πŸš€ Premium Banner Placement β€” Reach 100K+ daily crypto readersAdvertise with us β†’
LIVE
BTCβ€”ETHβ€”SOLβ€”BNBβ€”XRPβ€”ADAβ€”AVAXβ€”DOGEβ€”LINKβ€”DOTβ€”MATICβ€”ATOMβ€”LTCβ€”TRXβ€”TONβ€”BTCβ€”ETHβ€”SOLβ€”BNBβ€”XRPβ€”ADAβ€”AVAXβ€”DOGEβ€”LINKβ€”DOTβ€”MATICβ€”ATOMβ€”LTCβ€”TRXβ€”TONβ€”
β€”β–²0.0%
DeFi

A Malicious Proposal Drains About $20M From BonkDAO's Treasury

6 Jul 2026by CryptoJazz Admin1 min read115 views
A Malicious Proposal Drains About $20M From BonkDAO's Treasury

An attacker drained roughly $20 million from BonkDAO's treasury on July 6 without breaking a line of code. The theft ran through the ballot box. Over the preceding week the attacker built up 1.01% of the supply of BONK, the Solana-based token behind the project, just past the threshold needed to carry a vote, then filed a governance proposal that moved treasury holdings to a wallet under their control. Seven wallets voted yes. More than 18,000 abstained, turnout came to 2.9%, and the proposal executed automatically on-chain the moment it passed. How hard BONK fell depends on the source: about 7% in the following 24 hours by one count, while some outlets logged the drop at 8% to 10%, and the tallies do not reconcile. BonkDAO said it had identified the exchange wallets used to buy tokens ahead of the vote and was coordinating with exchanges, bridges and the Solana Foundation.

A treasury that belongs to the token holders

A DAO treasury is the pool of assets a decentralized autonomous organization holds in common: tokens, stablecoins and protocol revenue that belong to the organization itself, not to any individual, and that no single person is supposed to be able to sign away. Direction over that money sits with the token holders, who exercise it by voting. An on-chain governance proposal is the instrument they vote on. It is a transaction written out in advance, held pending while the vote runs and, if it passes, executed by the governance contract itself with no human step between the result and the transfer. The design is deliberate, since it removes the possibility that whoever administers the treasury simply ignores an outcome they dislike. It also means a proposal that passes for the wrong reasons settles exactly as fast as one that passes for the right ones.

1.01% of supply against 2.9% turnout

Quorum is the minimum weight of votes a proposal must attract before it can pass at all, and it is normally set as a share of token supply on the assumption that ordinary participation will provide most of it. In practice most holders never vote. At 2.9% turnout the quorum bar and the winning margin become the same number, because there is almost no opposing weight on the other side of the ledger: whoever can buy past the threshold has bought the result outright. CoinDesk put the attacker's outlay at roughly $4.4 million, in tokens bought on Bybit and Binance and topped up with amounts borrowed through DeFi lending platforms. Against a treasury worth about $20 million, the vote was cheaper than the thing it moved.

$188,000 out, about $19 million behind a multisig

Containment was partial. The proceeds landed in a multisig wallet, one that requires several separate approvals before funds can move again. At the time of reporting, about $188,000 had reached an exchange while roughly $19 million was still sitting behind those approvals. That leaves the recovery question with exchanges and bridges instead of with any contract fix, since there is no exploited function to patch and no transaction the protocol can call invalid. It is the same shape as the year's other large losses that came from how control over funds was held, not from a flaw in the code. The chain did what it was instructed to do. The instruction was valid.

A quorum priced below the treasury

Nothing about the mechanism has been fixed by the incident being over. A quorum threshold that costs less to buy than the treasury is worth remains an open invitation wherever turnout stays in the low single digits, and turnout is not something a protocol can legislate. The available defenses are structural rather than technical: execution delays that leave time to react between a vote passing and funds moving, spending caps that keep a single proposal from reaching the whole balance, or a guardian able to veto. Each trades away some of the automation that made on-chain governance attractive in the first place. What happened to BonkDAO was a permission granted in good faith and later used against the people who granted it. The open questions now are whether the $19 million still behind the multisig can be frozen, and whether the exchange accounts BonkDAO identified lead anywhere.

Read also: Ostium Loses $23.75M After Its Price Feed Key Is Compromised

← All news