DeFi governance gives token holders the power to vote on protocol changes: fee structures, new collateral types, treasury spending, code upgrades, and parameter adjustments. Governance is typically on-chain: a proposal is submitted, a voting period runs (usually 3 to 7 days), and if quorum is met and the proposal passes, it executes automatically through a timelock contract. Governance tokens are the voting instrument; the value of governance rights depends entirely on the protocol’s value at stake.
How on-chain governance works
Compound pioneered the on-chain governance model adopted by most major DeFi protocols. COMP holders submit proposals and vote proportionally to their token balance. A proposal requires a minimum number of COMP to submit (to prevent spam) and a quorum of votes to pass. If passed, the proposal enters a 48-hour timelock before execution, giving users time to exit if they disagree with the outcome. Aave, Uniswap, Maker, and most large DeFi protocols use variants of this model.
Voter apathy is the most common practical problem. Most governance proposals pass with 2% to 8% of total token supply voting. Large token holders (VCs, foundations, whales) effectively control outcomes when retail participation is low. Delegation solves this partially: token holders can delegate their voting power to active participants without transferring ownership of the tokens themselves.
What this means for traders
Governance votes can directly affect token economics. A vote to increase the protocol’s fee switch (redirecting swap fees to governance token holders) can significantly change the fundamental value of the token overnight. A vote to add a new risky collateral type can increase protocol TVL but also systemic risk. Monitoring governance forums (Commonwealth, Snapshot, Tally) before major votes gives advance notice of changes that will affect token prices and yield rates.
The Curve Wars are the most significant governance dynamics in DeFi. CRV token holders who lock their tokens for up to 4 years receive veCRV, which controls the allocation of CRV emissions to different liquidity pools. Protocols that want to incentivize liquidity on Curve must either buy CRV, bribe veCRV holders through Votium, or accumulate their own veCRV position. At peak, the Curve Wars involved over $1 billion in CRV being accumulated by protocols competing for emission control. See: veTokenomics explained, DAO explained, and tokenomics explained.
A concrete example
In October 2022, a governance attacker exploited Mango Markets’ governance system. The attacker used governance tokens to pass a proposal granting themselves control of the protocol’s $117 million in remaining assets as “repayment” for the price manipulation exploit they had executed days earlier. The governance vote passed because the attacker held enough tokens to reach quorum. No code bug was exploited in the second step; the governance system worked exactly as designed, and it enabled the attacker to legitimize their theft. The Mango Markets incident remains the clearest example of governance as an attack surface rather than a security mechanism.
Frequently asked questions
What is a governance attack?
A governance attack uses token voting power to pass malicious proposals. An attacker can flash-loan governance tokens, vote on a proposal, then repay the loan in the same block if the protocol allows voting with tokens held at the time of the transaction. Most protocols now use a snapshot of token balances at a past block to prevent flash-loan governance attacks. However, purchasing tokens on the open market and accumulating enough to control votes is still a viable attack vector for well-funded adversaries.
What is a timelock in governance?
A timelock delays execution of passed proposals by a fixed period (typically 24 to 72 hours). During this window, users can review what is about to change and exit the protocol if they disagree. A timelock is the main safety mechanism against malicious governance proposals: even if a bad proposal passes, users have time to withdraw funds before it executes. Protocols without timelocks give governance token holders immediate execution power, which is a significant risk.
What is off-chain versus on-chain governance?
Off-chain governance (Snapshot) uses cryptographic signatures to record votes without paying gas, reducing participation friction. The results are non-binding: a multisig or core team executes the outcome. On-chain governance (Compound Governor, Aave’s governance contracts) executes automatically through smart contracts if the proposal passes. Off-chain governance is cheaper and has higher participation; on-chain governance is trustless and cannot be ignored by a team even if they disagree with the outcome.





