Governance Attacks and Defenses
What Is a Governance Attack?
Token-based governance gives voting power according to rules encoded in the governance system. Those rules determine who can propose, vote, and execute changes.
A governance attack occurs when an entity acquires enough voting power to pass proposals that benefit them at the expense of other users - typically draining the treasury or changing protocol parameters.
The Beanstalk Flash Loan Attack
In April 2022, Beanstalk (a stablecoin protocol) was attacked for $182 million. The attacker:
- Flash-borrowed massive amounts of tokens across multiple protocols.
- Used those tokens to gain a supermajority of governance voting power.
- Proposed and instantly passed a malicious proposal that transferred all treasury funds to their wallet.
- Repaid the flash loan within the same transaction.
The failure involved temporary voting power and the execution rules for an emergency proposal. Review the proposal lifecycle and historical voting-power checks together.
Attack Vectors
Flash Loan Voting
Borrow tokens in the same block as a vote. This gives temporary but overwhelming voting power without any capital at risk.
Vote Buying
Platforms like Convex (for Curve governance) and hidden OTC deals allow entities to accumulate voting power without buying the underlying token, through bribery and vote delegation markets.
Low Quorum Exploitation
Low participation can make it easier for a coordinated voter to influence a result. The attacker still has to satisfy the actual quorum, approval threshold, and proposal rules; inactivity does not lower those thresholds automatically.
Proposal Spam
Flooding a DAO with dozens of complex proposals so that voters suffer fatigue and stop reviewing them carefully, allowing a malicious proposal to slip through.
Defenses
Time-Locked Voting
Require tokens to be locked (staked) for a minimum period before they are eligible to vote. This prevents flash-loan attacks because borrowed tokens cannot meet the lockup requirement.
Voting Delay
Insert a mandatory delay between when a proposal is created and when voting begins. This gives the community time to review and organize opposition.
Timelocks on Execution
Even after a proposal passes, enforce a waiting period (24-72 hours) before it can be executed. This allows the community to exit the protocol if a malicious proposal passes.
Optimistic Governance
Some systems allow proposals to proceed unless challenged during a defined period. Other systems use a security council or veto authority. Check the specific implementation: these arrangements are not interchangeable and give different powers to participants.
Quadratic Voting
Quadratic voting makes additional voting weight increasingly costly. Without identity or other Sybil protections, a participant may evade the intended limit by splitting resources across accounts.
Key Takeaways
- Governance is an attack surface, not just a feature.
- Flash loan attacks can pass proposals in a single transaction.
- Time locks, voting delays, and snapshot mechanisms are essential defenses.
- Low quorum is dangerous - DAOs should actively incentivize voter participation.
Quiz: Governance Attacks and Defenses
1 / 5What is a governance attack?