On-chain security researcher Specter said an initial review of the BONK DAO governance attack found notable on-chain links involving addresses tied to the suspected attacker. According to Specter, both the founder of Realms and Crypto Notte were found to have on-chain fund exposure to addresses associated with the suspected attacker.
Specter said the attacker created a malicious governance proposal on June 30, 2026 through a certain address. The proposal required support representing 1% of BONK’s circulating supply in voting power in order to pass.
He added that the attacker later obtained the needed voting power between July 4 and July 5 through exchange purchases and borrowing on marginfi. The borrowing portion was about $4 million. The statement was reported by ChainCatcher.
Initial probe points to on-chain links
ChainCatcher reported that on-chain security watcher Specter said an initial investigation into the BONK DAO governance attack found notable on-chain connections. According to Specter, both the founder of Realms and Crypto Notte had on-chain fund exposure to addresses linked to the suspected attacker.
How the voting power was assembled
Specter said the attacker used a certain address to create a malicious governance proposal on June 30, 2026. The proposal required voting support equal to 1% of BONK’s circulating supply to pass.
He said the attacker then acquired the required voting power between July 4 and July 5 through purchases on exchanges and borrowing on marginfi. The borrowing size was about $4 million.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.