Sky discloses remediated vote-tally amplification flaw
The Ledger · · Ketju Research
Affects: Sky (protocol)
What happened
Skybase disclosed a portal tally flaw that could count a voter's weight repeatedly through malformed encoded ballots.
What changed
The team states that ballot deduplication and a single-choice cardinality guard entered production on July 21.
What did not change
This is not evidence of an Arbitrum bridge failure. The post reports no user funds at risk and does not establish an actual manipulated historical poll.
Confirmed
- The postmortem dates the Immunefi report to June 23, 2026.
- The team reproduced the flaw against a local fork of the deployed Arbitrum polling contract and the real tally implementation.
- The team reports production deployment of two defensive layers on July 21.
- A historical malformed-ballot audit remains planned.
Still open
- Whether malformed ballots affected any historical live poll.
- Completion of regression tests and review of other aggregation paths.
- Independent verification of the production fix.
What it means for an advisor
- Review the Sky memo's governance-integrity assumptions and request the historical-vote audit before concluding there was no past governance impact.
Sources
- Post-Mortem for Immunefi bug report #82775 · Skybase governance team · · effective
Version 1, published . We check this event again on . Educational research, not investment advice.