ENTER THE HIVESTAY UNREKTTRAP DETECTORMEET NEWBEE
09 / PROTOCOL CONTROL

Oracles & Governance

Learn how smart contracts receive external data, how protocols make decisions, and why voting power, multisigs and admin keys matter.

10 lessonsBeginner → confidentLearn at your pace
NEWBEE SCHOOL09Read the lesson. Check yourself. Continue when it makes sense.
IN THIS TOPIC
01 · Why oracles exist02 · Price feeds03 · Oracle manipulation risk04 · Governance05 · Token voting06 · Multisigs07 · Timelocks08 · Upgrade and emergency powers09 · Reading governance proposals10 · Governance checklist
LESSON 01

Why oracles exist

Blockchains cannot automatically know off-chain facts such as market prices, weather or sports results. Oracles provide external data to smart contracts.

MENTAL MODEL / EXAMPLE
A lending protocol may need an asset price to calculate collateral value.
CHECK YOURSELFOracle failure can become protocol failure.
LESSON 02

Price feeds

Price feeds may aggregate data from multiple sources or use specialized mechanisms to reduce manipulation.

MENTAL MODEL / EXAMPLE
A price is not just a number; source quality, update frequency and fallback logic matter.
CHECK YOURSELFCheck how a protocol gets and validates its price data.
LESSON 03

Oracle manipulation risk

If an attacker can influence a price feed or exploit thin liquidity used by the oracle, a protocol may misprice collateral or trades.

MENTAL MODEL / EXAMPLE
A low-liquidity market can be easier to manipulate than a deep market.
CHECK YOURSELFProtocols should use robust oracle designs; users should understand the dependency.
LESSON 04

Governance

Governance is the process through which protocol decisions can be proposed and approved. It may involve token voting, delegates, councils or multisig signers.

MENTAL MODEL / EXAMPLE
“Decentralized” does not necessarily mean every decision is made directly by every token holder.
CHECK YOURSELFRead the actual governance rules.
LESSON 05

Token voting

Voting power may be based on token balances, delegated voting power, staking positions or other mechanisms.

MENTAL MODEL / EXAMPLE
A small number of large holders can sometimes control a significant share of votes.
CHECK YOURSELFCheck quorum, thresholds and concentration.
LESSON 06

Multisigs

A multisignature wallet requires multiple authorized signers to approve an action. This can reduce single-key risk.

MENTAL MODEL / EXAMPLE
A 3-of-5 multisig requires three of five signers for an action.
CHECK YOURSELFMultisig is a control structure, not a guarantee of honest signers.
LESSON 07

Timelocks

Some protocols delay execution of sensitive governance decisions, giving users time to review or exit.

MENTAL MODEL / EXAMPLE
A timelock can improve transparency by creating a visible window before changes execute.
CHECK YOURSELFCheck whether critical admin actions are timelocked.
LESSON 08

Upgrade and emergency powers

Protocols may retain emergency pause, upgrade or parameter-setting powers. These can be useful for incident response but introduce centralized control.

MENTAL MODEL / EXAMPLE
The most important question is often: who can change the rules?
CHECK YOURSELFMap privileged roles before trusting a protocol.
LESSON 09

Reading governance proposals

A proposal should be evaluated by its exact code changes, parameters, voting process and execution path—not just the title.

MENTAL MODEL / EXAMPLE
A proposal called “security improvement” can still change fees or permissions.
CHECK YOURSELFRead the payload and supporting documentation.
LESSON 10

Governance checklist

Identify oracle providers, admins, multisig signers, timelocks, upgrade paths, quorum and emergency powers.

MENTAL MODEL / EXAMPLE
If you cannot identify who can change a protocol, your risk model is incomplete.
CHECK YOURSELFNEWBEE rule: know who controls the controls.
NEWBEE RULE

Learn → Verify → Protect.

Before moving money, connecting a wallet, trusting a claim or signing a transaction, slow down. Identify the exact asset, network, contract, source, permissions and risks.

Oracles & GovernanceBeginnerSecurityVerification