Sky Lending Governance Rated High Risk With Two Critical Vulnerabilities Found
A DeFi security audit of Sky Lending, a permissionless lending platform with approximately $5.45 billion in total value locked across Ethereum and Layer 2 networks, has assigned the protocol an overall governance risk score of 7.5 out of 10. Auditors identified eight vulnerabilities, with the most severe being a potential timelock bypass via re-entrancy in the execute function and unrestricted upgradeability through a ProxyAdmin solely controlled by the Governor contract. The report warns that an attacker acquiring as little as 0.6 percent of the SKY token supply — worth roughly $30 million — could push through malicious proposals due to a low 0.5 percent quorum threshold. Additionally, the top ten token holders control around 38 percent of voting power, with a single treasury address holding 12 percent and also owning the ProxyAdmin, creating a dangerous concentration of control. The audit concludes that both critical flaws could allow an adversary to seize full protocol control in a single transaction, threatening all user funds.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in