The BONK memecoin ecosystem has faced a serious security incident. The decentralized autonomous organization BonkDAO reported an unauthorized withdrawal of tokens worth approximately $20 million after a malicious proposal was adopted in the governance system. This event immediately triggered a reaction from major exchanges: Kraken and Upbit temporarily suspended BONK deposit and withdrawal operations.

According to my data, the attacker exploited a vulnerability in the DAO voting mechanism. Technical details of the attack have not yet been disclosed, but it is evident that a holder of a large volume of tokens was able to manipulate the governance process to transfer funds from the treasury to their wallets. During the investigation, BonkDAO has already identified exchange wallets used to purchase BONK before submitting the malicious proposal. The team is actively interacting with exchanges, bridge protocols, and the Solana Foundation to minimize damage.

Technical Aspects of the Attack

The incident occurred on July 6, and the voting took place via the Solana Realms platform, a standard tool for DAO governance in the Solana ecosystem. The malicious proposal was identified as Bonk Improvement Proposal #76. Its description featured vague wording about "implementing Sowellian governance" and appointing new council members, which likely misled some voters. The funds were not distributed among voting participants as promised in the proposal text. Instead, the tokens were first sent to an address associated with Bybit and then transferred to another wallet.

Market Consequences

The market reaction was immediate. BONK quotes lost 7.7% over the past 24 hours, dropping to around $0.00000432. Exchanges Upbit and Kraken temporarily blocked deposits and withdrawals of the asset to prevent further manipulation. This is standard practice in such situations, but it creates additional pressure on liquidity.

It is worth noting that in December 2023, BONK's market capitalization exceeded $1.7 billion, and the memecoin was actively integrated into the Solana ecosystem. However, the current incident highlights fundamental risks associated with DAO governance. Even with apparent decentralization, the concentration of tokens in the hands of a few large holders makes such systems vulnerable to attacks through voting.

My expert assessment: this case is a serious blow to the reputation of BonkDAO and the Solana ecosystem as a whole. It demonstrates that even mature projects are not immune to attacks at the governance level. In the long term, this could push the industry to develop more reliable voting mechanisms, including multi-factor authentication and time delays for large transactions. Investors should reconsider their risks when storing funds in DAOs with a low degree of decentralization.