an example implementation of CK uh yes there is so there are a couple of example implementations of CK um you can find them on GitHub linked through the paper that I have shared in the resource list um one of them relies on an Asic one requires on Intel sgx which is a trusted execution environment and one relies on the uh The Enclave that is in an Android mobile phone um it's likely also possible to develop this for The Enclave that's within iOS or an Apple device but it hasn't yet been built awesome someone having problems with the QR code and wanting to ask a question we still have time for more questions well who wants to go ahead ah we have another question seems like it's a way for cbdcs on public blockchains I'm not sure I understand the question um um a cbdc a central bank digital currency is I think probably unlikely to want the particular set of privacy properties that a dark Dow has um but I'd be interested to hear more if someone wants to elaborate please the person who wrote the question wants to elaborate yeah so uh it seems like a way for centralized entities to control like multiple wallets um and to implement like a soft version of cbdc on a public blockchain so you mean it's a way for an entity who wants to control some aspect of a dow or a public blockchain to se control in an undetectable manner yeah yeah so I would say it's likely a large coordination and building lift to do this currently like I would be surprised surprised if this is currently ongoing and we're unaware of it um I it's hard to speculate on where dark Dows will go over time um or if they will become this sort of relevant problem um I could imagine them being tools for useful private coordination for groups that have a lot of funds to deploy um so I I can see your concern um but it's not one that I've considered thank you okay awesome we don't have more questions yes we have one more question that's right hi thanks for the qu uh thanks for the presentation um I had one question what would be the difference between an oligopoly and say dark Dows because I feel the difference would be between legal and illegal is that correct so I would say that the dark Dow um does not have to be lasting so it would depend on the structure it takes on the program that's being used um it would be possible for a dark Dow to be launched for just a single vote so uh somebody coordinates a dark Dow and then somebody launches a program that only coordinates a group of Voters or bribes A specific group of Voters for that particular round of voting then once the vote that is relevant to the whale that's paying them is over then the program is changed and so those voters that had been aligned in that earlier darkout are no longer aligned so I think the um as I understand olop a dark Dow might create a circumstance that looks similarly centralized for The Round In which that program is operating but it would be less lasting than an oligopoly in like a token system so it's kind of like a butt network but it can be turned on and off I trying I'm struggling to understand what the incentives of creating a bot network is and then for just one proposal and then turning it off unless of course that proposal means the collapse of of the the Dow right so I think the it's possible that one would be created and then immediately dissolved but it would be likelier my assumption would be that one would be created but then it would have different programs so different sort of adversaries who want to buy its weight for different votes so rather than one individual who's consistently commanding this network over time uh it might be more temporary based on who has the highest utility from that particular vote Yes hi um one possible solution to the problem could be using soulbound tokens with aliveness check at the point where you need to vote or for instance or claim your airdrop so you can't really sell or rent access to your private key if you need to prove that you're still the same person at that time so it would depend on how you structured it but I think you still actually would need to add proof of complete knowledge to that soulbound token so the sort of liveness check would need to be inclusive of this proof of complete knowledge because otherwise somebody who wanted to restrict the ability to vote in an election could permission it so that you could still uh succeed at that liveness check so provide the proof necessary from the soulbound token account that it's still sitting there and alive but then limit the way in which you can vote in that election so it could still say you can produce a liveness check but then you can only vote Yes but that would be built into the rules of the Dow or or that would be built into the program that would be commanding the use of the um secret Keys within the enclaves so the dark Dow would um create this set of rules by which you could cast your votes but you can do anything else from your account um so what you need to prove is actually that full unencumbered access to the secret key yeah okay I think let's see what you mean okay people thank you so much let's please give a great Applause to Sarah

Automatic transcript — names and jargon may be misspelled.