The exploit shows how lightly held voting tokens can become a means of attack when control of a protocol is cheaper than the assets it governs.