A malicious governance proposal submitted to the Tornado Cash DAO on June 25, 2026, targets $23 million in TORN tokens held in the protocol's treasury. Security Alliance researcher Pascal Caversaccio and L2BEAT flagged the proposal, which attempts to replace legitimate governance addresses with a...
"The proposal is basically designed to swap out key governance addresses and replace them with fraudulent ones — lookalikes, with similar opening characters, controlled by an attacker." — Pascal Caversaccio, Security Alliance Researcher
A malicious governance proposal submitted to the Tornado Cash DAO on June 25, 2026, targets $23 million in TORN tokens held in the protocol's treasury. Security Alliance researcher Pascal Caversaccio and L2BEAT flagged the proposal, which attempts to replace legitimate governance addresses with attacker-controlled lookalikes sharing the same first 15 characters. The proposer's address was funded via Railgun, a competing privacy protocol, four days prior. The proposal's contract code remains unverified.
This is the second governance attack on Tornado Cash in three years. In May 2023, an attacker seized full DAO control through a disguised proposal, extracted 483,000 TORN tokens ($890,000), and later returned governance — after laundering the proceeds through the protocol itself. The pattern repeats across the sector: Beanstalk lost $181 million in April 2022 to a flash-loan governance exploit. Compound's DAO narrowly survived a $24 million extraction attempt by the "Golden Boys" group in July 2024. DAOs collectively control over $26 billion in on-chain treasuries as of Q1 2026, yet voter turnout remains below 3% for most protocols. The mismatch between treasury size and governance participation creates a structural vulnerability that attackers have exploited repeatedly.
On June 25, 2026, a governance proposal appeared on the Tornado Cash DAO portal claiming to establish a "brand-new dynamic deflationary economic model" with restructured fee mechanics. ZK researcher Sergey Shemyakov raised the alarm on X, noting the proposal pointed to an unverified contract — a departure from standard DAO governance practice where proposal code is publicly auditable.
Pascal Caversaccio, a researcher at the Security Alliance, subsequently dissected the proposal and identified two distinct attack vectors embedded within it:
Address spoofing. The proposal would replace the DAO's governance address — which controls $23 million in TORN tokens — with an attacker-controlled address sharing the same first 15 characters. A parallel swap would target the staking governance proxy contract. This technique exploits the common practice of verifying addresses by checking only their opening characters.
Relayer balance zeroing. A secondary payload would enable the spoofed governance address to set any relayer's balance to zero at will. Relayers are critical infrastructure in the Tornado Cash ecosystem: they submit transactions on behalf of users, allowing interaction with the protocol without exposing wallet addresses. Wiping relayer balances would degrade the privacy functionality that constitutes the protocol's core value proposition.
The proposer's wallet was funded via Railgun — a privacy protocol that competes directly with Tornado Cash — four days before submission. This detail raises questions about competitive sabotage, though no attribution has been confirmed.
As of publication, the proposal has not passed. TORN trades at approximately $5–$9 across major exchanges, with a market capitalization between $19 million and $50 million depending on the data source, reflecting thin liquidity and wide tracking discrepancies.
The Tornado Cash incident is not isolated. DAO governance has been exploited with increasing frequency since 2022, with each attack revealing a distinct vulnerability class.
Method: Flash-loan governance capture Loss: $181 million ($76 million net attacker profit)
An attacker flash-borrowed over $1 billion from Aave, Uniswap, and SushiSwap — including 350 million DAI, 500 million USDC, and 150 million USDT — to acquire sufficient voting power (two-thirds threshold) for an emergency governance execution. Two proposals were submitted: BIP-18, which transferred treasury funds to the attacker, and BIP-19, which sent $250,000 in BEAN tokens to Ukraine's official crypto donation address, serving as social camouflage. The attack exploited the ability to vote and execute a proposal within the same transaction window, bypassing what was supposed to be a one-day delay for emergency actions. According to Immunefi's post-mortem analysis, Beanstalk subsequently replaced on-chain governance entirely with a community-run multisig.
Method: Disguised malicious proposal Loss: 483,000 TORN tokens ($890,000)
The attacker purchased TORN tokens on decentralized exchanges and submitted a proposal designed to mimic a previously accepted one. After community approval, the attacker activated a hidden self-destruction function that destroyed the existing proposal contract and replaced it with malicious code granting full governance control. The attacker extracted 483,000 TORN tokens, swapped most for 485 ETH, and laundered the proceeds through Tornado Cash itself. In an unusual twist, the attacker later submitted a proposal to return governance control, which passed on May 26 with 517,000 votes in favor and zero against. The motive for restoration remains unclear.
Method: Coordinated whale capture via token delegation Loss: $24 million (partially reversed)
A group operating under the name "Golden Boys" executed a multi-stage campaign to extract treasury funds. Three progressive proposals (247, 279, and 289) attempted to transfer 499,000 COMP tokens worth $25 million to a yield protocol called goldCOMP controlled by the group's leader, a whale known as Humpy. Proposals 247 and 279 failed after community opposition. Proposal 289 passed by a margin of 682,191 to 633,636 votes, with five wallets delegating over 228,000 COMP obtained from Bybit exchange to boost voting power. According to CoinDesk, COMP fell 6.7% following the vote. The attacker ultimately agreed to a counter-proposal creating a DAO-controlled staking product, partially reversing the extraction.
Method: Address spoofing via unverified contract At risk: $23 million in TORN tokens
The current attack, described above, represents a new vector: rather than seizing governance through token accumulation, the attacker attempts to redirect treasury control through a contract-level address substitution. The attack is still pending community vote as of this writing.
The structural vulnerability underlying all four attacks is the same: large treasuries governed by tiny voter participation.
| Metric | Data | |--------|------| | Total DAO treasury value (Q1 2026) | $26 billion+ | | Total assets governed by DAOs | $35 billion+ | | Governance token market cap | ~$30 billion (April 2026) | | Average voter turnout (routine proposals) | Below 3% | | Uniswap DAO voter turnout (routine) | Below 3% | | Token holder voting participation rate | Less than 2% of holders vote | | Top 10% token holder control of voting power | 76.2% | | Protocols using one-token-one-vote | Majority |
According to CoinGecko's governance token report (April 2026), governance tokens represent approximately $30 billion in combined market capitalization. The five largest DAO treasuries — Uniswap ($4.8 billion), Sky/MakerDAO ($3.9 billion), Optimism ($2.1 billion), Arbitrum ($1.7 billion), and Lido ($1.4 billion) — account for over half of all DAO-held assets.
Yet voter turnout tells a different story. According to MEXC's analysis of on-chain voting data, less than 2% of token holders participate in most proposals. DAOs that transitioned from one-token-one-vote to delegated or quadratic models saw turnout rise from 2.8% to 11.4% on average, with proposal quality scores increasing 34% — but these remain minority implementations.
The data implies that a well-capitalized attacker needs to control a small fraction of total token supply to dictate governance outcomes. In Compound's case, with voter turnout at 4–5% of total supply, five coordinated wallets were sufficient to pass a $24 million extraction.
| Attack | Year | Vector | Capital Required | Outcome | Governance Fixed? | |--------|------|--------|-----------------|---------|-------------------| | Beanstalk | 2022 | Flash loan | $1B (borrowed, repaid) | $181M stolen | Replaced with multisig | | Tornado Cash I | 2023 | Disguised proposal | TORN purchases (~$890K) | 483K TORN stolen | Governance restored by attacker | | Compound | 2024 | Whale delegation | 228K COMP delegated | $24M partially reversed | Counter-proposal compromise | | Tornado Cash II | 2026 | Address spoofing | Minimal (Railgun-funded) | $23M at risk | Pending |
The evolution is notable. Beanstalk required $1 billion in flash-loaned capital. The 2023 Tornado Cash attack required purchasing tokens on the open market. Compound required acquiring delegation rights. The 2026 Tornado Cash attack requires almost no capital — just a well-crafted proposal with a spoofed address. The cost of governance attacks is decreasing while DAO treasuries grow.
The DAO ecosystem has developed several defensive tools since the Beanstalk attack. None have proven comprehensive.
Snapshot-based voting records token balances at a specific block prior to a vote, preventing flash-loan attacks where tokens are borrowed, voted with, and returned in a single transaction. This addresses the Beanstalk vector but does nothing against the Compound or Tornado Cash patterns.
Timelocks delay execution of approved proposals, providing a response window. The Governor contract pattern used by Uniswap, Compound, and others includes proposal creation, voting periods, timelock delays, and execution stages. Beanstalk's one-day emergency delay was insufficient; most protocols now implement longer periods.
Quorum requirements set minimum participation thresholds. However, quorums calibrated to low-turnout norms remain gameable. A 4% quorum in a protocol where 3% typically votes requires the attacker to mobilize only slightly more than normal participation.
Veto councils provide emergency override capability. The ENS DAO Security Council holds veto authority expiring on July 24, 2026, with a renewal proposal currently active. Uniswap has discussed implementing a similar structure. The trade-off is that veto power reintroduces centralization — the very thing DAO governance was designed to eliminate.
Proposal staking requires proposers to post tokens that can be slashed if a proposal is deemed malicious. Uniswap's governance forum has discussed this mechanism. It adds friction to attack attempts but also raises barriers to legitimate participation.
Code verification requirements — which would have flagged the 2026 Tornado Cash proposal immediately — remain informal norms rather than protocol-enforced rules. No major DAO has implemented mandatory on-chain verification of proposal contracts as a governance prerequisite.
From an economic value perspective, DAO governance represents a structural allocation problem. Treasury assets worth $26 billion are secured by participation rates that would be considered a crisis in any other governance system. The cost of attack, across all four cases examined, has been lower than the value at risk — often by orders of magnitude.
The concentration of voting power compounds this. When 0.1% of holders control approximately 90% of votes in some DAOs, the effective governance model is closer to a corporate board than a democratic assembly. The distinction matters because the security model assumes distributed participation as a defense. Absent that participation, the model degrades to trust in a small number of token holders — many of whom are funds, market makers, or protocol insiders with competing incentives.
The economic cost of governance attacks extends beyond direct losses. Beanstalk's protocol was effectively destroyed. Tornado Cash's TORN token lost 40% of its value in the hours following the 2023 attack. COMP dropped 6.7% after the Golden Boys vote. These price impacts represent wealth destruction for passive holders who were not party to the governance process — a form of extractive value transfer from passive to active (and often malicious) participants.
The 2026 Tornado Cash proposal introduces a further concern: the near-zero cost of submission. If governance attacks can be mounted with only a Railgun-funded wallet and a well-crafted proposal — no token purchases, no flash loans, no delegation campaigns — the attack surface expands substantially. Every DAO that permits unverified proposal contracts is vulnerable.
DAO governance attacks are not anomalies. They are a predictable consequence of a system that places billions of dollars behind participation rates below 3%. The four attacks examined here — Beanstalk (2022), Tornado Cash (2023), Compound (2024), and Tornado Cash (2026) — each exploited different technical vectors but shared the same underlying condition: insufficient voter participation to resist coordinated manipulation.
The declining cost of attack is the most concerning trend. The 2026 Tornado Cash proposal requires no token accumulation, no flash loans, and no whale coordination — only a spoofed address and an unverified contract. Unless DAO governance models evolve to enforce minimum security standards at the protocol level — mandatory code verification, proposal staking, and participation floors — treasury values will continue to outpace the security mechanisms protecting them.
The data suggests the current DAO governance model, predicated on one-token-one-vote with voluntary participation, does not scale to protect treasuries of this size. Whether the solution is veto councils, quadratic voting, or something yet designed, the status quo is measurably inadequate.