An independent developer released a blog post detailing how an attacker could purchase around 40,000 MKR tokens to gain control of governance and call a function issuing themselves all of the locked collateral. In addition, they could print infinite Dai which could then be used on platforms like Uniswap and Compound to permanently borrow assets.
This problem could have been mitigated by a delay function that would allow other stakeholders the ability to trigger a global shutdown thwarting the attackers, however, the parameter was set to 0 seconds. The Maker team has since responded by issuing a proposal to increase the Governance Security Module (GSM) delay to 24 hours.
Why it matters: