header-langage
简体中文
繁體中文
English
Tiếng Việt
한국어
日本語
ภาษาไทย
Türkçe
Scan to Download the APP

Marinade: The attacker exploited a voting vulnerability to initiate two malicious proposals, both of which have been rejected.

BlockBeats news, October 1st, Marinade stated that on September 25th, attackers exploited a vulnerability in the Marinade DAO voting process, attempting to take control of the DAO through two malicious proposals. The attackers needed only a small amount of MNDE tokens to obtain voting power far exceeding their actual holdings, and successively submitted a forged "MIP-23" proposal attempting to replace the DAO voting process, as well as another proposal to transfer DAO treasury funds. Both proposals were ultimately rejected, no funds were transferred during this period, and mSOL, native staking operations, and SAM were all unaffected.


The DAO's multi-layered governance mechanism prevented this attack. MNDE holders had already held the majority in the votes on both proposals, and the DAO committee exercised veto power within 6 hours after discovering the anomaly, still nearly 4 days before the relevant proposals were originally scheduled for execution. That evening, Marinade released a fix to prevent the vulnerability from further amplifying voting power. The rejected proposals will be permanently invalid and cannot be executed again, the DAO treasury funds currently remain intact, and MNDE holders need not take additional measures.


Marinade stated that the next step will be to implement a permanent code fix and add additional security measures for sensitive governance proposals, while introducing an AI-driven analysis mechanism to review all new proposals. In addition, the team has notified Realms DAO maintainers to help other DAOs guard against similar vulnerabilities.

举报 Correction/Report
Correction/Report
Submit
Add Library
Visible to myself only
Public
Save
Choose Library
Add Library
Cancel
Finish