← LibraryTechnique entry
W3-GOV-TAKEOVERPrivilege Escalation
DAO Governance Takeover
Borrow voting tokens via flash loan during a snapshot, propose + vote yourself in as admin, repay loan.
§ Where this technique fits
W3-GOV-TAKEOVER is catalogued under the Privilege Escalation tactic of the offensive-security kill-chain. It appears in 2 approved dossiers in the registry, typically at step 3 on average.
§ Dossiers chaining this technique
- step 3 / 5
Flash-loan veCRV → capture Curve gauge → emission redirect
Snapshot voting on Curve gauges uses veCRV balance at a specific block. Borrow large CRV via flash-loan, lock for max veCRV, vote in attacker pool's favour, unlock (or accept the limit) — emissions redirected for the epoch.
- step 3 / 6
Flash-loan governance attack → DAO admin
Voting power = token balance at snapshot. Borrow enormous quantity via flash loan inside the snapshot tx, vote yourself in as admin, repay loan.
§ What commonly comes next
- 01Exfiltration Over C2 Channelseen 1×T1041 · Exfiltration
- 02Flash Loan Exploitseen 1×W3-FLASH-LOAN · Impact