Smart Contract Upgrade Governance: A 2024 Risk Brief
Table of Contents
Table of Contents
Share

Assess protocol governance risk in smart contract upgrades: quorum, timelock delays, and the 2022 flash-loan governance exploit allocators must audit in 2024.
Frequently Asked Questions
- Protocol governance is the on-chain voting process that decides whether a smart contract upgrade proceeds. Token holders or delegates submit a proposal, vote for a fixed period, and if the proposal clears a quorum and majority threshold, it is queued in a timelock before the new logic goes live. The design of that vote, who can propose, how much voting weight is needed, and how long the delay lasts, is the actual risk control on the upgrade.
- Beanstalk lost roughly 181 million dollars in April 2022 because its governance let voting power be calculated from a token balance held at the moment of the vote rather than a prior snapshot. An attacker flash-loaned enough capital to pass and execute a malicious proposal inside a single transaction, draining the protocol before anyone could react. It showed allocators that a governance process without snapshot voting and a real timelock delay is not a safety mechanism, it is an attack surface.
- Score four variables: whether voting power is drawn from a historical snapshot rather than a live balance, the size of the quorum relative to circulating supply, the length of the timelock delay between a vote passing and execution, and who holds emergency override keys. A protocol strong on all four converts governance from a hidden liability into a disclosed, priceable risk, which is the return-side of the diligence.
Don't Miss What's Next
Subscribe to newsletter
Governance
Smart Contract Security
Web3 Strategy
Get in Touch
Our team will get back to you within 24 hours.



















