BonkDAO loses $20 million following ‘malicious governance proposal’ attack
The funds have been tracked to crypto exchanges, and South Korea-based Upbit said it has suspended BONK deposits and withdrawals.
BonkDAO, the decentralized autonomous organization behind the popular Solana-based memecoin BONK, has suffered a significant security breach resulting in losses of approximately $20 million. The attack was executed through what officials have described as a "malicious governance proposal," a method that exploited the protocol's on-chain voting mechanism to drain funds from the treasury.
BonkDAO operates as the governing body for the BONK token ecosystem, relying on community-driven proposals to manage protocol decisions and treasury allocations. Governance-based attacks of this nature involve bad actors crafting or manipulating proposals that, once passed, authorize unauthorized transfers of funds. The incident highlights an increasingly recognized vulnerability in DAO structures where governance mechanisms themselves can become attack vectors.
Following the breach, on-chain analysts tracked the stolen funds to several cryptocurrency exchanges. South Korea-based Upbit, one of the region's largest trading platforms, confirmed it has suspended BONK deposits and withdrawals as a precautionary measure, signaling that exchanges are actively cooperating in efforts to contain the fallout. The incident raises broader questions about the security frameworks governing decentralized organizations, particularly those managing substantial treasuries.
Observers will be watching closely for any official response from BonkDAO regarding potential fund recovery, legal action, or proposed changes to its governance structure. The community's handling of this breach may set a precedent for how DAOs respond to protocol-level exploits going forward.
Source: The Block