On paper, an attacker moved against the $1.5 million treasury of Umbra Privacy. On paper, the futarchy governance layer built by MetaDAO stopped it. The headline writes itself: the model proves its worth.
I do not trust the headline. I trust the exploit. And the exploit has not been published.
No code has been released. No post-mortem with market depth at the moment of the attack. No disclosure of the attack vector. One data point — a single successful defense — is being treated as a theorem.
I spent 2017 auditing a vesting contract that let early investors drain 40 percent of a token supply through an integer overflow. That project's community believed in its audits too. This is why I separate what happened from what is claimed to have happened. The defense is real. The proof is not.
This is a bull market. Bull markets are where “proves its worth” headlines are printed without audit. I am here to run the audit the headline skipped.
Futarchy is a governance model proposed by economist Robin Hanson in 2000. It replaces one-token-one-vote with a two-stage decision. The community first votes on which conditional markets to consider. Then prediction-market traders price the outcomes. A proposal is implemented only if the market for “token price rises if we pass this” trades above the market for “token price falls if we pass this.”
The logic is clean. Governance stops being a popularity contest and becomes a market — a continuous auction of conviction, where each participant's judgment is backed by capital at risk.
MetaDAO is the most prominent live deployment of futarchy, operating its own prediction markets. It is not a simulation. It is an experiment with real money and real governance authority. Umbra Privacy integrated it into treasury management — a decision that put a privacy protocol's control layer into a market-based decision engine.
Umbra Privacy is a stealth-address protocol. It is a privacy layer, not a lending market. The treasury held about $1.5 million. A governance attack was attempted. MetaDAO's futarchy mechanism was in the loop. The attack failed.
The clean narrative collapses on closer inspection. The event does not say what mechanism stopped the attack, what kind of proposal was attempted, how much market liquidity was present, or who stood on the other side of the trade. It says: an attack failed, and a governance model happened to be in the room.
Here is the uncomfortable part. Umbra is a privacy protocol attacked through its governance layer. Privacy protects data in motion. Governance protects control of the treasury. A protocol can encrypt every transaction on earth and still lose everything in a single malicious vote. The two properties are not connected. This event is the evidence.
Governance attacks come in recognizable forms. Vote capture: accumulate enough voting power to pass any proposal. Proposal weaponization: craft text that reads benign and executes maliciously. Timelock racing: exploit the delay between approval and execution. Social engineering: convince the signers of a multi-sig to sign. Against a multi-sig, an attacker targets a person. Against snapshot voting, an attacker targets a wallet. Against futarchy, an attacker must target a market — and markets are the most studied, most gamed, most adversarial artifacts humans have built.
What futarchy actually asks.
Futarchy does not ask whether a proposal is good in any moral or technical sense. It asks whether the proposal raises the token price. These are different questions. A proposal that dumps the treasury into a buyback will raise the price and pass, even if it destroys the protocol's mission. A proposal that fixes a critical vulnerability may lower the price if the market misreads it, and fail. The mechanism is a price-maximizer, not a truth-finder. It optimizes for the token, not for the protocol.
This distinction matters more in a privacy protocol than anywhere else. Umbra's value proposition is not a token price. It is a property: the inability of third parties to link transactions. That property cannot be priced by a prediction market in any meaningful way until the market defines it. Markets do not measure what matters. Markets measure what is tradeable. What is tradeable in a governance market is the token. The token and the protocol are related, but they are not identical. The gap between them is the attack surface that this first attack did not need to exploit.
The defense did not prove the mechanism.
Start with the statistical vacuum. One defensive success. One attack. One ecosystem. There is no base rate for futarchy governance attacks, no control group, no repeated trials. Most governance attacks fail for mundane reasons: a flawed payload, a miscalibrated vote, a gas bug, a rushed execution. Without knowing why this one failed, crediting the governance model is a narrative choice, not a conclusion.
I do not trust the audit; I trust the exploit. Until the attacker's transaction history is public, until we see the exact moment the market rejected the proposal, the mechanism's role is unverified. An audit of a defense is the same as an audit of a contract: it says nothing until an adversarial test is run.
Two attack surfaces are worse than one.
One-token-one-vote governance has a single attack surface: acquire tokens, pass a proposal, drain the treasury. Futarchy has two: acquire tokens and pass the vote, or manipulate the prediction market.
An attacker only needs to win one. A defender must defend both. This asymmetry is structural.
The manipulation path is the one I would take. A futarchy prediction market is a financial market. Markets are not truth machines; they are capital-weighted opinion. Under thin liquidity, opinion is purchased cheaply. A $150,000 buy on a thin book moves a price signal guarding a treasury worth ten times that. The attacker spends a fraction of the treasury to flip the signal, the proposal passes, and the treasury pays the attacker's costs.
This is the same mechanism I identified in 2020 while simulating Uniswap v2 pools. The constant-product curve x*y=k produces asymmetric risk in volatile conditions. A pool looks deep until a large directional trade arrives. The depth is not a property of the pool. It is a property of the order book standing behind it. Prediction markets built on automated market makers inherit exactly this fragility.
I have run the alternative test too. In 2026 I was asked to verify a “decentralized” compute network. The consensus mechanism was vulnerable to a Sybil attack through five thousand compromised IPs controlled by a single entity. The advertised decentralization was a shell. Prediction markets can be gamed the same way: colluding addresses spoofing volume and depth, quotes that exist only to decoy the honest participant. A governance model that depends on market depth depends on entities it cannot verify.
The timing attack.
Futarchy has a settlement delay. The market must run, close, and be checked against the token price at a reference block. That delay is a manipulation window. An attacker who controls the timing of a proposal waits for a low-liquidity block, a holiday weekend, an exchange outage, or a moment when the token price is already depressed by market noise.
In 2017, my audit of the vesting contract was not about the logic of the token model. It was about a boundary condition: the overflow triggered at a value the authors never considered. The same principle applies here. Futarchy's defenders will consider the obvious attack — a large proposal, a malicious wallet, a sudden market move. The attacker only needs to find the boundary condition the defenders did not consider. The timing of the submission. The settlement block. The depth of the order book at 3 a.m. UTC. These are the attack surface.
I have timed this class of manipulation in simulations. The window between proposal submission and market settlement is the soft underbelly. A sophisticated attacker does not fight the market at its fairest hour. They submit when liquidity is at its lowest, when the token is already volatile, when the settlement oracle is about to read a stale price. The mechanism's security is a function of the worst hour it defends, not the average hour.
The reflexive token problem.
Futarchy uses the token price as the signal of protocol health. The proposal outcome depends on the token price. The token price depends on the proposal outcome. This is a closed loop.
Consider the attack that does not need to win the market. An attacker launches a proposal the market correctly believes will damage the protocol. The token price falls. The market prices in the damage. In a naive conditional model, the proposal can pass precisely because the damage is already priced.
This is the seigniorage lesson I learned while reverse-engineering the UST model in 2022. Terra's reward loop looked coherent while demand grew. It collapsed when demand stopped growing. Complex financial engineering does not eliminate failure modes. It hides them inside a pricing mechanism that stops being reflexive only after the collapse.
Futarchy has the same property. The price signal that governs is the price signal being governed. When the mechanism is healthy, it is invisible. When it fails, it fails all at once.
The ammunition problem.
In a futarchy, the attack and the defense are transacted in the same token. The attacker buys tokens to push the conditional market. The defender buys the opposite side. Both sides mobilize the same ammunition.
The outcome of a governance decision is therefore determined not by the quality of the argument, but by the size of the war chest. Capital, not wisdom, wins.
A $1.5 million treasury is defended by a market. The defense costs the market participants real money: time, capital, attention. The attack is optional. The defense is mandatory. Every legitimate proposal imposes a defense tax on the honest side. An attacker can run a campaign of repeated small attacks, draining the defender's capital and attention, until one lands. This is adversarial attrition, and futarchy has no countermeasure for it.

Run the game theory. The attacker's expected value is the treasury amount times the probability of success, minus the cost of the attack. The defender's expected value is the treasury amount times the probability of failure, minus the cost of defense. Because the attacker selects the moment and the strategy, the probability of success is not fixed. It rises with every failed attempt, because every failure is a lesson. The defender learns nothing from a successful defense except that the last attack failed.
I have watched this pattern across asset classes. The same dynamic makes liquidity provision dangerous for large depositors: the moment volatility spikes, the asymmetric payoff of x*y=k transfers wealth from passive providers to the active trader who understands the risk. The passive participant is the product. In futarchy, the honest voter is the product.
The liquidity subsidy trap.
The critical question is where the prediction market's liquidity came from during the attack. If it was organic — token holders depositing because they believe in the protocol — the defense is meaningful. If it was subsidized — by the protocol, by MetaDAO, by liquidity emissions — the defense was purchased with the very treasury it protected.
Stop the subsidy. Watch the liquidity evaporate. Watch the next attack land in an empty book.
This is the liquidity-mining problem in a different costume. A protocol that subsidizes its own TVL is not a protocol with users. It is a protocol buying its own metrics. A prediction market subsidized to defend a treasury is not a governance mechanism. It is a marketing budget with an execution layer.
I have said this for years. The APY a protocol pays to attract liquidity is not revenue; it is a cost. The moment the subsidy stops, the real user count is revealed. Futarchy's defense surfaces deserve the same question. Who paid for the depth, and for how long?
The regulatory corner is unpriced.
Futarchy depends on prediction markets. Prediction markets are not neutral infrastructure. The CFTC has pursued prediction-market platforms. Polymarket, the most visible venue, was fined in 2022 and forced to restructure its access. A futarchy that allows United States users to trade conditional outcomes is a derivatives venue without a license, or a gambling venue without a license, depending on the prosecutor.
Apply the Howey test to the token that fuels the market. Money invested. A common enterprise. A reasonable expectation of profits. Profits derived from the efforts of others. The prediction-market token checks every box. A token that is both a governance instrument and a trading instrument is a security under the most plainly stated reading of the law. The market narrative does not care. The regulator does.

This is not a hypothetical. It is a constraint on the model's scale. If MetaDAO restricts US access, it loses the market depth that makes the price signal meaningful. If it does not, it invites a regulator to shut down the very mechanism that defended the treasury. The governance model is caught between regulatory safety and market quality. That trade-off does not appear in the treasury-defense narrative. It appears in the first subpoena.
The N=1 error.
One success proves the mechanism can work when the market is calm, liquid, and attentive. It does not prove the mechanism works against a sophisticated adversary who has studied the model. The first attacker was likely opportunistic. The next attacker will have read the post-mortem.
I have watched this cycle before. In 2021 I analyzed a PFP collection where most of the “rare” traits were procedurally generated through flawed random seeds. The floor price collapsed once the mechanism's predictability was published. Every system marketed on a single success is a system being measured for its next exploit. The exploit is a matter of iteration, not of possibility.
The audit institution is missing.
There is no certification authority for governance models. No SOC 2 for futarchy. No accredited auditor that can sign off on the security of a prediction-market governance layer. When a smart contract fails, the industry has learned to demand an audit trail. When a governance model fails, the industry demands nothing. The consequence is that every claim about governance security is unfalsifiable in the short term. The N=1 defense is the perfect example. Nothing in the public record allows an independent third party to verify that futarchy, rather than luck or attacker error, prevented the theft.

I have built my career on the opposite assumption: the code says what it does, and the exploit proves what the code missed. Governance models have no code in the same sense. They have incentives. Incentives are harder to audit than bytecode, which is precisely why they deserve more scrutiny, not less.
The standard of evidence being set.
The community that celebrates this defense is asking the wrong question. They ask: can futarchy stop an attack? The correct question is: how much does it cost to stop an attack, and who pays? Defense worked in this case because the attacker was small. The system's next test will not come from a small attacker. It will come from an actor who can outspend the market. That actor exists. Every ecosystem has one.
What would actually change my mind.
I want three data points.
First, the market depth at the moment of the attack. The number of unique counterparties. The volume on each side. If the defense came from a broad, deep book, the mechanism deserves credit. If it came from one or two whale addresses, the mechanism remains centralized, and the defense is another name for whale preference.
Second, the attack vector. If this was a vote-buying attack, and the prediction market directly rejected it, that is a clean defensive win. If this was a sloppy exploit that failed on its own, the governance model is irrelevant to the outcome.
Third, the cost of the defense. How much did the defending side spend, in fees and slippage, to hold the line? If the cost approaches the attack's potential payout, the mechanism's efficiency is near zero. A governance system that costs as much as the asset it protects will be abandoned in the next bear market.
The bulls are not wrong about everything.
Futarchy has a structural advantage no snapshot vote possesses: a falsifiable outcome. When a voter says “this proposal is good,” a snapshot vote records an opinion. A prediction market records an opinion with money on the line. The penalty for being wrong is real. The incentive to read, verify, and analyze is real. That is a genuine improvement over performative voting.
The second advantage is the adversarial market. A traditional governance attacker faces a passive voter base. A futarchy attacker faces a market of counterparties who profit from being right. That is a different class of opponent. The Umbra defense likely worked because the market priced the attack correctly, and the cost of fighting the market exceeded the attack's payout. That is not nothing.
The third advantage is traceability. Market prices are public. Manipulation attempts leave a detectable footprint in the order book and settlement data. No committee. No auditor. No single oracle. The market polices itself through arbitrage: a manipulated signal is a free trade for someone trading against the manipulator.
This is the closest governance has come to a self-verifying mechanism. I do not deny that.
Give futarchy its best case. A $100 million treasury. A deep, subsidy-free market with hundreds of active traders. A proposal that would drain the treasury. The market prices the proposal down by 20 percent. The attacker must now spend more than the expected profit to push the signal. The defense holds. This is a real scenario, and it is not impossible. But note the conditions. Deep market. High participation. Rational pricing. All three conditions are properties of the market, not of futarchy. The model does not create them. It consumes them.
But it only works at scale. A small protocol with a $1.5 million treasury cannot sustain the liquidity depth that makes a prediction market honest. A large protocol that can sustain it will attract regulators. The model is squeezed between the size it needs and the size that makes it illegal.
Elegance is not robustness. Intelligence is not capital. A thin market is not a market. The mechanism is only as strong as the depth behind its price signal, and the depth is only as strong as the incentive to provide it.
The code compiles, but the reality bankrupts.
The first attack was the easy one. It was opportunistic, under-researched, and under-capitalized. The next attack will be different. It will target the market, not the vote. It will wait for a thin liquidity window. It will merge vote capture with market manipulation on both books, and it will extract the treasury before the mechanism registers what it is looking at.
Run the scenario again with a $1.5 billion treasury. The prediction market must now mobilize enough capital to defend ten thousand times more value. The cost of defense scales with the asset. The cost of attack scales only with the attacker's patience. At some point, the defense becomes uneconomical. That is the threshold where every governance model fails, futarchy included. The question for Umbra and MetaDAO is whether they know where their own threshold sits.
The question is not whether futarchy survived its first test. The question is whether it can survive the attack designed for it. When the post-mortem is published, read it the way I will. Not for the headline. For the depth of the book. The number of counterparties. The time of the attack. The true cost of the defense.
The transaction is permanent; the mistake is not.
Illusion has a price tag; truth has none. The truth about this defense is unpublished, unaudited, and statistically insignificant. That is not a dismissal. That is a demand for the data.