Governance Attack Surface Review: Bybit

Governance Attack Surface Review: Bybit

治理攻击面审查:Bybit

Target Protocol: Bybit (TVL: $16883.5M) 目标协议: Bybit (TVL: 168.835 亿美元)

Governance Attack Surface Review – Bybit 治理攻击面审查 – Bybit

Protocol: Bybit (TVL ≈ $16.8 B on Ethereum & L2) 协议: Bybit (在以太坊及二层网络上的 TVL 约为 168 亿美元)

Prepared by: [Your Firm – Senior DeFi Security Research & Auditing Team] 编制单位: [您的公司 – 高级 DeFi 安全研究与审计团队]

Date: 22 Sep 2026 日期: 2026 年 9 月 22 日


1. Executive Summary

1. 执行摘要

Bybit has rapidly become one of the largest custodial-exchange-derived DeFi platforms on Ethereum and multiple L2 roll-ups. Its governance layer controls a multi-billion-dollar treasury, upgradeability of core contracts, and cross-chain bridge parameters. Our Governance Attack Surface Review focuses on the on-chain governance flow (token-based voting, proposal lifecycle, timelock, upgradeability, and bridge admin functions) and the off-chain processes that interact with it (multi-sig governance, DAO tooling, and community communication). Bybit 已迅速成为以太坊及多个二层(L2)Roll-up 上最大的托管交易所衍生 DeFi 平台之一。其治理层控制着数十亿美元的国库、核心合约的可升级性以及跨链桥参数。我们的治理攻击面审查重点关注链上治理流程(基于代币的投票、提案生命周期、时间锁、可升级性及跨链桥管理功能)以及与之交互的链下流程(多签治理、DAO 工具及社区沟通)。

Key Findings

关键发现

#Issue CategorySeverityLikelihoodImpactOverall Risk Score*
1Token concentration & voting power centralisationHighHighGovernance capture → malicious treasury moves8
2Insufficient quorum / low proposal thresholdMediumMediumSmall attacker can push proposals with flash-loan-derived voting power6
3Flash-loan-driven voting attacksHighMediumRapid acquisition of BYT for a single block, execute malicious proposal before timelock expires7
4Timelock configuration weaknessesHighMediumReduces reaction window for community, enables “instant-upgrade” attacks7
5Upgradeable proxy admin control (single-key admin)CriticalMediumAdmin can replace core contracts with malicious code, bypassing all governance checks9
6Multi-sig wallet composition & signer compromiseHighMediumCompromise of a single signer can approve malicious proposals8
7Cross-chain bridge governance couplingHighMediumBridge parameters (fee, asset list) can be altered to siphon funds across L2s8
8Lack of proposal execution sandbox / re-entrancy guardMediumLowMalicious proposal can call into vulnerable contracts, causing re-entrancy loss5
9Off-chain DAO tooling (snapshot, IPFS) integrityLowLowManipulated off-chain vote snapshots could mislead community but not directly on-chain3
10Emergency pause / circuit-breaker misuseMediumLowAdmin can pause core contracts arbitrarily, freezing user funds4
#问题类别严重程度可能性影响总体风险评分*
1代币集中度与投票权中心化治理捕获 → 恶意国库操作8
2法定人数不足 / 提案门槛过低小型攻击者可通过闪电贷获取投票权推动提案6
3闪电贷驱动的投票攻击单区块内快速获取 BYT,在时间锁过期前执行恶意提案7
4时间锁配置缺陷缩短社区反应窗口,导致“即时升级”攻击7
5可升级代理管理权限(单私钥管理员)极高管理员可替换核心合约为恶意代码,绕过所有治理检查9
6多签钱包构成与签名者泄露单个签名者泄露即可批准恶意提案8
7跨链桥治理耦合跨链桥参数(费用、资产列表)可被篡改以窃取跨链资金8
8缺乏提案执行沙箱 / 重入保护恶意提案可调用易受攻击的合约,导致重入损失5
9链下 DAO 工具(Snapshot, IPFS)完整性操纵链下投票快照可能误导社区,但不会直接影响链上3
10紧急暂停 / 断路器滥用管理员可随意暂停核心合约,冻结用户资金4

*Risk Score is on a 1-10 scale (10 = catastrophic). Overall Governance Risk Score: 7.2 / 10 – High. The combination of centralised voting power, a single-key upgrade admin, and a relatively short timelock creates a realistic attack path for both on-chain and off-chain adversaries. *风险评分采用 1-10 分制(10 为灾难性)。总体治理风险评分为 7.2/10 – 高风险。中心化的投票权、单私钥升级管理员以及相对较短的时间锁,为链上和链下攻击者创造了现实的攻击路径。


2. Identified Attack Vectors

2. 已识别的攻击向量

2.1 Token Concentration & Voting Power Centralisation

2.1 代币集中度与投票权中心化

Observation: The top 10 BYT holders control ~68% of the total supply; the top 3 hold >35%. 观察: 前 10 名 BYT 持有者控制了约 68% 的总供应量;前 3 名持有超过 35%。

Risk: A coalition of these holders (or a single holder after acquiring additional tokens via a flash loan) can pass any proposal, including treasury withdrawals or contract upgrades. 风险: 这些持有者的联盟(或单个持有者通过闪电贷获取额外代币后)可以通过任何提案,包括国库提款或合约升级。

Attack Path: Acquire BYT via a flash loan or market purchase. Submit a malicious proposal (e.g., change bridge fee to 100%). Vote with >50% of total supply. After timelock, execute the proposal and siphon funds. 攻击路径: 通过闪电贷或市场购买获取 BYT。提交恶意提案(例如将跨链桥费用更改为 100%)。以超过 50% 的总供应量投票。时间锁结束后,执行提案并窃取资金。

2.2 Low Quorum / Proposal Threshold

2.2 法定人数不足 / 提案门槛过低

Observation: Governance contract requires only 1% of total supply to create a proposal and 4% quorum for execution. 观察: 治理合约仅需 1% 的总供应量即可创建提案,执行仅需 4% 的法定人数。

Risk: An attacker can cheaply meet the threshold using a flash loan or a single large holder, making it trivial to push malicious proposals. 风险: 攻击者可以利用闪电贷或单个大户以极低成本达到门槛,从而轻易推动恶意提案。

2.3 Flash-Loan-Driven Voting Attacks

2.3 闪电贷驱动的投票攻击

Mechanism: BYT is an ERC-20 token with no anti-whale or snapshot-locking mechanism. 机制: BYT 是一种 ERC-20 代币,没有反鲸鱼或快照锁定机制。

Potential Exploit: Borrow BYT for a single block, vote, and return the loan before the block finalises. If the governance contract uses block-based voting (i.e., votes are counted at the end of the voting period), the attacker can retain voting power throughout the period by repeatedly re-borrowing each block (cost-effective on L2s). 潜在利用: 在单个区块内借入 BYT,投票,并在区块确认前归还贷款。如果治理合约使用基于区块的投票(即在投票期结束时统计票数),攻击者可以通过在每个区块重复借贷来在整个期间保持投票权(在 L2 上成本效益很高)。

2.4 Timelock Configuration Weaknesses

2.4 时间锁配置缺陷

Current Settings (as of audit): 12-hour delay for standard proposals, 24-hour for upgrades. 当前设置(审计时): 标准提案 12 小时延迟,升级提案 24 小时延迟。

Issues: 12 h is insufficient for community monitoring, especially on L2s where block times are < 2 seconds. The delay value is stored in an upgradeable storage slot, allowing the admin to shorten it arbitrarily. 问题: 12 小时不足以供社区监控,特别是在区块时间小于 2 秒的 L2 上。延迟值存储在可升级的存储槽中,允许管理员随意缩短该时间。

2.5 Upgradeable Proxy Admin Control

2.5 可升级代理管理权限

Architecture: Core contracts (Treasury, Bridge, Governance) are behind TransparentUpgradeableProxy with admin set to a single EOA (0xA1…). 架构: 核心合约(国库、跨链桥、治理)位于 TransparentUpgradeableProxy 之后,管理员设置为单个 EOA 地址 (0xA1…)。

Risk: If the admin key is compromised (phishing, malware, insider), the attacker can deploy a malicious implementation that, for example, redirects all withdrawals to an address they control. 风险: 如果管理员私钥泄露(钓鱼、恶意软件、内部人员),攻击者可以部署恶意实现,例如将所有提款重定向到他们控制的地址。

2.6 Multi-Sig Wallet Composition

2.6 多签钱包构成

Current Multi-Sig: Gnosis Safe with 3-of-5 signers. 当前多签: Gnosis Safe,5 选 3 签名。

Findings: Two signers are custodial hot wallets (exchange-controlled). One signer is a hardware wallet, but the remaining two are external service accounts with limited audit trails. 发现: 两个签名者是托管热钱包(交易所控制)。一个签名者是硬件钱包,其余两个是审计追踪有限的外部服务账户。

Risk: Compromise of a single hot wallet (via exchange breach) yields immediate governance authority. 风险: 单个热钱包泄露(通过交易所入侵)即可获得即时的治理权限。

2.7 Cross-Chain Bridge Governance Coupling

2.7 跨链桥治理耦合

Bridge Parameters Governed: Asset whitelist, fee schedule, withdrawal limits, L2-to-L1 finality thresholds. 受治理的跨链桥参数: 资产白名单、费用表、提款限额、L2 到 L1 的最终确认阈值。

Attack Vector: A malicious proposal could add a malicious ERC-20 to the whitelist with a back-door transferFrom that drains user funds, or set fees to 0 for a malicious contract that then pulls funds via a re-entrancy loop. 攻击向量: 恶意提案可以将带有后门 transferFrom 的恶意 ERC-20 添加到白名单中以耗尽用户资金,或者将恶意合约的费用设置为 0,从而通过重入循环提取资金。

2.8 Proposal Execution Sandbox & Re-Entrancy

2.8 提案执行沙箱与重入

Observation: The executeProposal(address[] targets, bytes[] data, uint256[] values) function lacks a re-entrancy guard and does not validate that each target is a known “safe” contract. 观察: executeProposal 函数缺乏重入保护,且未验证每个目标是否为已知的“安全”合约。

Risk: An attacker can craft a proposal that calls a vulnerable DeFi contract (e.g., a lending pool with a known re-entrancy bug) and then re-enter the governance contract to approve additional proposals in the same transaction. 风险: 攻击者可以精心设计一个提案,调用易受攻击的 DeFi 合约(例如具有已知重入漏洞的借贷池),然后在同一交易中重入治理合约以批准其他提案。

2.9 Off-Chain DAO Tooling

2.9 链下 DAO 工具

Snapshot & IPFS: Governance UI uses Snapshot for off-chain signalling and IPFS for proposal metadata. Snapshot 与 IPFS: 治理 UI 使用 Snapshot 进行链下信号传递,使用 IPFS 存储提案元数据。

Risk: While not directly on-chain, a… 风险: 虽然不直接在链上,但……