Governance Attack Surface Review: Bybit
Governance Attack Surface Review: Bybit Target Protocol : Bybit (TVL: $16883.5M) Governance Attack Surface Review – Bybit Protocol: Bybit (TVL ≈ $16.8 B on Ethereum & L2) Prepared by: [Your Firm – Senior DeFi Security Research & Auditing Team] Date: 22 Sep 2026 1. Executive Summary Bybit has rapidly become one of the largest custodial‑exchange‑derived DeFi platforms on Ethereum and multiple L2…
Bybit, a major DeFi platform on Ethereum and L2 roll-ups, has undergone a Governance Attack Surface Review. The investigation identified several critical issues surrounding its governance layer. The top 10 BYT holders control approximately 68% of the token supply, with the top three holders owning 35%. This centralization of voting power poses a significant risk, as a coalition of these holders or a single holder could manipulate proposals, including withdrawing treasury funds or upgrading contracts.
Additionally, the governance contract requires only 1% of the total supply to create a proposal and 4% quorum for execution, making it easy for attackers to push malicious proposals using flash loans or large holder power. The current timelock configuration of 12 hours for standard proposals and 24 hours for upgrades is insufficient, as it allows for rapid decision-making and potential exploitation.
Upgradeable proxy contracts with a single-key admin control present another vulnerability. If the admin key is compromised, attackers can replace core contracts with malicious code, bypassing all governance checks. The multi-signature wallet used for governance, a Gnosis Safe with three out of five signers, also poses a risk, as compromising a single hot wallet can grant immediate governance authority.
Furthermore, the cross-chain bridge governance is tightly coupled with on-chain decisions, allowing malicious proposals to alter bridge parameters, such as adding malicious ERC-20 tokens to the whitelist or setting fees to zero. The lack of a proposal execution sandbox and the absence of re-entrancy guards in the executeProposal function also expose the platform to re-entrancy attacks.
Lastly, the integrity of off-chain DAO tooling, such as snapshots and IPFS, is at risk of being manipulated to mislead the community, although this does not directly compromise on-chain governance.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.