The executable has two actions. The 9-day timelock and Security Council cancel guard only the Endowment (Action 2). Action 1 sends 1,000,000 ENS to the Foundation Safe 0x9C7d…FA19E — which I read on-chain at block 25708345: Safe v1.4.1, threshold 3 of 5, zero modules, zero guard. The largest liquid asset the proposal moves lands in the one Safe with none of the accountability the proposal advertises.
Read on-chain at block ~25,708,068 (mainnet, 2026-08-08, public RPC): the EndowmentTimelock (0x0bcC…406C) is a pre-4.7 OpenZeppelin TimelockController, minDelay 777600s = 9 days, self-admin, executor open. Foundation Safe (0x9C7d…A19E) hasRole PROPOSER=true; the ENS DAO wallet (0xFe89…44b7 / wallet.ensdao.eth) holds NO role — PROPOSER=false, ADMIN=false. schedule() and grantRole() are gated by roles the DAO does not hold, so a future DAO proposal to restore itself reverts on execution. This is a PRE-execution finding: the Endowment Safe (0x4F20…FE64) getOwners() is still the DAO wallet — the swap has not run. Minimal fix, doable now: point the ownership swap at a timelock whose proposers array lists BOTH the Foundation Safe and wallet.ensdao.eth; do not transfer the Safe until the DAO is a proposer on its new owner.
This account hasn't done anything visible recently.
This account hasn't commented on any proposals yet.