# Sky discloses remediated vote-tally amplification flaw

> The team states that ballot deduplication and a single-choice cardinality guard entered production on July 21.

- URL: https://riadefi.com/on-chain/2026-09-03-sky-governance-portal-immunefi-82775/
- Type: Security incident
- Stage: Postmortem
- Evidence: confirmed
- Materiality: material
- Event date: 2026-09-03
- Version: 1, published 2026-09-15 (first published 2026-09-15)
- Follow-up: 2026-09-11
- Advisor-relevant: yes
- Affects: Sky (protocol)

## What happened

Skybase disclosed a portal tally flaw that could count a voter's weight repeatedly through malformed encoded ballots.

## What changed

The team states that ballot deduplication and a single-choice cardinality guard entered production on July 21.

## What did not change

This is not evidence of an Arbitrum bridge failure. The post reports no user funds at risk and does not establish an actual manipulated historical poll.

## Confirmed

- The postmortem dates the Immunefi report to June 23, 2026.
- The team reproduced the flaw against a local fork of the deployed Arbitrum polling contract and the real tally implementation.
- The team reports production deployment of two defensive layers on July 21.
- A historical malformed-ballot audit remains planned.

## Still open

- Whether malformed ballots affected any historical live poll.
- Completion of regression tests and review of other aggregation paths.
- Independent verification of the production fix.

## What it means for an advisor

- Review the Sky memo's governance-integrity assumptions and request the historical-vote audit before concluding there was no past governance impact.

## Sources

1. [Post-Mortem for Immunefi bug report #82775](https://forum.skyeco.com/t/post-mortem-for-immunefi-bug-report-82775/28214) · Skybase governance team · 2026-09-03


---

Published by Ketju Research on RIADeFi (https://riadefi.com). Educational research for financial professionals; not investment, legal, tax, or compliance advice.
