On March 26, 2026, an unidentified attacker spent $1,808 to acquire 40 million MFAM governance tokens, created a malicious proposal, and reached quorum on the Moonwell lending protocol's Moonriver deployment — all within 11 minutes. The proposal, if executed, would transfer administrative control...
"The proposal is clearly an attack." — Luke Youngblood, Moonwell core contributor
On March 26, 2026, an unidentified attacker spent $1,808 to acquire 40 million MFAM governance tokens, created a malicious proposal, and reached quorum on the Moonwell lending protocol's Moonriver deployment — all within 11 minutes. The proposal, if executed, would transfer administrative control of seven lending markets, the comptroller, and the oracle to an attacker-controlled contract, putting $1.08 million in user deposits at risk.
The Moonwell incident is not an anomaly. It is the latest in a pattern of governance attacks stretching back to the $182 million Beanstalk flash loan exploit of April 2022. Despite four years of precedent, the structural conditions that enable these attacks — low voter turnout, thin token liquidity, concentrated voting power, and abandoned protocol deployments — remain largely unaddressed. DAO treasuries now exceed $24.5 billion in aggregate. The attack surface is growing faster than the defenses.
This report examines the mechanics of DAO governance attacks, catalogs the major incidents, quantifies the structural vulnerabilities, and assesses the emerging countermeasures.
Moonwell operates as a decentralized lending protocol across Moonbeam and Moonriver, both Polkadot-ecosystem chains. Total value locked across the protocol stands at approximately $85 million, according to DefiLlama data. The Moonriver deployment — the target — is a legacy instance that the team had been winding down.
The attack sequence, reconstructed from on-chain data and reporting by DL News and The Block:
The proposal's voting window extends through March 27, 2026. If executed, the attacker-controlled contract would gain the ability to modify interest rates, manipulate oracle feeds, and drain approximately $1.08 million in deposited user funds.
Moonwell's response relies on two mechanisms: community counter-voting and the "Break Glass Guardian," an emergency multisig with the authority to override governance decisions and block malicious execution. As of reporting, approximately 68% of votes cast oppose the proposal, suggesting the community recognized the threat. The Break Glass Guardian remains available as a backstop.
The incident followed a difficult period for Moonwell: in February, a faulty cbETH oracle configuration generated $1.8 million in bad debt on the protocol.
The Moonwell attack sits within a documented pattern. Major governance exploits since 2022:
Beanstalk — April 2022 — $182 million lost. An attacker flash-loaned over $1 billion from Aave, Uniswap, and SushiSwap to accumulate governance tokens (Stalk), triggered an emergency governance execution function requiring two-thirds voting threshold, and drained all protocol funds into a private wallet. The attacker netted approximately $80 million after repaying flash loans. Proceeds were laundered through Tornado Cash. The root cause: no flash-loan resistance in the governance voting mechanism.
Tornado Cash — May 2023 — $2.17 million stolen. An attacker submitted a proposal ostensibly to adjust relayer staking requirements. The code presented to voters included a hidden self-destruct function that, once executed, replaced the original logic with a malicious contract. The attacker minted 1.2 million governance votes to themselves, seizing total control of the DAO. TORN token price dropped 36%. The attacker subsequently offered to return control, and governance was partially restored.
Swerve Finance — March 2023 — $1.3 million at risk. A defunct DeFi protocol abandoned by its development team, Swerve still held $1.3 million in stablecoins. An attacker accumulated governance tokens across multiple addresses and attempted to pass proposals to transfer remaining funds. The attack unfolded over more than a week but ultimately failed — the attacker could not accumulate enough tokens to pass the quorum threshold. Wintermute's head of research Igor Igamberdiev published on-chain evidence identifying the alleged attacker.
Compound — July 2024 — $24 million contested. A whale known as "Humpy," operating through a delegate group called Golden Boys, passed Proposal 289 to transfer 499,000 COMP tokens (worth $24 million) to a yield protocol (goldCOMP) under their control. The vote passed 682,191 to 633,636, with voter turnout at just 4-5% of total supply. Wintermute and other large stakeholders objected. The dispute was resolved through negotiation: Humpy agreed to cancel the proposal in exchange for Compound creating a staking product distributing 30% of protocol reserves to COMP stakers.
Build Finance DAO — February 2022 — $470,000 lost. An anonymous attacker accumulated enough governance tokens to pass a proposal granting full control over the treasury and token minting capability. The treasury was drained entirely.
Cumulative documented losses from governance attacks since 2022 exceed $210 million.
The recurring pattern points to structural deficiencies, not isolated technical failures.
1. Voter apathy is endemic. Average voter turnout across DAOs stands at approximately 17%, according to 2025 aggregate data from DeepDAO and academic research. Most DAOs report participation below 10% of eligible token holders. For context, the Compound Proposal 289 that transferred $24 million passed with votes from fewer than 5% of outstanding COMP tokens. Low turnout means a small absolute number of tokens can determine outcomes.
2. Token concentration amplifies the risk. Approximately 78% of DAO governance tokens are held by the top 20% of stakeholders, per CoinLaw data. This creates a paradox: the same concentration that prevents some attacks (large holders can counter-vote) also enables others (a single large holder can pass proposals unilaterally when turnout is low).
3. Governance token liquidity creates an arbitrage. In the Moonwell case, the cost to acquire decisive voting power was $1,808 — against $1.08 million in extractable value. That is a 597:1 ratio of potential payoff to attack cost. When governance token market capitalization falls far below protocol TVL, the economic incentive to attack approaches certainty.
4. Emergency governance functions introduce single-point execution risk. Beanstalk's emergencyCommit function allowed a proposal to execute immediately upon reaching the two-thirds threshold, with no time delay. This eliminated the window for community response. Many protocols have since added time-locks, but implementation varies.
5. Code verification failures. The Tornado Cash attack succeeded because voters could not verify that the deployed contract matched the described proposal logic. The bait-and-switch — submitting benign-appearing code with a hidden self-destruct function — exploited a gap between what was described and what was deployed.
Swerve Finance and the Moonwell Moonriver deployment illustrate a category of risk specific to decentralized systems: abandoned or deprecated protocols that still hold user funds.
When development teams move on, governance activity declines, token prices collapse, and the cost of acquiring voting power drops proportionally. But deposited assets may retain full value. The Moonwell Moonriver deployment was being wound down, yet $1.08 million in deposits remained. Swerve Finance was entirely defunct, yet $1.3 million in stablecoins sat in its contracts.
There is no standardized procedure for sunsetting a DeFi protocol. No equivalent of a corporate liquidation or bankruptcy process exists. Funds persist in smart contracts indefinitely, guarded only by governance mechanisms whose defenders have economically rational reasons to leave.
This creates what amounts to unguarded vaults. The cost of acquiring keys (governance tokens) decreases over time while the value stored remains constant or decreases more slowly.
Protocols have deployed several countermeasures with mixed results:
Time-locks — Most major protocols now enforce a delay between proposal approval and execution (typically 24-72 hours). This provides a window for community response but does not prevent the attack itself. Moonwell's multi-day voting window allowed counter-mobilization; Beanstalk's instant-execute function did not.
Quorum thresholds — Setting minimum vote counts to validate a proposal. The Swerve attack failed precisely because the attacker could not meet quorum. However, quorum thresholds that are too high risk rendering governance inoperable.
Break Glass Guardian / Emergency multisigs — Moonwell's designated emergency multisig can override governance in extremis. This is effective but introduces centralization — a multisig of known parties that can unilaterally override token-holder votes. The trade-off between security and decentralization is explicit.
Vote-escrowed tokens (veToken models) — Requiring governance tokens to be locked for extended periods before granting voting power. This raises the cost of acquiring flash voting power. Curve Finance pioneered this model. It makes impulsive attacks more expensive but concentrates power among long-term holders, which can also be problematic.
On-chain proposal verification — Tools that allow voters to verify that deployed code matches proposal descriptions remain underdeveloped. The Tornado Cash bait-and-switch exploited this gap directly.
Governance token buybacks and burns — Reducing circulating supply to increase the cost of acquiring voting power. Limited adoption to date.
New incentive models introduced in pilot DAOs raised voter turnout by an average of 12 percentage points, according to 2025 data. Usage of governance tools like Snapshot and Tally increased 45% in 2025. Neither trend has been sufficient to close the structural vulnerability.
The numbers frame the scale of the problem:
The 81% native-token concentration figure is particularly relevant. When a DAO treasury is denominated in its own governance token, the token's price decline simultaneously reduces treasury value and the cost of acquiring voting control. This creates a reflexive dynamic: protocol distress makes governance attacks cheaper at precisely the moment they become most damaging.
The Moonwell attack cost $1,808. The Beanstalk attack cost a flash loan fee. The Compound dispute required sustained whale accumulation. The methods vary; the underlying condition does not. DAO governance systems are designed for a level of participation that does not exist.
The $24.5 billion in aggregate DAO treasuries represents significant economic value managed through governance mechanisms where fewer than one in five eligible voters participate. Emergency multisigs, time-locks, and quorum thresholds mitigate the risk but do not eliminate it. Each introduces its own trade-offs with the decentralization principles DAOs are built upon.
The Moonwell incident will likely be resolved without loss — the community counter-vote appears sufficient, and the Break Glass Guardian provides a backstop. But the fact that $1,808 and 11 minutes were enough to reach quorum on an $85 million protocol illustrates the structural fragility of token-weighted governance. As long as governance token liquidity remains thin relative to protocol value, and voter turnout remains low relative to quorum thresholds, the attack surface persists.