A Malicious Proposal Drains About $20M From BonkDAO's Treasury

An attacker drained roughly $20 million from BonkDAO's treasury on July 6 without breaking a line of code. Over the preceding week the attacker accumulated 1.01% of the supply of BONK, the Solana-based token behind the project, which was just over the threshold needed to carry a vote, then submitted a governance proposal that moved treasury holdings to a wallet they controlled. Seven wallets voted yes, more than 18,000 abstained, turnout came to 2.9%, and the proposal executed automatically on-chain the moment it passed. BONK fell about 7% in the following 24 hours, though some outlets logged the drop at 8% to 10%. BonkDAO said it had identified the exchange wallets used to buy tokens ahead of the vote and was coordinating with exchanges, bridges and the Solana Foundation.
The Target: A Treasury That Belongs to the Token Holders
A DAO treasury is the pool of assets a decentralized autonomous organization holds in common — tokens, stablecoins and protocol revenue that belong to the organization rather than to any individual, and that no single person is supposed to be able to sign away. Direction over that money sits with the token holders, and they exercise it by voting. An on-chain governance proposal is the instrument they vote on: a transaction written out in advance, held pending while the vote runs, and, if it passes, executed by the governance contract itself with no human step between the result and the transfer. The design is deliberate, because it removes the possibility that whoever administers the treasury simply ignores an outcome they dislike. It also means a proposal that passes for the wrong reasons settles exactly as fast as one that passes for the right ones.
The Arithmetic: 1.01% of Supply Against 2.9% Turnout
Quorum is the minimum weight of votes a proposal must attract before it can pass at all, and it is normally set as a share of token supply on the assumption that ordinary participation will supply most of it. In practice most holders never vote. At 2.9% turnout the quorum bar and the winning margin become the same number, because there is almost no opposing weight on the other side of the ledger: whoever can buy past the threshold has bought the result outright. The attacker's position cost roughly $4.4 million in tokens purchased on Bybit and Binance, topped up with amounts borrowed through DeFi lending platforms, according to CoinDesk. Against a treasury worth about $20 million, the vote was cheaper than the thing it moved.
The Money: $188,000 Out, About $19 Million Behind a Multisig
Containment was partial. The proceeds landed in a multisig wallet, one that requires several separate approvals before funds can move again, and at the time of reporting about $188,000 had reached an exchange while roughly $19 million was still sitting behind those approvals. That leaves the recovery question with exchanges and bridges rather than with any contract fix, since there is no exploited function to patch and no transaction the protocol can characterize as invalid. It is the same shape as the year's other large losses that came from how control over funds was held rather than from a flaw in the code. The chain did what it was instructed to do, and the instruction was valid.
What Is Unresolved: Quorum Rules Priced Below the Treasury
Nothing about the mechanism has been fixed by the incident being over. A quorum threshold that costs less to buy than the treasury is worth remains an open invitation wherever turnout stays in the low single digits, and turnout is not something a protocol can legislate. The available defenses are structural rather than technical: execution delays that leave time to react between a vote passing and funds moving, spending caps that keep a single proposal from reaching the whole balance, or a guardian able to veto. Each of them trades away some of the automation that made on-chain governance attractive in the first place. What happened to BonkDAO was a permission granted in good faith and later used against the people who granted it, and the open questions now are whether the $19 million still behind the multisig can be frozen and whether the exchange accounts BonkDAO identified lead anywhere.
Read also: Ostium Loses $23.75M After Its Price Feed Key Is Compromised