Press Enter to search · ESC to close

DeFi

Marinade Discloses DAO Vote Exploit: Malicious Proposals Defeated, No Funds Lost

An attacker manipulated Marinade's DAO voting procedure to inflate a small MNDE balance into outsized voting power and submitted two malicious proposals, including a fake "MIP-23" and a treasury transfer attempt. Token holders and the DAO Council defeated both within hours, and no funds were lost. Marinade has deployed a temporary fix and is preparing a permanent code remediation.

Marinade Flags Governance Exploit After Attackers Inflate Voting Power

Solana staking protocol Marinade has disclosed that an attacker exploited a flaw in its DAO voting procedure on September 25, manipulating a small amount of MNDE into voting power far exceeding its real quantity. Using that inflated weight, the attacker submitted two malicious proposals: one impersonating a “MIP-23” proposal designed to replace the voting program itself, and another attempting to move DAO treasury funds.

Neither succeeded. MNDE holders voted the proposals down, and the DAO Council exercised its veto within roughly six hours. With nearly four days still remaining before the proposals became executable, no capital ever left the treasury. Marinade confirmed that mSOL, Native Staking, and SAM were unaffected.

Why the Attack Matters

The incident is a textbook example of a governance-layer vulnerability rather than a smart-contract drain. The attacker did not break the staking protocol or steal validator assets; they targeted the mechanism that translates token balances into decision-making power. That distinction matters because governance bugs are often under-scrutinized relative to contract exploits, yet they can be just as destructive if a proposal reaches its execution window.

  • Vote-weight manipulation: A tiny MNDE position was counted as a dominant share of the vote.
  • Proposal spoofing: A fake “MIP-23” aimed to swap out the voting program — a classic setup for a permanent takeover.
  • Treasury extraction: A second proposal tried to move DAO funds directly.
  • Defense in depth: Token-holder voting plus a Council veto bought enough time to stop execution.

Governance as an Attack Surface

Marinade has deployed a temporary fix to block abnormal vote amplification and says a permanent code remediation plus stricter protections for sensitive proposals are coming. That layered response — emergency patch, then structural hardening — is becoming standard practice across DeFi, where governance tokens increasingly control real treasuries and upgrade authority.

The episode also highlights the value of time delays. The near four-day execution window gave the Council room to act, a design choice that has saved multiple DAOs from governance attacks. Protocols that shorten timelocks for “efficiency” trade away exactly the buffer that made this defense possible.

Outlook

Expect Marinade’s permanent fix to include stricter quorum rules, vote-weight caps, and possibly mandatory review for proposals touching the voting program itself. More broadly, the incident reinforces a lesson the sector keeps relearning: as DAOs mature into custodians of significant capital, governance contracts deserve the same audit rigor as the core protocol. For Solana’s staking ecosystem, the outcome is reassuring — the guardrails held — but the vulnerability itself is a reminder that the weakest link is often the ballot box, not the vault.

View original

Share
Risk notice This site provides news and information on the crypto, blockchain and Web3 industry for reference only and does not constitute investment advice or any promise of returns. Virtual currency-related activities are illegal financial activities in mainland China; digital asset prices are highly volatile; use at your own risk. This site does not provide trading, token issuance or related referral services.

Related Reading

Latest News

TREE NEWS share card
Long-press image above → Save to Photos / Share
Pitch us Feedback