We audited the governance timelock of a live AI-agent protocol. Our AI found a critical access-control flaw that can gut the timelock's protection. Details withheld under responsible disclosure.
We found the delay parameter can be changed by any caller, and can be set to 0 — instantly bypassing the timelock's purpose. A malicious actor could neutralize the delay and execute queued transactions immediately.
The project's own code comment admits the zero-delay risk. Full mechanics withheld. Project owners: contact for the report.
A governance timelock that can be zeroed by anyone is no timelock at all. AI caught it in minutes.