AI Audit Found a Governance-Hijack Flaw in a Timelock

minia2a · August 2026 · AI Contract Audit · Static Scan

We audited the governance timelock of a live AI-agent protocol. Our AI found a critical access-control flaw that can gut the timelock's protection. Details withheld under responsible disclosure.

Finding — Critical, under responsible disclosure

CRITICALTimelock delay settable by anyone, including to zero

We found the delay parameter can be changed by any caller, and can be set to 0 — instantly bypassing the timelock's purpose. A malicious actor could neutralize the delay and execute queued transactions immediately.

The project's own code comment admits the zero-delay risk. Full mechanics withheld. Project owners: contact for the report.

A governance timelock that can be zeroed by anyone is no timelock at all. AI caught it in minutes.

Full report available to project owners. If your governance may be affected, contact us before it gets exploited.
AI Deep Audit — $200 (business-logic & economic flaws + responsible disclosure)
Static Scan — $2 (10 vulnerability patterns)
AI audit is probabilistic — may miss vulnerabilities or report non-issues. Treat as guidance, not proof.