> For the complete documentation index, see [llms.txt](https://funarchy.gitbook.io/funarchy/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://funarchy.gitbook.io/funarchy/security-for-prediction-market/governance/whale-cartel-attack.md).

# Whale Cartel Attack

#### Description

A governance attack is a situation where a majority of voting power is controlled by a single entity or cartel, and the results of important market decisions, such as YES/NO decisions, are manipulated to their own advantage.

At this time, the attacker can acquire the necessary voting rights by purchasing or borrowing governance tokens, and then propose a YES/NO decision to the attacker's desired YES/NO, and pass it by meeting the passing criteria with only his votes.

#### Real World Case Study

{% hint style="info" %}
[**Polymarket × UMA Governance Attack (2025)**](https://www.coindesk.com/markets/2025/03/26/polymarket-suffers-uma-governance-attack-after-rouge-actor-becomes-top-5-token-staker)
{% endhint %}

{% stepper %}
{% step %}
This incident occurred in the Polymarket prediction market, where the question "Does Ukraine agree to the Trump mineral deal before April?" was asked. \
(As shown in the figure below, this was a market where 96% of the market voted No)
{% endstep %}

{% step %}

<figure><img src="https://4210179539-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2DiVEbUgCTsp2iPassR9%2Fuploads%2FcVobkX409vdNtgAw3Jmk%2Fimage.png?alt=media&amp;token=5ae93158-b0a7-4ba2-a97b-4bbca8057f74" alt="" width="563"><figcaption><p>&#x3C;Market vote results></p></figcaption></figure>
{% endstep %}

{% step %}
In contrast, the voting results in UMA governance were contrary to expectations and the final result was YES.

<figure><img src="https://4210179539-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2DiVEbUgCTsp2iPassR9%2Fuploads%2FFksYYKiBApLJDxYp2Hzr%2Fimage.png?alt=media&amp;token=41feabc5-d98b-472b-9640-28e33e9329ac" alt="" width="563"><figcaption><p>&#x3C;UMA Governance Voting Results></p></figcaption></figure>
{% endstep %}

{% step %}
The normal outcome should be "No," but when examining the UMA governance metrics, we found that whales had voted "Yes." The actual percentage of "Yes" votes cast by whales exceeded 30% of the total, effectively altering the outcome. \
(The figure below shows the number of votes cast by a whale called **borntoolate.eth.**)

<figure><img src="https://4210179539-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2DiVEbUgCTsp2iPassR9%2Fuploads%2F2madtjIjojA0xFdheSRC%2Fimage.png?alt=media&amp;token=d8e7201a-e9e8-420e-abfe-bf4f0ea70d93" alt="" width="563"><figcaption><p>&#x3C;Whale's address and vote count></p></figcaption></figure>
{% endstep %}
{% endstepper %}

#### Mitigation

* Market capitalization increase
  * **Method (Dual Staking)**: 1 UMA + 0.0005 ETH = 1 vote
    * Based on the current price (UMA approximately 1,000 won + 0.0005 ETH approximately 2,000 won), the cost per voting right has increased by approximately 3 times.
    * Stablecoins are easy to raise through low-cost loans/flash loans, but they use ETH.
  * **Dynamic Ratio**: UMA votes on multiple proposals simultaneously in one round, and the same staked amount is used for all proposals in that round.
    * An attacker can raise the total OI of a single round by raising disputes in multiple markets, so that the “profit from a successful attack” exceeds the “cost of token acquisition/voting rights acquisition.”
  * **Response (Dynamic Scaling)**: Track the total OI of markets going up in the same round, and if the attack profit is close to/exceeding the attack cost, increase the ETH proportion (e.g. 1 UMA + 0.0006 ETH = 1 vote) to always maintain the attack profit < attack cost.
    * Adjust the ratio gradually according to OI to avoid sudden loss of user accessibility.
    * Disclosing tracking/adjustment status through UI alleviates distrust that “it suddenly got more expensive.”
  * **Penalty**: Both UMA and ETH are subject to slashing in case of incorrect voting (rule violation/misjudgment).


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://funarchy.gitbook.io/funarchy/security-for-prediction-market/governance/whale-cartel-attack.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
