Governance Risk
Governance risk is the possibility that decisions made through a protocol’s governance process (token voting, multisig, or admin actions) negatively affect users—via malicious proposals, poor parameter changes, or capture by large holders.
✦ Key Insight
Even well-audited DeFi protocols can be altered by governance. Traders holding positions or providing liquidity are exposed to sudden fee changes, collateral adjustments, or outright malicious upgrades that can devalue or seize funds.
✕ Common Misconceptions
Ignoring token distribution and quorum rules; assuming “decentralized” means immune to capture; failing to monitor active proposals while capital is deployed.
Detailed Explanation
How It Works: Most protocols issue governance tokens. Holders vote on proposals. If voting power is concentrated, or if flash-loan attacks temporarily boost votes, harmful changes can pass. Some protocols retain emergency admin powers that bypass normal voting.
FAQs:
How to mitigate?
Prefer protocols with time-locks, multisigs, and distributed token ownership.
Is no governance safer?
Sometimes,immutable contracts have zero governance risk but cannot fix bugs.
Flash-loan governance attacks still possible?
Yes on some designs.
In Practice
Dig Deeper
Governance Token
A governance token is a token that grants its holders the right to vote on changes to a protocol — fee parameters, treasury spending, code upgrades, or strategic decisions. Holding the token is the on-chain equivalent of owning a share of the project's decision-making.
DAO
A DAO, or Decentralized Autonomous Organization, is a community-led organization that uses blockchain tools for governance and decision-making.
Admin Key
An admin key (or privileged key/role) is a private key or multisig address that retains special permissions over a smart contract—such as upgrading code, pausing the protocol, changing parameters, or withdrawing funds.

Ad
Get a $100K funded account
See current qualification terms and payout conditions.
Sponsored
