BonkDAO, the governance organization tied to Solana meme coin BONK, said on July 6 that it had suffered a governance attack that drained roughly 4.4 trillion BONK from its treasury. The incident did not involve a smart contract exploit. Instead, the attacker used a proposal that passed through the DAO’s own voting process and triggered an on-chain transfer that was technically valid at every step.

Based on varying price references and timestamps, the value of the transferred tokens was estimated at roughly $19.3 million to $21.2 million, with most reports rounding the figure to about $20 million. Soon after the treasury drain, the stolen BONK began moving toward exchanges, adding selling pressure to the market. BONK fell around 7% to 10% over 24 hours, sliding to about $0.0000043, or roughly 93% below its all-time high of $0.000058.
BonkDAO described the event as a malicious governance proposal and said it had contacted law enforcement. The organization added that it was working with exchanges, bridge providers, and the Solana Foundation to trace funds and determine liability. The episode has quickly become one of the most high-profile examples of a DAO being emptied not by broken code, but by governance rules that could be manipulated through token accumulation.

Proposal #76 packaged a treasury transfer as a reform motion
The attack centered on a governance motion titled “BIP #76 - Sowellian BonkDAO”. On the surface, the proposal read like a sweeping reform manifesto. It discussed ideas such as introducing a “Sowellian” model of governance, replacing committee members and directors, restructuring the organization, monetizing holdings, and stopping losses. It also claimed that anyone voting in favor would be eligible for BONK token rewards.
However, the proposal’s actual executable effect was far narrower and far more dangerous. Embedded in its action steps was an instruction to transfer about 4.43 trillion BONK directly to the attacker’s wallet. According to BonkDAO, this transfer was tucked into the second execution step rather than placed where reviewers would immediately notice it. Once the proposal cleared the voting threshold, the transfer could be executed automatically on-chain without another round of human approval.
BonkDAO said the funds moved at around 4 a.m. Eastern Time on July 6 into an attacker-controlled wallet ending in “JHvQ.” The promised BONK rewards for supportive voters were never distributed. In practical terms, the governance proposal was not a real reform package at all. It was a treasury-draining instruction wrapped in political language designed to lower scrutiny.

The attacker spent about a week accumulating voting power
On-chain analysis from Chainalysis and Lookonchain suggested the exploit was premeditated and unfolded over roughly a week. An anonymous wallet first submitted the proposal on June 30. Under BonkDAO’s rules, passage required affirmative votes equal to at least 1% of the token supply, or around 879.95 billion BONK.
Between July 4 and July 5, another wallet acquired about 882.38 billion BONK through Bybit and Binance, spending roughly $4.4 million to build just enough voting power to exceed the threshold. Lookonchain also said the attacker may have borrowed additional BONK through DeFi lending venues to reinforce the position. Because the purchases were routed through exchange-linked wallets and accumulated over time, the broader community appears to have missed the buildup.
The final vote passed by an extremely narrow margin. Approval totaled 882.38 billion BONK against a threshold of 879.95 billion BONK, almost exactly matching the position accumulated in the days before the vote. The voting structure itself raised additional alarms: only seven wallets participated, more than 18,000 members did not vote, turnout was only about 2.9%, and the “yes” side accounted for 99.9% of participating votes. That made the result look less like broad community consensus and more like concentrated control over a lightly attended governance process.

Stolen treasury BONK was mostly retained while the vote-buying stash was dumped
After the treasury was drained, the attacker handled two BONK pools in very different ways. For the roughly $20 million taken from the treasury, Chainalysis said that only about $188,000 was sent to exchanges within about nine hours, potentially for liquidation. The remaining roughly $19 million was moved into a multisig wallet requiring multiple approvals. During that period, some of the funds also briefly passed through another address ending in “eh42.”
The BONK acquired to secure the vote was treated much more aggressively. About one hour after the treasury transfer, the attacker began selling that position and offloaded roughly $5.3 million worth of BONK. In other words, the attacker held on to most of the stolen treasury assets while quickly unwinding the inventory used to gain voting power in the first place.
That distinction matters for market impact. It suggests the attacker may have wanted to reduce exposure from the purchased tokens immediately while keeping the larger treasury haul parked for later use, negotiation, or staged liquidation. It also helps explain why BONK faced visible sell pressure without seeing the entire stolen treasury amount immediately dumped on the open market.

Exchanges moved to contain risk as BonkDAO sought recovery
In response to the incident, Upbit and Kraken suspended BONK deposits and withdrawals under their security procedures. BonkDAO said it had identified exchange wallets used by the attacker to accumulate BONK before the vote and had already notified relevant parties. The DAO added that it was coordinating with exchanges, cross-chain infrastructure providers, and the Solana Foundation in an effort to trace and potentially recover assets.
While the outcome of those recovery efforts remains uncertain, the response shows how governance attacks can quickly move beyond a DAO’s internal process and spill into centralized venues and broader ecosystem infrastructure. Once governance-controlled treasury assets are routed to exchanges or bridged elsewhere, the issue becomes part on-chain enforcement problem and part off-chain compliance and law-enforcement matter.
The case revives debate over what counts as an “attack” in DAO governance
The BonkDAO incident has also reignited a familiar argument in crypto governance. Because every step of the sequence—buying tokens, voting on a proposal, and executing the transfer—was technically valid on-chain, some observers argue the attacker simply exploited weak governance design rather than breaking in through an unauthorized code path. BonkDAO and multiple analytics firms, however, have clearly labeled the event an attack, and the involvement of law enforcement reflects that framing.

More broadly, the incident highlights structural weaknesses in token-governed treasuries. Proposal text can be padded with rhetorical language while harmful executable actions remain obscured. Voting thresholds can be met through short-term token accumulation. If there is no substantive review of proposal payloads, no meaningful delay before treasury disbursement, and no manual oversight for large transfers, then governance itself becomes an attack surface.
For DAOs managing large pools of capital, the lesson from BonkDAO is not about a software bug. It is about process design. Treasury proposals may need clearer payload disclosure, stricter review standards, higher participation or quorum requirements, time locks before execution, and human checks for extraordinary transfers. Without those controls, a system built to decentralize authority can be turned into a mechanism for extracting funds with formal approval.

