COVER ยท RISK

Governance risk

The rules your money sits under are changeable

What can happen

Voting rights are usually a token themselves. And a token can be bought, borrowed or accumulated.

Whoever holds enough of them can put a proposal forward and pass it themselves. What such a proposal may do differs from protocol to protocol - and is often more than users expect: change fees, shift parameters, swap out the oracle, replace contracts with new ones, in some cases reach the till.

Getting there need not take years. There are constructions in which voting rights are borrowed for the duration of a single transaction, used to vote and then given back.

How that turns into a financial loss

In two ways that match in their result but differ entirely in how they are judged.

The open route: a resolution redirects funds or changes the rules so that they flow out. For the blockchain that is a valid operation. There is no break-in, there is a majority.

The quiet route: a resolution changes a parameter that looks harmless - a threshold, a deadline, a price source. The loss arises days later and then looks like an ordinary market event.

Anyone with money in a protocol has it sitting under rules somebody else is allowed to change. That is not a malfunction of the system, it is its design.

A documented case

DOCUMENTED CASEBeanstalk, April 2022
On 17 April 2022 an attacker borrowed funds worth around one billion US dollars for the duration of a single transaction, converted them into voting rights in the Beanstalk protocol and thereby held more than two thirds of the votes - exactly the majority that triggers an emergency decision without a waiting period. In the same operation he called the emergency function provided for and thereby executed a proposal submitted earlier that transferred the protocol’s funds to his own address. He then repaid what he had borrowed. Around 182 million US dollars flowed out; about 76 million of it stayed with the attacker.

That is exactly where the difficulty of this risk lies. With smart contract risk it can be shown that something ran otherwise than intended. Here everything ran as intended - the emergency function was part of the rules, the majority was real. It is only that nobody meant what was intended to be used that way.

Can this be the subject of a cover?

To a limited extent. Of all the risks described here this is the hardest to pin down.

The event is fully visible onchain - better documented than any hack. It is only that what is visible is a properly conducted vote. A wording therefore does not have to establish whether something happened but whether what happened was abusive - and that is a judgement, not an observation.

Some products exclude governance expressly. Others cover it under narrow conditions, for instance where voting rights were borrowed or deliberately accumulated in a short time.

THE MOST USEFUL PART

What the wording has to answer

Is governance covered at all?More often excluded than covered. That line is rarely under “governance” but among the general exclusions.
What separates abuse from politics?An unpopular but honest decision is not a loss. Where does the line run, and who draws it?
Does borrowed voting weight count?Votes borrowed for the duration of a transaction are the clearest marker - and in some wordings the only one.
Who determines it?A committee, an expert, another vote? Where a judgement is called for, the procedure decides the outcome.
Indirect losses too?A changed parameter often takes effect only later. Is the connection still covered then?
What if the resolution is reversed?Protocols occasionally overturn resolutions. Does the payment fall away with it?
ASSUMED KNOWLEDGE

Terms used here

  • Protocol

    Why a protocol is more than its contracts - and who steers it.

  • Hack and exploit

    The difference between breaking in and following the rules, here in its purest form.

  • Oracle

    One of the dials that can be swapped out by resolution.