DeFi Governance Attacks: When Voting Power Turns Against the Community
A DeFi governance attack occurs when someone accumulates enough voting power to push through a proposal that benefits them, not the community. This can happen in protocols where decision-making is handed over to token holders, with more tokens meaning more votes.
The damage isn't limited to obvious changes; attackers often use this method to drain treasuries or gain control of a protocol. Two real cases illustrate this risk: Beanstalk Farms and Build Finance DAO. In both instances, the attacker used voting power to pass proposals that benefited them financially, with Beanstalk losing $182 million in collateral.
Protocols are responding by implementing time-locked execution, quorum requirements, governance-token vesting, and other measures to prevent such attacks. However, these defenses come with trade-offs between speed, decentralization, and security. The data suggests that low-turnout DAOs remain exposed to governance risks.