BONK DAO confirmed a large-scale attack on its decentralized governance infrastructure. As a result of a malicious proposal, approximately $20 million in BONK tokens were drained from the treasury. The attacker has already begun moving the stolen assets to cryptocurrency exchanges, and the memecoin's price has plummeted by more than 10%.
This incident is yet another reminder that even established DAOs are not immune to governance-level attacks. Unlike smart contract exploits, this attack used a legitimate voting procedure, making defense against such threats particularly challenging.
Attack Mechanics: How It Happened
According to blockchain analysts, the attacker preemptively purchased approximately $4 million worth of BONK tokens. This allowed them to accumulate enough voting power to pass their proposal through the Solana-based Realms platform. After the DAO approved the proposal, the governance mechanism enabled the transfer of about $20 million from the treasury to wallets controlled by the attacker.
A key feature of this attack is the absence of code vulnerability exploitation. Instead, social engineering and manipulation of the voting mechanism were used, representing a far more sophisticated method. The attacker essentially bought the right to control the treasury.
Team Response and Market Consequences
The BONK team has already identified the exchange wallet addresses used to concentrate the voting stake before the proposal was submitted. The project is currently actively cooperating with cryptocurrency exchanges, the Solana Foundation, cross-chain bridge operators, and law enforcement agencies to track and potentially recover the stolen funds.
Part of the stolen BONK has already begun moving to exchanges, indicating the attacker's attempts to convert the assets. The market reaction was immediate: the BONK token lost over 10% of its value amid panic and uncertainty among holders.
What's Next: Lessons for the Entire DAO Sector
This incident once again raises fundamental questions about DAO governance security. It is clear that a simple "one token, one vote" system without additional protective mechanisms is extremely vulnerable. Tools such as timelocks, multi-signatures, and delays on treasury execution decisions should become the de facto standard for all serious projects.
Investors are now awaiting news on fund recovery and potential changes to the BONK governance protocol. The success or failure of this asset recovery mission will set an important precedent for the entire DeFi space. From my perspective, this case should serve as a catalyst for reviewing the security architecture of many DAOs that rely solely on voting without multi-layered treasury protection. The market will now evaluate project resilience not only based on their technology but also on the maturity of their governance systems.