RIADeFi

Sky discloses remediated vote-tally amplification flaw

The Ledger · · Ketju Research

PostmortemConfirmed evidence

Affects: Sky (protocol)

What happened

Skybase disclosed a portal tally flaw that could count a voter's weight repeatedly through malformed encoded ballots.

What changed

The team states that ballot deduplication and a single-choice cardinality guard entered production on July 21.

What did not change

This is not evidence of an Arbitrum bridge failure. The post reports no user funds at risk and does not establish an actual manipulated historical poll.

Confirmed

  • The postmortem dates the Immunefi report to June 23, 2026.
  • The team reproduced the flaw against a local fork of the deployed Arbitrum polling contract and the real tally implementation.
  • The team reports production deployment of two defensive layers on July 21.
  • A historical malformed-ballot audit remains planned.

Still open

  • Whether malformed ballots affected any historical live poll.
  • Completion of regression tests and review of other aggregation paths.
  • Independent verification of the production fix.

What it means for an advisor

  • Review the Sky memo's governance-integrity assumptions and request the historical-vote audit before concluding there was no past governance impact.

Sources

  1. Post-Mortem for Immunefi bug report #82775 · Skybase governance team · · effective

Version 1, published . We check this event again on . Educational research, not investment advice.