What Is a Flash Loan Governance Attack?
A flash loan can briefly acquire enough governance tokens to swing a vote — with zero lasting capital commitment. Here's how the attack actually works.
A flash loan governance attack takes the same borrow-and-repay-within-one-transaction mechanism used in DeFi exploits and applies it directly to voting power itself — briefly acquiring enough governance tokens to swing a vote, all within a single, self-contained transaction.
Why This Combines Two Separate Mechanisms
This attack specifically combines how flash loans work — borrowing a large amount of capital with no collateral, repaid within the same transaction — with the underlying vulnerability of token-weighted governance voting, where voting power is determined by how many tokens a wallet holds at the relevant moment.
How the Attack Actually Executes
An attacker borrows a large amount of a DAO's governance token through a flash loan, uses that borrowed token balance to cast a vote (or votes) on a live proposal, and then repays the flash loan — all within a single transaction, meaning the attacker never needs to genuinely own or hold the tokens beyond that single, momentary voting action.
Why This Doesn't Require Genuine, Sustained Capital Commitment
Unlike acquiring governance tokens through a normal purchase and holding them, a flash loan attack requires no lasting capital commitment at all — the attacker's exposure is limited to the transaction fee and any flash loan fee, rather than the actual value of the tokens used to swing the vote.
Why This Specifically Exploits a Snapshot-Based Voting Design
This attack works against governance systems that check a wallet's token balance at the exact moment of voting, rather than requiring tokens to have been held for some minimum period beforehand — a design that doesn't distinguish between genuine, long-term stakeholders and a balance that exists for a single transaction.
Why Vote-Locking Mechanisms Specifically Defend Against This
Some DAOs require governance tokens to be locked or held for a minimum duration before they count toward voting power, specifically to prevent exactly this kind of instantaneous, single-transaction manipulation — a flash loan's borrowed tokens can't satisfy a holding-period requirement, since the loan only exists for one transaction.
Why This Attack Vector Became More Widely Discussed After Real Incidents
Documented real-world instances of flash loan governance attacks against specific protocols have demonstrated this isn't purely a theoretical vulnerability — actual governance decisions have been influenced or attempted through exactly this mechanism, prompting many protocols to reconsider their voting design specifically in response.
What This Means for Evaluating a Specific DAO's Governance Resilience
Checking whether a DAO's governance system uses snapshot-based voting vulnerable to this specific attack, or includes vote-locking or other time-based safeguards that would prevent a flash-loaned token balance from being usable for voting purposes.
Check whether a DAO's governance design includes vote-locking or other protections against flash loan manipulation before assuming a vote's outcome reflects genuine, sustained stakeholder sentiment.