# kaal:claim:6819121-005

**Claim.** In the Beanstalk Farms exploit of April 2022, an attacker borrowed roughly one billion dollars in flash loans to hold two-thirds of governance tokens for a single block and drained roughly 182 million dollars, showing that token-weighted governance offers no defense against temporary token acquisition.

**Type.** empirical  **Support.** evidenced

**Holds when.**

- documented flash-loan governance attack

**Source quote.**

> The Beanstalk Farms exploit of April 17, 2022, in which an attacker borrowed approximately one billion dollars in stablecoin flash loans to acquire two-thirds of the protocol's governance tokens for a single block and used that supermajority to pass a malicious proposal that drained approximately 182 million dollars from the protocol, illustrates the pattern in stark form

**From.** Wulf A. Kaal, *The Institutional Deficit in Decentralized Autonomous Organizations - An Empirical Analysis* (2026), II. Theoretical Framework, page 7

**Cite as.** Wulf A. Kaal, The Institutional Deficit in Decentralized Autonomous Organizations - An Empirical Analysis (2026). SSRN: https://ssrn.com/abstract=6819121

**Verify.** sha256 of source PDF `f04b274f926d23848e77b429a13227baed9858b90fec826ddaabd2acca7035fe` at https://raw.githubusercontent.com/wulfkaal/Academic-Papers/main/papers/pdf/Kaal%20-%202026%20-%20The%20Institutional%20Deficit%20in%20Decentralized%20Autonomous%20Organizations%20-%20An%20Empirical%20Analysis.pdf

**Topics.** dao, consensus-and-security, defi, risk-and-incentives

**Canonical form.** This markdown file is the canonical hashed representation of the claim. Its sha256 is the content hash used for attestation.
