The Solana ecosystem has faced another serious incident in decentralized governance. The decentralized autonomous organization (DAO) BonkDAO, which manages the treasury of the popular memecoin BONK, reported the theft of approximately $20 million. The attacker exploited a vulnerability in the governance system by passing a malicious proposal that allowed tokens to be withdrawn from the treasury.
Technical Details of the Attack
According to a statement from the BonkDAO team, the incident occurred on July 6. An unknown participant, controlling a significant number of votes, initiated and passed a proposal on the Solana Realms governance platform that was essentially fraudulent. Under the guise of "implementing Sowellian governance" and changing the council composition, the attacker transferred funds to their wallet. Notably, the text of the malicious proposal promised BONK rewards to those who voted "yes," but the tokens were not distributed—all funds went to a single address, which was later linked to a deposit via the Bybit exchange.
Following the incident, major exchanges, including Kraken and Upbit, temporarily suspended operations with BONK. This is a standard security measure aimed at preventing further fund outflows and protecting users. Currently, the BonkDAO team is actively cooperating with exchanges, bridge protocols, and the Solana Foundation to recover the assets.
Market Reaction and Context
The news of the treasury hack immediately impacted the price of BONK. Over the past 24 hours, the memecoin's quotes have dropped by 7.7%, and at the time of writing this analysis, the asset is trading around $0.00000432. This decline occurs against the backdrop of a general decrease in interest in memecoins within the Solana ecosystem. In June 2026, activity on Pump.fun, a key "memecoin factory," decreased by 30% compared to spring figures.
Expert Opinion
This incident is a stark example of how vote centralization in decentralized governance systems can lead to catastrophic consequences. Despite the loud name "DAO," real power is often concentrated in the hands of a few large token holders. The attack on BonkDAO should serve as a wake-up call for all projects using token-based voting mechanisms. Without implementing more sophisticated protection mechanisms, such as time delays on fund withdrawals or multi-level transaction approval, such vulnerabilities will be exploited again. The most important thing now is how quickly and effectively BonkDAO can restore community trust and recover part of the stolen funds.