The Solana ecosystem and the meme coin BONK have faced a serious security incident. The decentralized autonomous organization (DAO) BonkDAO confirmed the withdrawal of tokens worth approximately $20 million from the treasury. The cause was the adoption of a malicious proposal in the governance system. Amid this event, cryptocurrency exchanges Kraken and Upbit promptly suspended deposit and withdrawal operations for the asset.
According to my data, the attacker, exploiting vulnerabilities in the voting mechanism, managed to push through a malicious proposal and gain control over the funds. Technical details of the attack, including voting parameters, have not yet been disclosed, raising questions about the transparency of governance in the project. The attack itself is classified as a "voting takeover" — when holders of a large volume of tokens use their weight to transfer funds to their own benefit.
Incident Details and Consequences
The event occurred on July 6. The voting took place via the Solana Realms platform, designed for managing DAOs in the Solana ecosystem. The withdrawal of funds was linked to proposal number 76 (Bonk Improvement Proposal #76), which, under the guise of "implementing Sowellian governance" and appointing new council members, effectively legitimized the theft. The funds were not distributed among voting participants but were sent to an address associated with the Bybit exchange, and then transferred to another wallet.
The market reaction was immediate. BONK quotes collapsed by 7.7% over the past 24 hours, dropping to around $0.00000432. This demonstrates how sensitive meme tokens are to such incidents, especially when the project's governance infrastructure itself comes under attack.
BonkDAO is actively cooperating with exchanges, bridges, and the Solana Foundation to resolve the situation. However, given that in December 2023, BONK's market capitalization exceeded $1.7 billion, and interest in the project was fueled by airdrops and integration into the Solana ecosystem, this incident deals a serious blow to community trust.
My analysis: This case is yet another reminder that decentralized governance is not a panacea. Vulnerabilities in voting systems can be exploited for attacks, especially if the DAO lacks mechanisms to protect against "power takeovers" of votes. For projects, particularly in the meme token space, where the community often prioritizes speed over security, this is a critical signal. Multi-layered proposal verification systems and time delays for audits need to be implemented to prevent such incidents in the future.