On this page
When DAOs go wrong: known attacks
Flash-loan governance capture
A lets a user borrow any amount with no collateral, as long as it's returned in the same transaction — enough to hold a voting majority for one block. The fix: governance must snapshot token balances before the vote (a delay), so same-block flash-borrowed tokens can't vote. Not every capture needs a loan: in November 2021, the Mochi Inu team swapped its own USDM stablecoin for CRV, locked it as veCRV (Curve's ) to vote CRV rewards to its own pool, then dumped the rewards — Curve's Emergency DAO killed the gauge.
Beanstalk (2022) — flash-loan capture
The Beanstalk stablecoin protocol was drained of ~$182M when an attacker used a flash loan to acquire enough voting power to pass a malicious governance proposal — executed in a single block. The DAO had no voting delay. It's the textbook case of why governance delays and quorum / supermajority requirements matter.
Governance capture in one transaction
Plutocracy and low turnout
Many DAOs see <10% turnout; a small active minority can pass proposals. Combined with whale dominance, this means a few large holders effectively control many “decentralized” protocols. The SEC has cited this in arguing some DAOs are effectively controlled by a team, undermining decentralization claims in securities-law analysis.
Compound governance (2024)
In July 2024, a voting bloc led by one large holder narrowly passed Proposal 289, moving 499,000 COMP (~$24M) from Compound's treasury into a vault the bloc controlled, over the objections of many delegates. It agreed days later to rescind it in exchange for a new staking product, but the episode underscored that turnout is a security boundary: when most holders don't vote, a determined minority can pass a proposal that drains the treasury.
Most “DAOs” have a core team, a foundation, a multi-sig of known humans, and off-chain coordination long before any on-chain vote. Treating “decentralized” as “trustless” is a frequent mistake — DAOs have people, and people have incentives.
The legal status of DAOs is unsettled. In the US, the Wyoming DAO LLC (2021) and similar state frameworks let a DAO register as an LLC, providing liability shielding for members. But the 2022 CFTC action against Ooki DAO held that a DAO can be sued as an unincorporated association, and that token holders who voted on the offending actions could face liability — a sharp contrast to the “code is law” ethos. The Marshall Islands has also registered DAOs as entities. In practice, most large DAOs sit behind a foundation (often Swiss, Cayman, or Singaporean) that holds the treasury and signs contracts, with the on-chain DAO handling protocol-level decisions. This hybrid structure is pragmatic but muddies the “decentralized” claim.
How this connects to the rest of NodeScholar
DAOs sit at the intersection of DeFi (most major DAOs govern DeFi protocols), the technology unit (smart contracts, the substrate DAOs run on), and regulation (the Howey test, Ooki DAO, and the legal-status debate). The security unit covers the broader smart-contract risk mindset that DAO attacks are a part of.
Key takeaways
A one-page summary of DAOs & On-chain Governance. Print it for quick reference.
- A DAO coordinates people, rules, and funds via smart contracts and token-holder votes — replacing (some) corporate structure with code.
- Voting designs span token-weighted (1 token = 1 vote), quadratic (favoring breadth over wealth), and conviction (rewarding persistent preference). Each has tradeoffs.
- Treasuries hold protocol-owned assets under governance control; mismanaged or captured treasuries are a top attack vector.
- On-chain voting is expensive, so most DAOs use off-chain Snapshot signaling and reserve on-chain execution for what passes.
- Known attacks: flash-loan governance captures (borrow voting power for one tx), plutocracy (whale dominance), and low-turnout captures.
- DAOs are powerful but experimental; legal status (are they general partnerships? liability shields?) remains unsettled in most jurisdictions.
Unit check
80% to complete this unitPass the unit check (4 of 5) to complete this unit.