Security
Governance attacks and the controls that stop them

Treasury-scale money attracts treasury-scale attacks. Nearly all of them target the execution path.
Vote-buying and flash-loan voting
Snapshot voting power at a block before the proposal opens so borrowed tokens cannot vote.
Payload substitution
Bind the vote to a hash of the calldata. If the payload changes, the authorisation dies with it.
Signer compromise
Distribute keys across people, devices and jurisdictions; require more signatures for higher-impact actions.
The common attack patterns
Vote buying and borrowed voting power let an attacker rent influence for the length of a vote. Proposal spam exhausts attention so a harmful item passes unnoticed. Payload substitution relies on the gap between what people read and what actually executes.
The most damaging attacks are rarely clever cryptography. They exploit low turnout, weak review of calldata and the assumption that whoever wrote the transaction is trustworthy.
Defences worth the cost
Snapshot voting power at proposal creation rather than at execution, which removes the value of borrowing tokens after a proposal appears. Require a proposal deposit to make spam expensive. Enforce a timelock so a surprising result can be examined before it settles.
Add a human review step that decodes the payload independently of the proposer. Most substitution attacks fail immediately when one person compares the decoded call against the written description.
Keep the execution path connected: this guide pairs well with multisig wallet, timelock contract and dao voting, which cover the neighbouring steps between an approved vote and a settled onchain transaction.
Key concepts explained
New to this topic? These are the core terms you will meet again and again in governance work. Understanding them makes every proposal easier to read.
- Governance attack
- Capturing enough voting power - by buying, borrowing or flash-loaning tokens - to pass a proposal that drains or damages the protocol.
- Flash loan governance attack
- Borrowing huge token amounts within one transaction to swing a vote. Snapshot-based voting power and timelocks are the standard defenses.
- Hostile proposal
- A proposal designed to transfer treasury assets or seize upgrade control. A mandatory timelock gives the community a window to react or exit.
- Vote buying
- Paying holders to delegate or vote a certain way, often through hidden marketplaces. Transparency and delegation diversity reduce its impact.
Frequently asked questions
- What is a governance attack?
- It is any attempt to obtain an outcome the community would not approve, usually by acquiring temporary voting power, hiding the true effect of a proposal, or exploiting low participation.
- Can someone borrow tokens to win a vote?
- If voting power is measured at the wrong moment, yes. Snapshotting balances at proposal creation makes borrowing far less effective because the attacker must hold the tokens before anyone knows what the vote is about.
- What is a common governance challenge for DAOs?
- Low participation. When turnout is a few percent of supply, a modest holder can decide outcomes, which turns an apparently decentralised system into an effectively controlled one.