On-chain voting has its own attack surface. An attacker can borrow voting tokens via a flash loan to pass a proposal in one transaction, buy votes, or sneak a malicious proposal past inattentive voters (e.g. to drain the treasury). Defenses: voting delays/timelocks, snapshot-based voting power, quorums, and vote-escrow (locking tokens). Governance is a security domain, not just politics.