A nonprofit once handed back roughly $500 million and dissolved itself on purpose. Here is what that taught crypto about legal structure, onchain governance and who actually holds power.
Three structures, three different jobs. Only one of them can sign a contract.
In May 2021, a nonprofit gave away 84,000 governance tokens. At the time they were worth close to $500 million.
Then it shut itself down. On purpose.
That nonprofit was the Maker Foundation. The protocol it had been stewarding is known today as Sky Protocol.
And that single decision still frames a question every onchain project eventually has to answer out loud.
Who actually runs this thing?
There are three answers in circulation. A DAO. A foundation. A company. Most people treat them as competing options.
They are not. They are layers. And the protocols that hold up under pressure tend to use all three.
DAO vs Foundation vs Company: What Actually Separates Them
Short version first.
A DAO is a decision-making system. Token holders vote, code executes. No registered office, no signature on a lease.
A foundation is a legal entity with no owners. It can hold IP, sign contracts, publish reports and instruct a law firm. It is not supposed to control the protocol.
A company is a legal entity with owners. Fast, familiar, easy to hire through. It also has a boss, which is exactly the problem.
The real dividing line is not ideology. It is far more boring than that.
Who can a court sue. Who can open an account. Who signs when a vendor asks for a signature.
A DAO, on its own, cannot sign anything. That gap is the entire story.
Signing power, liability shield and control, side by side. The gaps are the reason legal wrappers exist.
Why a Pure DAO Leaves Token Holders Legally Exposed
Here is the part most “what is a DAO” explainers skip.
If a group acts together for profit without registering an entity, most legal systems already have a default box waiting: general partnership, or unincorporated association.
In a general partnership, members are personally liable for the group’s debts.
Read that twice if you hold governance tokens and vote with them.
This is why “we are just a DAO, we have no entity” stopped being a flex around 2023. Governance is not a shield. Governance without a legal wrapper is exposure.
The Crypto Foundation Structure Is a Legal Wrapper, Not a Boss
Foundations exist to absorb that exposure without becoming a boss. Three shapes dominate.
Cayman foundation company. Ownerless. Run by a small board or council, with token holders named as beneficiaries. Common for large token ecosystems holding IP and contracts.
Wyoming DUNA. A US nonprofit association purpose-built for DAOs, effective July 1, 2024. No mandatory board. Bylaws can point directly at onchain votes. Members are shielded from the association’s debts.
The catch is honest and worth saying out loud. A foundation fixes the paperwork problem by creating a small group of humans who hold a pen. That is a genuine centralization cost.
Which is why wording matters. The footer of skyeco.com reads:
“This website is managed by Sky Frontier Foundation (SFF). The SFF is an independent entity and does not have authority over Sky Protocol, its smart contracts, or governance decisions.”
That is a foundation publicly disclaiming control over the thing it supports. Not modesty. Architecture.
The Company Model Buys Speed and Cannot Shed Control
Companies are still everywhere in crypto, for good reason. You can hire. You can sign an engagement letter. You can buy insurance.
What you cannot do is make the control disappear.
Regulators have not drawn a neat line between “the DAO” and “the dev shop.”
If your company holds admin keys, your decentralization story is a marketing asset, not a legal defense.
So the pattern that actually emerged is not DAO or foundation or company. It is:
DAO for authority
Foundation for legal capacity
Independent companies for execution
Three layers, deliberately kept apart.
Authority, legal capacity and execution, kept in separate hands.
How Sky Ecosystem Splits Authority, Publishing and Execution
Sky Ecosystem is a clean worked example, because each layer is named differently on purpose.
Sky Governance holds authority. Staked SKY activates voting power over risk parameters, collateral types, debt ceilings and protocol upgrades. Proposals move through forum review, then onchain voting, then execution. Once executed, a change cannot be reversed directly. It can only be challenged by passing a new proposal.
Sky Frontier Foundation publishes. Reports, disclosures, formal positions. It does not set parameters.
Sky Agents execute. Spark, Grove, Obex, Osero and others are independent capital allocators. They access USDS liquidity under governance-set risk parameters and deploy it. They are not subsidiaries.
The naming discipline is not pedantry. It is the difference between “Sky Governance voted to change the rate” and “the foundation changed the rate.” Only one of those is true, and only one survives a regulator reading it.
Scale check. Sky Protocol currently shows roughly $14.15B in Total Collateral backing about $11.48B in stablecoin supply.
A coalition of crypto organizations then wrote to the US Treasury asking for federal recognition of the DUNA model.
Second, credit agencies started grading governance. When S&P Global assigned Sky Protocol a B- issuer credit rating, the first ever given to a DeFi protocol, it flagged governance concentration and low voter participation as risk factors. Not code quality. Governance.
That is the real trend. Governance design is now a credit input.
And the numbers deserve honesty. Most DAO proposals draw participation in the 5% to 15% range.
An OpenZeppelin governance review found that in 17 of 23 major DAOs, the top 10 delegates held enough voting power to pass a proposal on their own.
Decentralization on paper is not decentralization in practice.
Decentralization on paper versus decentralization in practice.
So Which Structure Should a Protocol Actually Pick?
A rough decision frame.
Public infrastructure with a global contributor base? Foundation plus DAO.
Distributing revenue to holders? A nonprofit DUNA will not fit. Look at LLC structures.
Pre-launch with a small team shipping fast? A company, plus a credible plan to reduce control.
Already decentralized and worried about member liability? A DUNA or an offshore foundation, and stop delaying.
The one answer that is clearly wrong is doing nothing and hoping the word “decentralized” holds up in court. Ooki settled that argument.
Eight years of protocols answering the same structural question.
The Question Nobody Has a Clean Answer To
Here is what I keep circling back to.
The Maker Foundation dissolved itself in 2021. Sky Frontier Foundation exists today and openly disclaims authority over the protocol.
Both were the right call at the time, which suggests these structures are not permanent identities at all. They are stages.
So, a question worth arguing about below.
If a foundation’s job is to eventually make itself unnecessary, how do you tell the difference between one genuinely winding down its influence and one quietly becoming the boss?
After a final rule upending the RIF process took full effect, performance will now be the top priority, with seniority and tenure serving as tiebreakers.
New Amazon board member Kevin Mandia is a cybersecurity veteran. (Photo via Amazon)
Amazon named cybersecurity veteran Kevin Mandia to its board of directors, adding new security expertise a few months after former NSA director Keith Alexander stepped down.
Mandia founded Mandiant, the breach-investigation firm Google acquired for $5.4 billion in 2022, and remained at the search giant as a strategic advisor through July 2025, according to his LinkedIn profile. He now leads Armadin, an AI security startup he started last year.
Amazon said in its announcement that “cybersecurity is one of the most consequential risks and responsibilities organizations face today, and the threat landscape continues to evolve rapidly alongside advances in AI.”
Amazon added a cybersecurity specialist to its board in 2020, when it elected Alexander, who also led U.S. Cyber Command. Mandia comes from the other side of the field, with two decades spent investigating corporate breaches rather than defending government networks.
His appointment also puts an AI security entrepreneur on the board of a company whose cloud infrastructure underpins much of the internet. Armadin, founded in September 2025, uses AI to run attacks against corporate networks, probing defenses the way an intruder would.
The board’s Security Committee, which oversees Amazon’s cybersecurity policies and its response to significant cyber incidents, is now chaired by Dan Huttenlocher, dean of the MIT Schwarzman College of Computing. Mandia joins as a member, along with former Bridgewater co-CEO Jon Rubinstein.
Amazon also named Mandia to the board’s Audit Committee, according to a securities filing.
Mandia received 4,086 restricted stock units in connection with his election to the board, vesting in three equal annual installments beginning Nov. 15, 2027, the filing shows. The shares were worth about $1.03 million at Amazon’s closing price Wednesday.
The filing disclosed that his sister-in-law, Kristin Mandia, is an Amazon employee with an annual salary of $185,000. The company said her compensation is consistent with that of other employees at her level with similar responsibilities.
"Somewhere along the way we've lost the tolerance for federal workers to make a mistake when they're trying to do the best job that they can," said Rob Shriver.
Australia plans to let social media users choose algorithmic or follow-only feeds under new digital safety rules targeting platform design and control.
Australia plans to let social media users choose algorithmic or follow-only feeds under new digital safety rules targeting platform design and control.
Aave governance is considering an emergency Guardian powers proposal that would allow vulnerable lending pools to be frozen quickly during active security threats, without requiring immediate public write-ups.
It is a slightly uncomfortable proposal, and that is exactly why it matters.
On one hand, DeFi users want transparency. On the other hand, publishing too much detail during an active exploit can hand attackers a roadmap. Aave contributors are trying to solve that tension: how do you act fast enough to protect users without making governance feel opaque?
The proposal does not allow guardians to seize user funds or liquidate deposits. It is about emergency freeze powers.
For more details, visit the official Governance platform.
TL;DR
Aave governance is discussing emergency Guardian freeze tools.
The proposal would allow faster response during active exploit situations.
It does not give guardians power to seize deposits.
Why Emergency Tools Matter In DeFi
DeFi moves fast when things go wrong.
A bug, oracle issue, bad debt event, or market manipulation attack can escalate in minutes. Waiting for a full public governance process is not always realistic when funds are at risk.
That is why many large protocols use emergency roles.
These roles are supposed to pause, freeze, or limit certain functions while the team or DAO investigates. The difficult part is designing those powers so they are strong enough to protect users, but narrow enough that they cannot be abused.
Aave’s proposal sits right in that design problem.
Transparency Versus Security
The public-notice question is the most interesting part.
In normal conditions, users should expect clear explanations. If a market is frozen, people want to know why. They want to understand whether their funds are safe and when normal operations may resume.
During an active exploit, though, immediate disclosure can be dangerous.
If the issue is not fully contained, a public write-up may expose technical details that help attackers move faster. That is the argument behind delaying some disclosures until the threat is under control.
It is not an easy trade-off.
Aave Has To Protect A Large System
Aave is one of DeFi’s core lending protocols.
That means its risk controls matter beyond one market. Aave deployments sit across multiple chains and assets, with users relying on the protocol for borrowing, lending, collateral management, and liquidity.
Emergency response is not a side issue.
It is part of the protocol’s safety design. If governance cannot respond quickly enough, users can suffer. If emergency powers are too broad, users may worry about centralization.
Finding the middle ground is the hard part.
What The Proposal Does Not Do
The proposal should not be exaggerated.
It does not mean Aave guardians can take user funds. It does not mean deposits can be seized. It does not mean liquidations can be manually forced outside protocol rules.
The proposal is about freezing vulnerable markets during emergencies.
That distinction is important because “emergency powers” can sound scarier than the actual mechanism.
The DeFi Governance Lesson
Aave’s discussion shows how mature DeFi protocols are thinking about crisis management.
Early DeFi loved pure automation. Over time, protocols learned that some emergency controls may be necessary, especially when billions of dollars are at stake. The question is how to make those controls accountable.
The best version of this proposal would protect users during live threats while preserving post-incident transparency.
That is the balance Aave governance now has to debate.
This article draws on Aave governance materials relating to the emergency Guardian powers proposal.
This article was written by the News Desk and edited by Samuel Rae.
This report is based on information released by Governance. at Governance
Attack by air ironically showed the resilience of the air traffic control system, plus the skill and nerves of people who landed a million passengers safely.
In this March 16, 2017 photo, air traffic controllers work in the tower at John F. Kennedy International Airport in New York. President Donald Trump is looking to shift responsibility for the system from the government to a private, nonprofit corporation run by airlines and other aviation interests. (AP Photo/Seth Wenig)