Blog

The 97% Consensus That Wasn't: Anatomy of a DAO Governance Attack

Written by tortue974 - August 23, 2026

A DAO treasury holds $182 million in stablecoins and governance tokens. The community has debated a proposal for two weeks, and when the vote closes it passes with 97% in favor. On paper, that is overwhelming consensus.

The proposal passes. Twenty-four hours later, the timelock expires and it executes.

The “proposal” was a contract upgrade that redirected the treasury to an address nobody recognized. By the time anyone started asking questions, the funds were already moving through a mixer. And those 97% of “yes” votes? They came from wallets that had existed for less than a day, each one holding borrowed tokens that were paid back the moment the vote closed.

This is what a governance attack looks like. Nothing was exploited in the traditional sense - the smart contract executed exactly as designed. The vulnerability was the governance system itself: who could vote, how votes were counted, and what a winning vote was allowed to do. Flash loans and freshly minted wallets turned a skin-deep majority into total control of nine figures.

The uncomfortable lesson is that “the code ran correctly” and “the community decided” are two very different claims. If voting power can be rented for an afternoon, a quorum is just a rental agreement - and the lease is signed by whoever shows up with the most borrowed tokens.

This is exactly the class of failure Vulpine was designed against. Your identity is a key that never leaves your device, your messages are end-to-end encrypted, and there is no treasury of trust sitting in the middle for a coordinated majority - however convincing its 97% - to walk away with.

← All articles
Privacy Policy Terms © 2026 Vulpine. Your acts, your responsibility.