How a $4.4 Million Vote Hijack Drained $20 Million From BONK's Treasury
A BONK attacker exploited minimal voting participation to pass a malicious governance proposal that transferred approximately $20 million in treasury assets to their wallet, then cashed out roughly $13.58 million across multiple exchanges. The entire operation complied with BonkDAO's on-chain governance rules, making recovery extraordinarily difficult and raising urgent questions about how decentralized autonomous organizations (DAOs) protect their treasuries when voting participation is extremely low.
What Happened in the BONK Governance Attack?
On June 30, an attacker submitted proposal BIP #76 through Realms, a governance platform in the Solana ecosystem, superficially packaged as a governance optimization plan. The proposal's actual purpose was far more sinister: directly transfer approximately 4.426 trillion BONK tokens from the BonkDAO treasury to an address controlled by the attacker. At the time, the circulating supply of BONK was about 88 trillion tokens, meaning the attacker targeted roughly 5% of all BONK in existence.
To pass the proposal, the attacker needed to meet a 1% voting threshold, which required approximately 880 billion BONK tokens. Between July 4 and 5, the attacker accumulated exactly 882.285 billion BONK through purchases on exchanges including Binance and Bybit, supplemented by some DeFi borrowing (decentralized finance borrowing, which allows users to take loans using cryptocurrency as collateral). The total cost was approximately $4.4 million, just enough to meet the quorum requirement.
On July 6, the proposal entered voting. Only 7 addresses participated throughout the entire voting process, with addresses controlled by the attacker contributing 99.878% of the yes votes. After the vote passed, the smart contract immediately and automatically executed the transfer, moving about 4.426 trillion BONK (worth approximately $20 million at the time) from the treasury to the attacker's wallet. No timelock was triggered, nor were there any additional multi-signature or manual review steps during the entire process.
How Did the Attacker Cash Out and Evade Detection?
Once in possession of the funds, the attacker acted with remarkable speed and sophistication. Within about 9 hours of the transfer, roughly $190,000 worth of BONK was sent to OKX, a major cryptocurrency exchange. The remaining approximately $19 million was transferred to a newly created multi-signature wallet, which blockchain analysis firm Chainalysis described as a "BONK 2.0" shadow DAO, jointly controlled by the malicious voting wallet, a fund-receiving wallet, and a third-party address with funding ties to the voting address.
Meanwhile, the attacker began liquidating the BONK tokens used to gain voting power. About one hour after the vote ended, the related addresses began selling roughly $5.3 million worth of holdings. In the following weeks, on-chain monitoring showed the attacker continuing to move funds to platforms like Coinbase. On July 17, the attacker transferred 1.186 trillion BONK (worth about $4.11 million) into Binance. On July 19, according to on-chain analyst Ember, the attacker transferred another 400 billion BONK, valued at about $1.11 million, to Coinbase. By July 20, the attacker had completed their sell-off, depositing their last 400 billion BONK ($1.17 million) into Coinbase 30 minutes earlier.
Data statistics show that the attacker cashed out a cumulative total of approximately $13.58 million. During this period, the BONK price fell from $0.0000047 to $0.0000027, a cumulative drop of about 41%, as the attacker's massive sales flooded the market.
Why Is Recovery So Difficult?
The core challenge in recovering stolen funds from this attack lies in a fundamental legal and technical reality: the entire process was compliant with BonkDAO's governance rules. There was no private key compromise, no smart contract vulnerability, and no unauthorized function call. The attacker bought voting power, submitted a proposal, got it passed by a vote, and the smart contract automatically executed the transfer exactly as programmed.
Most jurisdictions remain conservative toward pure governance attacks. Courts are more inclined to treat "code is law plus vote passed" as a valid internal decision rather than traditional theft, significantly weakening the grounds for criminal investigation and civil asset freezes. Additionally, on-chain data shows the attacker has already completed the dumping and transfer of some assets, further reducing the size of freezable assets. The attacker's identity remains undisclosed, and the high cost and long duration of cross-border enforcement make the probability of recovering most losses extremely low.
How to Strengthen DAO Governance Against Similar Attacks?
- Implement Meaningful Quorum Requirements: Set voting thresholds high enough that a single attacker cannot accumulate the necessary voting power with a modest capital investment. When the quorum is set very low and long-term voting participation is extremely minimal, the treasury becomes exposed to the open market.
- Add Timelock Delays: Introduce a mandatory waiting period between proposal passage and execution, allowing the community time to detect and respond to malicious proposals before funds are transferred.
- Require Multi-Signature Approval: Establish additional manual review steps or multi-signature wallet controls for large treasury transfers, ensuring that no single governance vote can immediately drain significant assets without human oversight.
- Monitor Voting Participation Trends: Track whether voting participation is declining over time, as extremely low participation (only 2.9% of members participated in the BONK vote) is a red flag that governance has become vulnerable to attack.
What Happened After the Attack Was Discovered?
BonkDAO officials quickly spoke out after the incident, confirming that "BonkDAO suffered a malicious governance proposal, resulting in approximately $20 million in BONK being transferred from the treasury." The team stated they had identified the attacker's exchange wallet addresses used for early accumulation and had notified law enforcement. They also maintained communication with exchanges, cross-chain bridges, and the Solana Foundation in an attempt to recover the funds and hold the responsible party accountable.
On July 13, BonkDAO issued a follow-up update: the related wallets had been flagged and were under continuous monitoring, and the team was exploring all possible recovery avenues. They emphasized that the BONK token itself and users' personal assets were unaffected and that the token contract was secure. A formal post-mortem analysis report was planned for later release, and the project team called on the community to focus on improving governance mechanisms.
On July 23, the officials further stated that recovery efforts were still ongoing. However, as of the time of reporting, there has been no official public notification of large sums being successfully returned to the treasury, nor any formal confirmation of substantial funds being successfully frozen or recovered.
Why Did Upbit Delist BONK?
On August 7, South Korea's largest cryptocurrency exchange Upbit officially announced that it will terminate trading support for BONK at 15:00 (KST) on September 7, affecting the BONK/KRW and BONK/USDT trading pairs. Withdrawal services will be maintained until October 7. Upbit stated that after evaluating BONK, it found that the distributed ledger used by the operator for issuing, transmitting, and storing virtual assets had experienced security incidents such as hacking attacks whose causes were unknown or unresolved, and that the issuer or operator had failed to promptly disclose important matters regarding the virtual asset through appropriate electronic transmission media.
After the announcement, the price of BONK fell from $0.0000028 to $0.0000025, a drop of about 10%, and its current market cap is $222.26 million. Upbit delisted BONK for compliance risk aversion and mandatory legal review. After South Korea implemented the Virtual Asset User Protection Act in July 2024, DAXA (Digital Asset Exchange Alliance) has strict statutory obligations for projects involving major governance vulnerabilities and security risks. Currently, other exchanges have yet to take action for the time being.
The BONK governance attack represents a watershed moment for the DAO ecosystem. It demonstrates that when voting participation is extremely low and the quorum is set very low, it is equivalent to exposing treasury control to the open market. Whoever can centrally buy the minimum voting threshold can effectively steal from the DAO, provided they do so through the governance mechanism itself. For any DAO holding a large treasury, this attack pattern poses an existential threat that cannot be solved by audits or code reviews alone.