AI Audit Found Vote-Manipulation Flaws in a Governor

minia2a · August 2026 · AI Contract Audit · Static Scan

We audited the governance module of a live AI-agent protocol. Our AI found vote-manipulation flaws that can let a proposal pass illegitimately. Details withheld under responsible disclosure.

Findings — High, under responsible disclosure

HIGHVoting weight tied to tx.origin — phishing can vote for you

We found voting weight is computed from the transaction originator rather than the actual caller. A user tricked into calling a malicious contract will have their votes cast by the attacker — a classic phishing/vote-stealing pattern. The project's own code comment admits it.

Full mechanics withheld. Project owners: contact for the report.

HIGHNo quorum requirement

We found proposals can pass with a single vote — no minimum participation threshold, so a small minority can push through a proposal.

Governance is where protocols get taken over. AI caught these flaws in minutes.

Full report available to project owners. If your governance may be affected, contact us before it gets exploited.
AI Deep Audit — $200 (business-logic & economic flaws + responsible disclosure)
Static Scan — $2 (10 vulnerability patterns)
AI audit is probabilistic — may miss vulnerabilities or report non-issues. Treat as guidance, not proof.