Spiko’s Governance Faces Security Flaws: Unrestricted Calls, Voting Risks, and Lacks Community Safeguards
August 30, 2026
A comprehensive assessment reveals multiple attack vectors in Spiko’s on-chain governance, including unrestricted external calls during proposal execution, potential re-entrancy or token drains, and the risk of concentrated voting power amplified by flash loans.
Additional concerns include overlap between timelock and emergency pause admin roles enabling instant pauses and upgrades without safeguards, and upgradeability via a proxy pattern that lacks multi-sig protections.
Proposal metadata can grow without bound, raising the risk of out-of-gas execution for older proposals, and there is an absence of a community veto mechanism to counter harmful proposals.
Cross-chain bridge governance is tied to core governance, increasing the risk if bridge assets are exposed, while delegate-by-signature replay across chains due to missing chain-ID domain separation compounds the threat.
Summary based on 1 source
Get a daily email with more Tech stories
Source

DEV Community • Aug 30, 2026
Governance Attack Surface Review: Spiko