Can a DAO Treasury Be Drained by a Malicious Proposal?

A DAO treasury drained "legitimately" through a passed vote is a real risk if governance itself can be manipulated. Here's how, and what protections exist.

Published: October 3, 2026
Updated: October 3, 2026

A DAO's treasury — often holding substantial funds meant for the project's ongoing development or community initiatives — is typically accessible only through a passed governance vote, which means the vote itself, rather than any separate hack, can become the actual mechanism for draining it.

Why the Treasury's Access Mechanism Is Governance Itself

Unlike a treasury controlled by a single admin key or a small team, a properly decentralized DAO treasury requires a passed governance proposal to authorize any withdrawal or spending — this is generally considered a security improvement over centralized control, but it shifts the relevant attack surface to the voting process itself.

How a Malicious Proposal Could Theoretically Pass

If voting power is sufficiently concentrated in a small number of wallets, or if a flash loan or similar mechanism can temporarily acquire enough voting power, a proposal authorizing a treasury withdrawal to an attacker-controlled address could theoretically pass the same way any other proposal would — the treasury's funds move exactly as the governance system is designed to allow, just directed by a malicious rather than legitimate proposal.

Why Proposals Can Sometimes Be Disguised or Obscured

A malicious proposal isn't always presented transparently as "send treasury funds to this address" — some real incidents have involved proposals with misleading descriptions, technical complexity obscuring the actual effect of the code being voted on, or bundling a harmful action alongside seemingly legitimate, unrelated changes.

Why Reading a Proposal's Actual Code Matters More Than Its Description

The text description accompanying a governance proposal is written by whoever submitted it and doesn't necessarily accurately reflect what the underlying smart contract code the proposal would execute actually does — checking the actual code, or relying on independent technical review of it, provides a more reliable picture than the proposal's own summary.

Why Time Delays Between Proposal Passage and Execution Help Mitigate This

Some DAO structures include a mandatory delay between a proposal passing and its actual execution, providing a window during which the community can notice a problem and potentially organize a response — such as an emergency proposal to cancel or override the malicious action — before funds actually move.

Why Multisig-Controlled Treasury Execution Adds an Additional Check

Some DAOs require passed proposals to still be executed through a multisig wallet controlled by trusted signers, rather than fully automated execution — adding a human checkpoint that could catch an obviously malicious proposal even after it technically passed a vote, though this reintroduces some centralization in exchange for that safeguard.

What to Check About a Specific DAO's Treasury Protections

Whether proposals face a delay before execution, whether treasury actions require additional multisig confirmation beyond the vote itself, and the DAO's specific voting safeguards against the concentration and flash-loan risks that could allow a malicious proposal to pass in the first place.

Check a DAO's specific treasury execution safeguards and proposal review process — a passed vote authorizing treasury access is only as safe as the governance process that produced it.