Library · Crypto, word by word · Scams and security

What is a governance attack?

A governance attack is when someone gains enough voting power in a protocol's token vote to pass a proposal that benefits them, such as moving the treasury to their own address or changing the rules. Voting power can be bought, borrowed or gathered from holders who do not vote.

What it means for you

If you hold a governance token or keep funds in a protocol run by token votes, a single passed proposal can change where your deposit goes. You can check whether the protocol has a timelock that delays approved changes, which gives holders time to spot a hostile proposal and withdraw, and you can read pending proposals before they execute.

How it works

In token voting, power is usually measured by tokens held. ethereum.org describes an attacker who takes out a flash loan, borrows enough tokens to dominate a vote and pushes through a malicious proposal, all before repaying the loan. Defences include measuring voting power at a past block rather than the current one, so freshly borrowed tokens count for nothing; weighting votes by how long tokens are locked; and a timelock that delays execution of any approved proposal, giving users time to react. Unlike a 51 percent attack on a blockchain itself, this needs control of only one application's vote.

Source: ethereum.org: Smart contract security (governance attacks) · checked 4 October 2026

Often confused with

Governance attack vs 51% attack

Related words

DAOGovernance tokenGovernance timelockFlash loanOn-chain governance

Educational content, not financial advice. Written by hand and checked against the source named above. Something wrong? Tell us and we reply within two business days.