defirisk.co
rubric v1.7.0

Governance token concentration (Gini)

A governance & admin factor in the v1.7.0 rubric. Measured per protocol on a s cadence.

Methodology how we score#

What this measures
This factor computes the Gini coefficient of governance token holdings across the top-N holders — producing a concentration measure between 0 (perfectly equal distribution) and 1 (fully concentrated in one address). The assessment reads on-chain token holder distributions for the governance token and applies the Gini formula, displayed alongside the protocol's current quorum threshold to provide context on whether a small number of whales can unilaterally control governance outcomes.

Why it matters
Highly concentrated governance token distributions are a prerequisite for governance attacks by large holders without requiring flash loans. When the top five holders collectively control more than 50% of the voting supply, any two or three of them can pass a proposal unilaterally. This factor surfaces the structural power distribution within a protocol's governance, which is orthogonal to the attack surface factors (RD-F-036, RD-F-037) but relevant for assessing governance capture risk from large holders. It is a display field rather than a critical factor — concentration alone is not sufficient for a D or F grade — but it informs the holistic governance picture.

Green / Yellow / Red
Green is assigned when the Gini coefficient of voting token distribution is below 0.6 and no single address controls more than 20% of voting supply. Yellow covers Gini 0.6–0.8 or single-address control of 20–40%. Red is assigned when a single address or a clearly coordinated group controls more than 40% of voting supply, enabling unilateral governance outcomes.

Common gray cases
This factor is grayed when the governance token is vote-locked (non-transferable), where the standard holder scan does not accurately represent voting power, or when governance is off-chain and token distribution is not directly linked to proposal authority.

Notable historical examples
No cross-hacked incidents currently linked in database for this factor.

Measurement what to look for#

Compute the Gini coefficient of governance token holdings across the top-1000 holder addresses.

Data & output #

Data source
Etherscan token holders API + on-chain `Transfer` event history via subgraph (The Graph governance subgraph or protocol-specific)
Output format
Green / Yellow / Red
Evidence artifact
Holder distribution snapshot JSON + Gini coefficient + top-10 share % + block number
Confidence signal
green = Gini <0.7 (reasonably distributed); yellow = 0.7–0.85; red = >0.85 or top-3 holders control >50%; gray = governance token not identified or no on-chain governance

Scored protocols 0 carry this factor#

No protocols have been scored for this factor yet.

Linked hacks no historical incidents linked#

No historical incidents are linked to this factor.
rubric_version v1.7.0factor RD-F-047category 2carried 0critical no