Hashtag Web3 Logo

Governance Attacks and Defenses

10 min
advanced

What Is a Governance Attack?

Token-based governance gives voting power according to rules encoded in the governance system. Those rules determine who can propose, vote, and execute changes.

A governance attack occurs when an entity acquires enough voting power to pass proposals that benefit them at the expense of other users - typically draining the treasury or changing protocol parameters.

The Beanstalk Flash Loan Attack

In April 2022, Beanstalk (a stablecoin protocol) was attacked for $182 million. The attacker:

  1. Flash-borrowed massive amounts of tokens across multiple protocols.
  2. Used those tokens to gain a supermajority of governance voting power.
  3. Proposed and instantly passed a malicious proposal that transferred all treasury funds to their wallet.
  4. Repaid the flash loan within the same transaction.

The failure involved temporary voting power and the execution rules for an emergency proposal. Review the proposal lifecycle and historical voting-power checks together.

Attack Vectors

Flash Loan Voting

Borrow tokens in the same block as a vote. This gives temporary but overwhelming voting power without any capital at risk.

Vote Buying

Platforms like Convex (for Curve governance) and hidden OTC deals allow entities to accumulate voting power without buying the underlying token, through bribery and vote delegation markets.

Low Quorum Exploitation

Low participation can make it easier for a coordinated voter to influence a result. The attacker still has to satisfy the actual quorum, approval threshold, and proposal rules; inactivity does not lower those thresholds automatically.

Proposal Spam

Flooding a DAO with dozens of complex proposals so that voters suffer fatigue and stop reviewing them carefully, allowing a malicious proposal to slip through.

Defenses

Time-Locked Voting

Require tokens to be locked (staked) for a minimum period before they are eligible to vote. This prevents flash-loan attacks because borrowed tokens cannot meet the lockup requirement.

Voting Delay

Insert a mandatory delay between when a proposal is created and when voting begins. This gives the community time to review and organize opposition.

Timelocks on Execution

Even after a proposal passes, enforce a waiting period (24-72 hours) before it can be executed. This allows the community to exit the protocol if a malicious proposal passes.

Optimistic Governance

Some systems allow proposals to proceed unless challenged during a defined period. Other systems use a security council or veto authority. Check the specific implementation: these arrangements are not interchangeable and give different powers to participants.

Quadratic Voting

Quadratic voting makes additional voting weight increasingly costly. Without identity or other Sybil protections, a participant may evade the intended limit by splitting resources across accounts.

Key Takeaways

  • Governance is an attack surface, not just a feature.
  • Flash loan attacks can pass proposals in a single transaction.
  • Time locks, voting delays, and snapshot mechanisms are essential defenses.
  • Low quorum is dangerous - DAOs should actively incentivize voter participation.

Quiz: Governance Attacks and Defenses

1 / 5

What is a governance attack?