A massive attack on the decentralized organization BONK has shaken the crypto community. The attacker exploited a vulnerability in the DAO's governance mechanism to withdraw tokens worth $21.2 million from the project's treasury. At the same time, their own costs for executing the scheme amounted to only $4.4 million, resulting in a net profit of $16.8 million.

How the Attack Was Carried Out

On June 30, the hacker submitted a proposal to the DAO to transfer 4.426 trillion BONK tokens (equivalent to $21.2 million) to a wallet under their control. However, the key element of the attack was the preparation: two days prior, the attacker purchased 882 billion BONK on the Bybit and Binance exchanges, spending $4.4 million.

This volume of tokens was sufficient to exceed the quorum required for proposal approval — 879 billion BONK. By voting "yes" with their entire stake, the hacker ensured the initiative passed, after which the funds were automatically transferred to their wallet.

Current Status of the Stolen Assets

As of now, part of the stolen funds has already been moved. According to analytics data, 40 billion BONK ($188,000) were sent to the OKX exchange. The remaining 4.386 trillion BONK ($19.3 million) still remain in the wallet EXaJnm…eh42. The hacker appears to be in no hurry to withdraw the bulk of the funds, which may indicate waiting for more favorable market conditions or an attempt to avoid tracking.

The Root of the Problem — in Governance, Not Code

Members of the crypto community rightly note that in this case, the vulnerability lies not in BONK's smart contracts, but in the very architecture of the DAO's governance. A system where votes are tied to the number of tokens allows a large holder — or someone who can temporarily concentrate a significant amount of coins — to effectively make decisions unilaterally. This is a classic example of a governance attack, highlighting the fundamental weakness of many modern DAOs.

Expert Opinion: The BONK incident is yet another reminder that decentralized governance does not guarantee security. As long as DAOs use simple "one token, one vote" voting mechanisms, they will remain vulnerable to such manipulations. Projects need to implement more complex systems, such as delegated voting, time locks, or quadratic voting, to prevent the concentration of power in a single set of hands. The market must learn from this attack, which cost the BONK treasury $16.8 million.