MakerDAO Initiates Executive Vote On Flash Loan Attacks

  • The changes were proposed after last week BProtocol’s team used borrowed flash loans to sway a vote in their favor.
  • If approved by the community, the Maker protocol will increase its GSM Pause Delay and deauthorize its Oracle Freeze Module and Liquidations Circuit Breaker.

Illustration from Freepik

On October 30, MakerDAO announced that their Governance Facilitator and the Smart Contracts Domain Team have initiated an executive vote, which will allow users to vote on proposed security actions against malicious governance attacks.

The proposed changes come as a response to newly-detected voting behavior irregularities, which happened last week. If approved by the community, the GSM Pause Delay will be increased to 72 hours from the previous 12, which will allow the governance to effectively respond to a potential attack on the Maker protocol.

Moreover, the Oracle Freeze Module will be deauthorized to prevent freezing of the Oracle price feed by an attack using flash loans. This will also allow the governance to freeze the oracle without waiting for the GSM Pause Delay.

Another change proposed by the team is the deauthorizing of the Liquidations Circuit Breaker, which will prevent the freezing or unfreezing of vault liquidations by malicious third parties, with the Maker Governance being able to freeze or unfreeze liquidations without waiting for 72 hours.

Last week, the cryptocurrency community saw the first time in which an attacker uses flash-loans in order to alternate the governance vote. BProtocol flash borrowed $7 million worth of MKR tokens from the derivatives platform dYdX to swing the vote in its favor.

This happened after the available MKR liquidity exceeded the value of MKR on the hat, with the risk of malicious governance action being described as “unacceptably high”. A total of 63,445 MKR is currently accessible for borrowing through multiple platforms, which is enough to sway controversial new proposals.

The newly-announced executive vote will continue until the number of votes surpasses the total in favor of the previous one (a so-called continue approval vote), with members being able to join a community debate on these topics in the MakerDAO governance forum.

Discussion
Related Coverage
Top DeFi Protocols to Watch in 2023 and More
  • Decentralized finance (DeFi) has become one of the hottest trends in the crypto world as it’s more transparent and decentralized than traditional finance.
  • Here are our top picks of DeFi projects that have a good potential growth, and some of the protocols that did not made the list, such as RING Financial.
May 15, 2023, 2:22 PM
person scanning chart data

Shutterstock

Celsius Swaps Legal Team, Continues to Pay Off Debt
  • Celsius decided to hire new lawyers to advise on its available restructuring options, after reportedly resisting a Chapter 11 bankruptcy advice from previous counsel.
  • The company has also continued to repay its outstanding debt with DeFi lending protocols, and today transferred 20 million USDC to Aave, reducing its total debt to around $215 million.