A protocol treasury is the on-chain reserve that funds operations, development, and emergency response across multiple market cycles. The two failure modes that sink most treasuries are concentration (100 percent native token exposure) and timing (waiting until the token has already crashed before diversifying). A defensible treasury holds 12 to 18 months of operating expenses in stablecoins, sits inside a legal entity, and discloses its deployment plan, not just its allocation slide.
The timing problem nobody plans for
Most protocols build treasuries the same way. Token launches well, the team holds the supply allocation in native tokens, and nobody asks the diversification question while the chart is going up. Then the chart stops going up, and the treasury that was supposed to fund operations through the next bear market drops in lockstep with the token it was supposed to insulate against.
No one thinks about treasury until they need it. You launch, the token is doing well, and the question lands the same way every time: why sell tokens that are performing? If the token is growing 10 percent per month, then next month you will have even more capital. Sell now and you suppress the price early. This is the wrong frame of mind. The token might keep going up, or it might not. When it stops going up, you should be able to catch it. Build your treasury now, because if you need to liquidate when everyone else is doing it, it is already too late.

The pattern shows up in the largest treasuries on chain. Uniswap Foundation reported $85.8 million in assets at the end of 2025, of which $49.9 million sat in cash and stablecoins, with the rest in 15.1 million UNI tokens and 240 ETH. The broader Uniswap Treasury (the protocol-level reserve, distinct from the foundation) is dominated by UNI, with the latest DefiLlama figure showing roughly 90 percent of the on-chain treasury in own tokens. Compound's situation is similar: as of mid-2025 the DAO controlled around $164 million in total assets, with significant COMP and ETH exposure that moves with the broader market.
When UNI drops 70 percent, a UNI-heavy treasury drops 70 percent in dollar terms, exactly when the protocol most needs dry powder. Ford does not hold its corporate treasury in Ford stock, and securities regulation would not allow it. Crypto allows it because the legal infrastructure has not caught up, not because it is a good idea.
A diversified treasury (the BitDAO model from 2022 was roughly 41 percent native, 27 percent ETH, 23 percent stablecoins, with the remainder in other assets) preserves capital through downturns. Selling native tokens for diversification looks like weakness in the short term. It survives drawdowns that 100 percent native treasuries do not. I have not seen a single protocol that diversified mid-bull and regretted it. I have seen many that did not diversify mid-bull and ran out of stable runway in the bear that followed. The timing of those mid-bull sells, when and how to do them without crashing the price, is its own design problem covered in the sell pressure mitigation playbook.
Why most treasuries are 100 percent native by construction
There are three ways a treasury gets funded, and only two of them produce diversified holdings. The third, supply allocation alone, is what most early-stage protocols default to without realizing they are committing to single-asset concentration on day one. The list below is the diagnostic question to ask before launch.

- Token sale proceeds. Whatever the buyers used to pay, usually stablecoins, fiat, or ETH.
- Protocol fee revenue. Whatever unit the fees come in. Often stables, sometimes ETH, sometimes the protocol's own token.
- Supply allocation. A percentage of total token supply minted directly to the treasury at genesis. By construction, 100 percent native.
Projects that fund treasury only via supply allocation, which is most launches between 2020 and 2022, end up single-asset by default. There is no other outcome available without later treasury sells. Projects that fund treasury via fee revenue diversify organically as fees accumulate, provided the fees are not denominated entirely in the native token.
Uniswap is the cleanest current example of the corrective move. In December 2025, governance approved the UNIfication proposal, which turned on the protocol fee switch and routed a share of swap fees into a burn mechanism. The same proposal also formed DUNI, the legal entity wrapping the DAO. The fee switch is the structural fix for the diversification problem: instead of one-off treasury sells (which read as weakness), inflows arrive as a programmatic stream from real protocol revenue.
If you are designing a token now, the lesson is operational. Decide where treasury inflows come from before you launch, not after the token has done its first 5x. Fee architecture and fundraising structure are the levers; later treasury sells are the lagging indicator that those levers were set wrong.
The allocation framework, and the runway floor that actually matters
Industry consensus on treasury allocation has converged on roughly the same shape across DAO tooling firms and treasury reports: 40 to 50 percent operations, 25 to 30 percent development, 10 to 15 percent marketing and growth, 15 to 20 percent strategic reserves. The split varies by protocol type, but the proportions are consistent enough that they form a defensible default. Inside operations and reserves, the load-bearing rule is the stablecoin runway floor: 12 to 18 months of operating expenses held in stables, untouched, before any other allocation question gets answered.
Why this rule and not a different one. A protocol with three months of stable runway and ten years of native tokens is three months from distress, regardless of what the headline treasury number says. The native tokens cannot be relied on to cover the next twelve months of payroll, infrastructure, audits, and emergency spend; they may be worth zero by then, or they may be untradeable at the size you would need. The stable reserve is the thing that keeps the protocol solvent through the bear, period. Everything else is secondary.
Most teams I have worked with underweight this. They optimize for the optical headline (a 25 percent treasury allocation looks like a lot), then check stable runway after the design is locked and discover six months instead of fifteen. Restructuring after launch is expensive: it requires either a treasury sell while the token is high (the whole problem this article is about) or a stable raise on terms that are usually worse than the original sale. Plan for the runway floor first. Build the rest of the allocation on top of it.
A protocol with three months of stable runway and ten years of native tokens is three months from distress.
Treasury is shadow supply, and the liabilities side nobody nets
A 25 percent treasury allocation is not a number on a slide. It is an emissions schedule. If you deploy that 25 percent over five years to fund grants, salaries, and infrastructure, the market sees roughly 5 percent annualized supply pressure from treasury alone, on top of vesting, staking emissions, and any other unlock schedules. The market prices this in if it knows the schedule, and it reads opacity as risk.
This is why the disclosure standard for serious protocols has shifted from the allocation slide to the deployment roadmap. Optimism Collective, Arbitrum DAO, and Sky (formerly MakerDAO) all publish quarterly treasury reports with deployment categories, estimated annual spend, and rebalancing rules. Treasury behaves as shadow supply in the same way unlocks do; the difference is that unlocks are usually disclosed at launch and treasury deployment usually is not.
Then there is the liabilities side, which is where most treasury reporting silently misleads. The standard treasury figure is gross. It does not net out grant program commitments already approved, validator emissions already promised, developer salary obligations, infrastructure contracts, audit budgets, bug bounties, or any of the other forward commitments that will pay out regardless of token price. A protocol can show $400 million in treasury and have $180 million in committed outflows over the next eighteen months. The defensible runway calculation is on the net figure, not the gross.
Sky pioneered this with its vault architecture, which makes liability matching explicit at the protocol level. Most other treasuries do not track it. The fix is not technically hard: publish a net-of-commitments balance alongside the gross figure, and base the runway calculation on the lower number. The harder part is admitting in public that the headline figure was overstating things, which is why most teams do not do it until they have to.
RWA: the 2025 to 2026 yield layer
The third allocation question, after stable runway and deployment disclosure, is what the stable portion actually does between when it is raised and when it is spent. Until 2024, the answer was usually that it sat in USDC at zero yield. That is no longer the default.
Tokenized US Treasury products crossed $5 billion by mid-2025 and reached approximately $12 billion by early 2026. BlackRock's BUIDL fund alone holds around $2.5 billion. Franklin Templeton's BENJI holds approximately $700 million. Ondo's OUSG and USDY products together hold approximately $2.6 billion. On-chain US Treasury exposure is no longer a niche product; it is a standard option for any treasury with idle stables.
Sky (formerly MakerDAO) is the largest DeFi consumer, holding more than $2 billion in RWA collateral backing DAI as part of its Endgame strategy. The yield is real (short-duration US Treasuries have been paying meaningfully above zero through this cycle), the rails are increasingly DeFi-native (BUIDL is accepted as collateral on multiple venues), and the credibility benefit with institutional counterparties is straightforward. The combination has moved RWA from exotic option to standard treasury infrastructure for any protocol with serious stable reserves.
The trade-off is honest. RWA exposure means custodian dependency, legal structure exposure, and a regulated counterparty in the chain that pure crypto-native treasuries do not have. If the SPV holding the underlying Treasuries fails or freezes redemptions, the on-chain token does not protect you. For a protocol with significant stable reserves and an eighteen-month runway, the question to evaluate is whether the marginal yield justifies the counterparty surface, not whether RWA is good or bad in the abstract.
My read: for a protocol with $20 million plus in idle stables and the operational discipline to handle the additional reporting, RWA allocation is now standard. Smaller treasuries can stay in plain stablecoins without losing much. The threshold is set by reporting overhead, not by yield meaningfulness.
Custody and governance: the two attack surfaces
A defensible treasury still has two ways to go to zero: the custody attack surface (private keys, signers, hardware) and the governance attack surface (proposals that drain the treasury under cover of a quorum). Both have been broken at protocols people thought were safe. The defenses for each are now well documented, but uneven adoption is the norm rather than the exception.
Most protocol treasuries sit in a Safe (formerly Gnosis Safe) multisig, typically 5-of-9 or 7-of-11 with signer diversity requirements. In 2024, private key compromises accounted for 43.8 percent of stolen cryptocurrency, with $2.2 billion in total losses across the year per Chainalysis. Custody is the single largest attack vector right now, larger than smart contract exploits. The defensive posture is well known but unevenly applied: signer diversity by geography and hardware wallet type, timelocks on every treasury outflow above a threshold, regular signer rotation, emergency pause mechanisms, per-transaction caps enforced in code rather than in policy documents. Each of these costs operational friction; each has prevented a six- or seven-figure loss somewhere. Treasury custody design is the kind of thing FinDaS works through with clients at the architecture stage rather than after the first close call.
The governance side is more recent. The Compound GoldenBoyz attempt in 2024 staged a series of malicious proposals to drain roughly $24 million from the Compound treasury (499,000 COMP, or 5% of the treasury); attackers had quietly accumulated delegated voting power sufficient to narrowly clear the quorum threshold. The community caught it. Beanstalk in 2022 was less fortunate, losing $182 million via a flash-loan governance attack: the attacker borrowed enough governance tokens to pass a malicious proposal that drained the treasury in a single transaction.
The defensive controls are now standard for any treasury-touching proposal. Required: timelocks before execution, minimum quorum thresholds, snapshot-based voting that defeats flash-loan governance, guardian veto power during emergencies, per-transaction caps that limit blast radius. The pattern across post-mortems is consistent. Single controls have been broken; layered controls have held. Governance design is the bridge between treasury design and the rest of the protocol that most teams do not think about until they have to.
A treasury cannot legally exist without an entity
The last failure mode is structural and usually retrofitted at high cost. A treasury without a legal entity wrapping it is held in escrow by a group of multisig signers, who may be personally liable for its operations under the laws of whichever jurisdictions they happen to live in. The token holders nominally control it, but no entity owns it, no entity can sue or be sued on its behalf, no entity can sign contracts, hire vendors, file taxes, or hold IP. This is fine until something goes wrong, at which point the absence of legal personhood becomes the central problem.
The available wrappers are now well mapped: Wyoming DUNA, Cayman Foundation, Marshall Islands DAO LLC, BVI Foundation, plus a handful of Swiss and Singaporean structures. Each has tradeoffs around tax treatment, signer protection, governance flexibility, and disclosure obligations. Governance design and legal structure are inseparable; you cannot meaningfully decentralize control of a treasury that has no legal home.
The cost of doing this retroactively is real and recently visible. Uniswap's UNIfication proposal, approved December 26, 2025, formed DUNI as the legal wrapper for the DAO. The proposal earmarked roughly $16.5 million for tax obligations owed to the IRS and legal defense tied specifically to the previously unwrapped period. Wrapping a treasury before it accumulates significant assets is cheap. Wrapping after, especially when tax authorities are interested, is not.
The operational rule is simple. Set up the legal entity before the token sale closes. Do not wait until the treasury has $100 million in it; do not wait until governance is asking how to pay vendors. The cost of doing it early is in the low six figures plus annual maintenance. The cost of doing it late is whatever the legal defense bill turns out to be, plus retroactive tax exposure, plus the reputational cost of the founders looking like they did not plan for any of this. Building the legal entity into the launch process is the cheapest version of the same end state.
More from the 101 series
This article is part of our 101 series. A few related explainers if you want to go deeper:
