BonkDAO, a meme project within the Solana ecosystem, has suffered a governance attack that led to the transfer of roughly $20 million worth of BONK from its treasury. In a statement posted on X early on July 7 Beijing time, BONK said a malicious governance proposal had been approved, resulting in the loss of treasury assets. The team added that it had identified exchange wallets that accumulated BONK before the proposal and was coordinating with exchanges, cross-chain bridge operators, and the Solana Foundation.

A treasury transfer executed under the cover of governance
The proposal tied to the incident was submitted on Realms on June 30 under the title BIP #76 - Sowellian BonkDAO. On the surface, it proposed a so-called “Sowellian” governance restructuring that would replace members and committees, rebuild the DAO, liquidate or manage holdings, stop losses, and distribute tokens to those who voted in favor. In practice, the proposal enabled a transfer of a major portion of the BonkDAO treasury to an address controlled by the proposer.
According to the source material, the proposal covered more than 4.4 trillion BONK, valued at around $20 million at the time. The naming drew additional attention because “Sowellian” is also the name of a governance prediction market mechanism associated with Realms, the Solana governance platform that hosted the vote. That mechanism was originally meant to align incentives and improve decision-making through economic game theory, but in this case the attacker appears to have used that same governance framing to legitimize the treasury transfer.
The attack relied on capital and low voter participation, not code exploitation
After submitting the proposal, the attacker did not exploit a smart-contract vulnerability or compromise infrastructure. Instead, the strategy was straightforward: acquire enough BONK to meet the minimum voting requirement, then use that stake in a lightly attended governance process. According to on-chain observations cited in the report, the attacker withdrew about 88.2285 billion BONK from Binance and Bybit over several days, with an estimated market value of $4.4 million.
That amount was enough to satisfy the governance threshold, described as the minimum 1% token requirement. The attacker then cast a vote in favor of the proposal on Realms. Because BonkDAO governance participation was unusually low, only seven addresses voted in total. The attacker-controlled address accounted for 99.878% of the voting weight, effectively giving it overwhelming control over the outcome.
Under the timeline presented in the article, the result was finalized on July 6 and the proposal passed. Once approved, the governance system executed according to preset rules and transferred approximately 4.4 trillion BONK from the treasury to the attacker’s address. In other words, the treasury drain did not occur through an external hack but through the DAO’s own authorized governance process.

Missing safeguards turned a malicious proposal into an immediate payout
The case has drawn attention to the absence of standard defensive layers often seen in more mature DAO governance systems. Treasury-related proposals that affect core reserves are usually subject to higher quorum thresholds, stricter approval standards, or additional procedural review, making it harder for a small number of addresses to take over governance in a low-participation environment.
Another common safeguard is a timelock. In many DAO frameworks, even after a proposal passes, execution is delayed by several days. That window gives the community, core contributors, or multisig signers time to review the result, identify malicious intent, and, where applicable, exercise a veto or emergency intervention. Some systems also include delayed-voting or anti-last-minute-manipulation protections to reduce the chance that large token positions can swing a vote just before the deadline.
BonkDAO appears to have lacked enough of these protections. As a result, the malicious proposal was able to move from passage to execution without an effective pause, and the funds were reportedly moved quickly after the transfer. The event is therefore better understood as a governance manipulation incident driven by economic control and weak process design, rather than a traditional exploit of faulty code.
The broader implication for Web3 is clear: the most severe DAO risks do not always come from smart-contract bugs. Governance parameters, participation patterns, execution timing, and emergency controls can be just as critical. In BonkDAO’s case, roughly $4.4 million worth of BONK voting power was enough to extract about $20 million from a treasury because the system lacked robust quorum rules, timelocks, and multisig oversight.

