BonkDAO Governance Attack Lets $4.4 Million in BONK Seize Nearly $20 Million Treasury

BonkDAO Governance Attack Lets $4.4 Million in BONK Seize Nearly $20 Million Treasury

N
News Editor
2026-07-07 05:14:58
BonkDAO, a meme project in the Solana ecosystem, suffered a governance attack that resulted in roughly $20 million worth of BONK being transferred out of its treasury through an approved proposal rather than a smart-contract exploit. According to BONK’s official disclosure on X on July 7, the malicious proposal was passed on Realms, the governance platform used by the DAO. The attacker reportedly accumulated about 88.2285 billion BONK, worth around $4.4 million, from Binance and Bybit to meet the voting threshold, then used that position to secure 99.878% of the voting weight in a low-turnout vote involving only seven addresses. Once the proposal passed, approximately 4.4 trillion BONK, valued at around $20 million, was automatically transferred by the governance system. The incident highlights structural weaknesses in DAO governance, including insufficient quorum requirements, the lack of a timelock, no effective multisig veto layer, and limited protection against vote manipulation near the end of the voting window.
BonkDAOBONKSolanaDAO GovernanceGovernance AttackRealmsOn-chain Security

BonkDAO, a meme project within the Solana ecosystem, has suffered a governance attack that led to the transfer of roughly $20 million worth of BONK from its treasury. In a statement posted on X early on July 7 Beijing time, BONK said a malicious governance proposal had been approved, resulting in the loss of treasury assets. The team added that it had identified exchange wallets that accumulated BONK before the proposal and was coordinating with exchanges, cross-chain bridge operators, and the Solana Foundation.

BonkDAO Governance Attack Lets $4.4 Million in BONK Seize Nearly $20 Million Treasury 2

A treasury transfer executed under the cover of governance

The proposal tied to the incident was submitted on Realms on June 30 under the title BIP #76 - Sowellian BonkDAO. On the surface, it proposed a so-called “Sowellian” governance restructuring that would replace members and committees, rebuild the DAO, liquidate or manage holdings, stop losses, and distribute tokens to those who voted in favor. In practice, the proposal enabled a transfer of a major portion of the BonkDAO treasury to an address controlled by the proposer.

According to the source material, the proposal covered more than 4.4 trillion BONK, valued at around $20 million at the time. The naming drew additional attention because “Sowellian” is also the name of a governance prediction market mechanism associated with Realms, the Solana governance platform that hosted the vote. That mechanism was originally meant to align incentives and improve decision-making through economic game theory, but in this case the attacker appears to have used that same governance framing to legitimize the treasury transfer.

The attack relied on capital and low voter participation, not code exploitation

After submitting the proposal, the attacker did not exploit a smart-contract vulnerability or compromise infrastructure. Instead, the strategy was straightforward: acquire enough BONK to meet the minimum voting requirement, then use that stake in a lightly attended governance process. According to on-chain observations cited in the report, the attacker withdrew about 88.2285 billion BONK from Binance and Bybit over several days, with an estimated market value of $4.4 million.

That amount was enough to satisfy the governance threshold, described as the minimum 1% token requirement. The attacker then cast a vote in favor of the proposal on Realms. Because BonkDAO governance participation was unusually low, only seven addresses voted in total. The attacker-controlled address accounted for 99.878% of the voting weight, effectively giving it overwhelming control over the outcome.

Under the timeline presented in the article, the result was finalized on July 6 and the proposal passed. Once approved, the governance system executed according to preset rules and transferred approximately 4.4 trillion BONK from the treasury to the attacker’s address. In other words, the treasury drain did not occur through an external hack but through the DAO’s own authorized governance process.

BonkDAO Governance Attack Lets $4.4 Million in BONK Seize Nearly $20 Million Treasury 3

Missing safeguards turned a malicious proposal into an immediate payout

The case has drawn attention to the absence of standard defensive layers often seen in more mature DAO governance systems. Treasury-related proposals that affect core reserves are usually subject to higher quorum thresholds, stricter approval standards, or additional procedural review, making it harder for a small number of addresses to take over governance in a low-participation environment.

Another common safeguard is a timelock. In many DAO frameworks, even after a proposal passes, execution is delayed by several days. That window gives the community, core contributors, or multisig signers time to review the result, identify malicious intent, and, where applicable, exercise a veto or emergency intervention. Some systems also include delayed-voting or anti-last-minute-manipulation protections to reduce the chance that large token positions can swing a vote just before the deadline.

BonkDAO appears to have lacked enough of these protections. As a result, the malicious proposal was able to move from passage to execution without an effective pause, and the funds were reportedly moved quickly after the transfer. The event is therefore better understood as a governance manipulation incident driven by economic control and weak process design, rather than a traditional exploit of faulty code.

The broader implication for Web3 is clear: the most severe DAO risks do not always come from smart-contract bugs. Governance parameters, participation patterns, execution timing, and emergency controls can be just as critical. In BonkDAO’s case, roughly $4.4 million worth of BONK voting power was enough to extract about $20 million from a treasury because the system lacked robust quorum rules, timelocks, and multisig oversight.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.