We audited the governance module of a live AI-agent protocol. Our AI found vote-manipulation flaws that can let a proposal pass illegitimately. Details withheld under responsible disclosure.
We found voting weight is computed from the transaction originator rather than the actual caller. A user tricked into calling a malicious contract will have their votes cast by the attacker — a classic phishing/vote-stealing pattern. The project's own code comment admits it.
Full mechanics withheld. Project owners: contact for the report.
We found proposals can pass with a single vote — no minimum participation threshold, so a small minority can push through a proposal.
Governance is where protocols get taken over. AI caught these flaws in minutes.