No funds lost as Marinade Finance DAO suffers malicious proposal attack, vulnerability patched
Odaily reports: Marinade Finance stated that on September 25, its DAO was attacked by actors who attempted to seize governance control through two malicious proposals, but both proposals were rejected by the DAO committee. No funds were transferred, and mSOL, Native Staking, and SAM services were unaffected. The attackers exploited a vulnerability in the DAO voting process to have a small amount of MNDE tokens counted as voting power far exceeding their actual amount, and submitted a forged "MIP-23" proposal attempting to replace the voting process; they simultaneously submitted another proposal attempting to transfer DAO treasury assets. The actual voting power of MNDE holders exceeded that of the two malicious proposals, and the DAO committee completed the rejection within 6 hours, approximately 4 days ahead of the proposals' originally scheduled execution time.
