In March 2026, someone spent $1,808 and came close to controlling $1.08M of user funds. Nothing was hacked and the contracts did exactly what they were written to do. Here, we break down how governance attacks work, what each stage leaves onchain, and why the window to stop one is usually measured in days.
Nothing breaks in a governance attack
Onchain losses typically start with a mistake in the code. Things like rounding errors, missing access checks and reentrancy pathways are all viable vectors, and they can be patched readily enough by the auditors. Governance attacks have nothing to patch.
The attacker acquires voting power, writes a proposal, wins the vote, and executes it, and each of those steps runs through functions that work as designed. The treasury transfer at the end is authorized because as far as the contract is concerned, the community simply changed its mind.
In 2026 alone governance attacks have been responsible for a $20.5M loss to Bonk DAO, $8.5M taken from Term Finance's meta vaults, and admin control of the Yam Finance timelock, while attempts against Moonwell, Reserve, Olas and Ampleforth were caught and stopped in time.
Encouragingly, attackers can’t take money or control quietly. A DAO's own mechanics force the attacker to publish what they intend to do, in decodable form, and then wait for a vote on it. The difference between the losses and the saves comes down to whether anybody is watching intently enough when the clock runs down.

The vocabulary you need
A decentralized autonomous organization (DAO) runs a protocol's treasury and settings by token holder vote rather than by unilateral admin action, and a governance token is what gives you a vote. In order to put something to a vote, you have to clear the proposal threshold, which is a minimum amount of voting power intended to stop anyone spamming the DAO with proposals. To win, the proposal has to clear quorum, a minimum level of participation, and take more votes for than against. If it passes it goes to a timelock, a contract that holds the approved action for a fixed delay before anyone can execute it, so that holders who disagree have time to exit and somebody has time to intervene.
The last three of those are settings a DAO chooses, and it's most of the attack surface. Basically attackers read it as a price list.
Step 1: Buy the votes
The first thing an attacker works out is what a controlling position costs today. On a healthy DAO with engaged holders the answer is prohibitive, but on a dormant one it is often less than a restaurant bill.
Moonwell's Moonriver deployment shows how cheap that can get. In March 2026 an attacker spent about $1,808 on just over 40 million MFAM, delegated it to themselves and cleared the 40 million quorum with 0.4% to spare. Eleven minutes later they filed MIP-R39, "Protocol Recovery: Admin Migration," which would have handed the admin of seven lending markets and the protocol's core contracts to an address they controlled. DL News reported just over $1 million of user funds at risk, so the attacker was risking roughly one dollar for every six hundred they stood to take.
When a protocol winds down, gets abandoned or migrates to a new deployment, its governance contracts usually stay where they were. The token keeps trading, the treasury keeps its balance, and the people who used to vote have long since stopped paying attention. In July 2023, BarnBridge’s DAO was told by its own counsel to close its pools under an SEC investigation and settled in December, but its governance contracts were still live three years later.
In July 2026, an attacker spent about 0.335 ETH on BOND, locked 32,000 of it for voting power and passed a proposal that swapped out the SmartYield controller. The replacement logic reached a privileged function and pulled 776,600 USDC out of ~50 wallets that still had spending approvals open against a protocol nobody had used in years, for a total outlay of roughly $600. Reserve's hyUSD had been quiet for more than a year when someone came for it.
There are five ways an attacker builds this position:
- Self-delegation. In OpenZeppelin and Compound-style governance, holding tokens isn’t enough by itself. You’d have to delegate them (to yourself or to someone else) before they count towards anything. That delegation emits a DelegateVotesChanged event. A wallet going from zero voting power to above quorum in a single transaction is one of the loudest signals. Both Moonwell and Yam Finance mentioned previously were attacked this way.
- Staking or vault shares. Some protocols count staked positions or wrapped LP tokens instead, with no delegation event firing when they change hands, so the signal has to come from the staking contract's own accounting. Term Finance's ETH meta vault had so little staked that roughly half an ETH bought ~91% of the staked voting power, later used to execute a proposal that took about $8.5 million.
- Buying quorum outright. Where a token is liquid enough, an attacker can simply purchase as much as they need. Bonk DAO's attacker spent about $4.09 million for 1.003% of supply, just over the approval threshold, then recovered that stake after the vote and left with $20.5 million.
- Flash loans. This is the classic version of the attack. Beanstalk's attacker borrowed $1 billion in stablecoins from Aave in April 2022, and ~$44 million more from Uniswap and SushiSwap, reached a two-thirds supermajority and executed inside the same transaction leading to a drain of $182 million. Snapshot-based vote counting has made this considerably harder, but it’s a large part of why execution delays exist at all.
- Buying only the right to propose. The cheapest variant and quite easy to miss. In September 2026 the proposer behind a hostile Olas proposal locked 5,100 OLAS, worth roughly $135, which cleared the 5,000 proposal threshold by 2% and bought nowhere near the votes a proposal needs to pass. Presumably, they anticipated delegates would wave through something that read like routine operations. A detection rule comparing acquired voting power against quorum sees nothing in these cases as the threshold crossing is both cheaper and earlier.

Step 2: Write the proposal
Once the votes are in place the attacker has to say what they actually want, which is where they are most exposed. Four things tend to give a hostile proposal away, and all four are checkable before voting opens.
The payload rarely moves money directly. Attackers will mostly target admin surfaces for control rather than just transfers, so pay attention to the following in the calldata: setPendingAdmin, changeOwner, transferOwnership, upgradeTo, grantRole. Moonwell's proposal would have migrated admin rights, Yam's called setPendingAdmin on the timelock, Olas's called changeOwner on the treasury, and Reserve's would have upgraded two core contracts to unverified code.
The description gives the game away. Yam's proposal #45 shipped with an empty description, just 0x. Where there is a description it frequently contradicts the calldata sitting underneath it, for example, the Olas proposal was titled "Owner migration: transfer treasury ownership from old timelock to Safe updater," but the address it named as a Safe had no code deployed to it and was an ordinary wallet.
Legitimacy is cheap to fake and cheap to check. The same Olas proposer registered the ENS name autonolas-deployer.eth four days before proposing and pointed it at their own address, impersonating the protocol's deployer. That costs a few dollars to set up and about ten seconds to check, since ENS records are public: anyone can see who owns a name and when it was registered.
Timing is chosen deliberately. When Ampleforth's team described the two malicious proposals filed against its DAO in September 2026, they named a pattern worth knowing: hostile proposals land when the fewest people are looking. Weekends, holidays, and the small hours of whatever timezone the core team keeps, with no forum post ahead of them. Both Ampleforth proposals went up on a weekend, the voting snapshots opened at 2:25am Pacific, and none of it had been raised in any community channel beforehand. Proposal #54 asked for 2.5 million USDC, about 98% of the treasury's USDC balance, framed as a retrospective grant for work that had supposedly already been delivered.
Step 3: Win the vote
Attackers usually don’t have to out-vote the DAO, generally they just need it not to show up.
A quorum set as a percentage of total supply looks like a real barrier but at a 10% turnout it’s just a price. Synthetify's DAO lost about $230,000 in 2023 to a proposal that reached quorum on the attacker's own tokens and passed before anyone noticed it was there.
Where a community does turn up, the remaining trick is timing. In Compound's proposal 289 in July 2024, Tally's record shows 682,191 votes for and 633,636 votes against. Researchers at the Max Planck Institute for Software Systems found that 563,591 of those votes in favor (~ 82%) were cast inside the final 34 minutes of a multi-day voting window. This is vote sniping, and most governance contracts do nothing to prevent it because the standard Governor pattern ends voting at a fixed block. A vote cast in the last second counts the same as one cast on day one, and nothing extends the window when the result flips late.
Compound's funds never actually moved. The proposal was canceled before execution two days after passing, once the proposers agreed to stand down after a public argument among token holders.
The same team went looking for how widespread that exposure is. Their study examined 48 public, actively used Ethereum DAOs and found that 15 of them have no oversight mechanism at all, meaning neither a certifier nor a vetoer, and that all but four run governance contracts with no defense against vote sniping.
Furthermore, seven DAOs carried all three of the flaws that made Compound exploitable: a large float available to buy on public markets, no protection against vote sniping, and no one with a veto. The list was Uniswap, Radicle, Gitcoin, Silo, Ampleforth, Hop and Cryptex.
Ampleforth's DAO received two malicious proposals six weeks after that paper was published, and both were canceled without the loss of a dollar. No vetoer was involved, because Ampleforth didn’t have one. The delegator who had lent the proposer its voting power took the tokens back, which dropped the proposer under the threshold and opened the route to cancel the proposal outright.
All the research above illustrates that the exposure was readable in advance from public data by anyone willing to check the DAO's own settings.
Step 4: Execute
If a proposal passes, the execution delay is what stands between the vote and the money.
Of the 24 onchain voting DAOs in the Max Planck study, nine had no execution delay whatsoever, and the rest ranged from one day to three.
Bonk DAO had no delay, so its attacker finalized and executed in one motion the moment voting closed. Beanstalk ran a seven-day voting period on ordinary proposals, but its emergencyCommit function let a two-thirds supermajority execute once a proposal was 24 hours old. A two-thirds supermajority is exactly what a flash loan manufactures.
Term Finance had a delay but it didn't help. The malicious proposal, created on 17 August 2026, executed six days later, in full public view, on a protocol whose liquidity providers held veto rights over queued governance transactions, and not one of them used it. The contract behaved correctly and the control existed, but it was not attached to anyone who was paying attention.
The delay does not judge anything. It creates a window, and whether that window is worth anything comes down to who is watching during it.

Three questions worth asking about your own DAO
The Compound analysis reduces to a test any team can run in an afternoon, against public data, with no tooling required.
- What does a controlling position cost today? Read the current float on exchanges and in pools (not at listing or at peak), and price the quorum and the proposal threshold separately. Dormant protocols and thinly staked vaults are where this figure collapses.
- Can a vote be decided in the last block? If your voting window doesn’t extend when quorum is reached late, the outcome can be flipped after everyone else has stopped watching.
- Who can stop a proposal that has already passed? You should be able to name the wallet. If the answer is nobody, then the vote is the final authority on everything the DAO controls.
Half of the token acquisition governance attacks cataloged in the Max Planck study failed, and what those failures had in common was that somebody noticed in time and had a way to act, whether that meant a veto, enough counter-votes, or pulling the proposer's own voting power out from under them.
Compound reached that conclusion the hard way and passed proposal 304, which added a Proposal Guardian able to veto a passed proposal awaiting execution. Olas answered its September attempt by raising the proposal threshold from 5,000 to 250,000 OLAS and quorum from 3% to 10%, a change its team documented publicly the day after the hostile proposal appeared.
What stopping one looks like
In February 2026 an attacker submitted a proposal against Reserve's hyUSD, a token folio that had been dormant for over a year, asking to upgrade two of its core contracts to an unverified implementation. Roughly $80,000 in TVL and all of the RSR staked against hyUSD were at risk, and the proposer had opened no forum discussion beforehand.
ABC Labs, the core team behind Reserve Protocol, monitors governance across its DAOs with Hypernative's Onchain Monitoring & Automated Response, configured so that proposals carrying privileged actions like contract upgrades or role changes are treated differently from routine governance, routed to Slack and escalated through PagerDuty. The proposal raised an alert the moment it was posted. The team reviewed the proposer and the target contract, then took it public on Telegram. RSR holders staked against it in enough weight to outvote the attacker and within 24 hours the attacker unstaked and walked away.
The reputational risk of losing even $100 in user funds is massive.
Patrick McKelvy, Director of Engineering @ Reserve
That proposal and Bonk DAO's BIP #76 are structurally the same attack, and both were open about what they would do if approved. One was flagged within minutes and beaten inside a day, while the other sat unexamined for six days.
Read the full case study: How Reserve Secures a DTF Ecosystem Built on Decentralized Control
What to watch at each stage
Every step in the sequence produces something observable before the next one starts, so governance monitoring is really four separate jobs.
On voting power, watch for delegation and staking events that move an address from negligible weight to above the proposal threshold or quorum, and measure against both numbers. Mixer funding into a fresh address that then buys governance tokens belongs here too.
At proposal creation, decode the calldata and check it against a payload list that covers the ownership and admin surface alongside value transfers. Look at the proposer's age, history and funding path. Flag empty or duplicated descriptions, several proposals filed at once across related contracts, descriptions that contradict the calldata, and target addresses with no deployed code or no prior interaction with the protocol.
During the vote, track turnout against quorum in real-time and watch for voting that concentrates as the window closes.
Between passing and execution, check whether the code at the proposal's target changed after the proposal was created, which is how the 2023 Tornado Cash governance attack worked. Run a countdown that escalates as execution approaches, so the last hour is louder than the first.
The takeaway
Most malicious governance attacks come out of the same two things: a set of parameters chosen for a healthy, engaged DAO and never looked at again once attention moved elsewhere, and the reasonable assumption that somebody else is reading the proposals. That makes this one of the few attack classes where the defender can hold a structural advantage. Where an execution delay exists, the attacker has to publish the plan in decodable form and then wait, usually for several days, and what decides the outcome is whether that publication reaches someone who can act before the timer runs out.
Hypernative monitors governance across the full proposal lifecycle as one of 300+ risk types, on 75+ chains, with a 99.8% detection rate. More than $3 billion in losses have been prevented to date, all verifiable onchain.
Reach out for a demo of Hypernative's solutions, and follow Hypernative's blog and our social channels for the latest on onchain security.
Proactive security for onchain finance. Website | X (Twitter) | LinkedIn
Frequently asked questions
What is a governance attack?
A governance attack is an attempt to pass a malicious proposal through a DAO's own voting process and seize its treasury or its admin rights. No smart contract vulnerability is involved. The attacker acquires enough voting power to propose and pass an action that the protocol's code then executes exactly as it was designed to.
How is a governance attack different from a smart contract exploit?
An exploit makes a contract do something it was never meant to do, whereas a governance attack makes a contract do something it was explicitly built to do, after the DAO has authorized it. An audit will not catch the second kind, because there is no defect there to find.
Do timelocks prevent governance attacks?
Not on their own. A timelock delays execution, but it does not judge whether the action being delayed is safe. Term Finance lost about $8.5 million in August 2026 with a multi-day delay running and veto rights held by its liquidity providers, because the proposal sat in public for six days and nobody looked at it. The delay created a window, and monitoring is what puts someone in it.
Why are dormant DAOs being targeted?
Because a protocol can stop operating while its governance keeps running. Turnout collapses long before the contracts do, and a controlling position gets cheap in proportion. BarnBridge had wound down three years earlier, but its governance contracts were still live in July 2026 when an attacker spent roughly $600 to pass a proposal that pulled 776,600 USDC out of wallets whose spending approvals had never been revoked.
What is the cheapest governance attack on record?
Cheap enough that price has stopped being the barrier. BarnBridge cost its attacker roughly $600 in July 2026 and took 776,600 USDC. The Moonwell Moonriver attempt in March 2026 cost $1,808 and put more than $1 million of user funds at risk before it was stopped. The floor is lower still if all you want is to file a proposal, which is what the September 2026 Olas proposer did for around $135.
How can a DAO tell whether it is exposed?
Price a controlling position at today's float, against both the proposal threshold and quorum. Check whether a vote can be decided in its final minutes. Identify, by wallet address, who can stop a proposal that has already passed. A Max Planck Institute for Software Systems study of 48 public, actively used Ethereum DAOs found 15 with no oversight mechanism at all.



.avif)



