Quick Answer
DAO governance contracts are among the highest-stakes smart contracts in DeFi — they control protocol parameters, treasury funds, and the future direction of protocols managing billions in TVL. A governance attack doesn't require finding a code bug; it requires finding a logical weakness in how voting power translates to execution authority.
Historical record — each demonstrates a distinct attack class covered by governance audits.
| Protocol | Loss | Date | Attack Method |
|---|---|---|---|
| Beanstalk | $182M | April 2022 | Flash loan governance attack — borrowed supermajority, passed malicious proposal, drained treasury in one transaction. No timelock. |
| Compound | $80M | Oct 2021 | Governance proposal bug: comp distributor contract misconfiguration allowed users to claim excess COMP before governance could correct it. |
| Build Finance | $470K | Feb 2022 | Governance takeover — attacker accumulated enough BUILD tokens over time to pass a proposal granting full treasury control. |
| Tornado Cash DAO | $N/A control | May 2023 | Attacker passed a malicious proposal that granted self 1.2M votes via a custom contract, took over DAO governance entirely. |
Governance contracts that use spot balance for voting allow flash loans to temporarily grant supermajority control. The fix — snapshot at proposal creation block — is a single design requirement that eliminates the entire attack class.
Every governance execution path — including 'emergency' paths — needs at least a 24-48 hour delay. Without it, a proposal can be created and executed in the same transaction. Beanstalk had no timelock.
Quorum based on participating votes (not total supply) allows minority control. 4% of total supply is a common quorum threshold — an attacker who controls 4% plus sufficient delegation can govern unilaterally.
Emergency guardian addresses with single-key control and bypass authority are the highest-value target in a governance system. Guardian functions should require multi-sig with time delay even for security-critical operations.
| Vulnerability | Severity | Description | Example |
|---|---|---|---|
| Flash Loan Governance Attack | Critical | DAOs that use a governance token's spot balance (rather than a time-weighted or snapshotted balance) for voting allow flash loan-powered governance attacks. An attacker borrows a supermajority of the token supply, proposes and votes on a malicious proposal that drains the treasury or transfers admin rights, and repays the loan — all in a single atomic transaction. Beanstalk ($182M, April 2022) is the canonical example with no timelock on proposal execution. | A governance contract using block.timestamp as the voting snapshot rather than a fixed block snapshot — a flash loan can inflate voting power in the same transaction as proposal creation and execution. |
| Timelock Bypass via Emergency Paths | Critical | Governance contracts often include 'guardian' or 'emergency' functions that can execute without a timelock, intended for critical security patches. If these paths are accessible without a supermajority requirement, they represent a privileged execution bypass. An attacker who compromises the guardian key or meets the lower threshold for emergency activation can execute arbitrary proposals instantly. | A DAO with a guardian address (single key) that can execute any proposal bypassing the 48-hour timelock — the guardian key is compromised and the full treasury is transferred in a single transaction. |
| Quorum Manipulation via Token Delegation | High | Many DAOs reach quorum based on the total voting power participating in a proposal, not the total supply. If token holders can delegate their votes to an attacker-controlled address just before a vote, a small coalition can meet quorum with a tiny fraction of the total supply — allowing minority governance decisions. This is worsened when quorum thresholds are set too low at launch and are themselves changeable via governance. | A DAO where quorum is 4% of total supply, delegation is unrestricted, and a proposal can change quorum — an attacker delegates 4% to themselves, passes a proposal reducing quorum to 1%, then operates with near-unilateral control. |
| Proposal Execution Reentrancy | High | Governance contracts that execute proposals by calling external contract addresses defined in the proposal data are vulnerable to reentrancy. A malicious proposal that calls a contract which re-enters the governance executor before the proposal is marked executed can bypass the 'already executed' check and run the proposal a second time — or chain into other proposals. | A governance executor that calls the external contract in a proposal, then marks the proposal as executed — a malicious external contract re-enters the executor's execute() function before the state update, running a second proposal that wasn't voted on. |
| Vote Delegation Double-Count | Medium | Delegation systems that allow a delegatee to re-delegate their received votes can create double-counting if the delegation chain is not properly tracked. Circular delegation (A → B → A) or multi-hop delegation without proper accounting allows voting power to be counted multiple times, inflating individual voting weight beyond the actual token balance. | Delegator A delegates to B. B delegates to C. C delegates to A. If the delegation implementation follows the chain without cycle detection, all three addresses may count the same token balance in voting. |