It is important to note that this was not a smart contract exploit. The point of failure here was the website UI. Users were sent to a malicious website due to a stolen Cloudflare API key. What can DAOs do to prevent the single point of failure that is the web front end? Is there a reliable second level of security to ensure you are at the site you intended? The SSL certificate didn't work because Cloudflare was stil…
I disagree that this is an important detail. Even though the smart contract code wasn't exploited directly (this time), this type of massive theft is only possible because the smart contract ecosystem thrives on a lack of accountability.