On June 30, 2025, an attacker successfully breached the treasury of the BONK protocol, exploiting a vulnerability in the decentralized autonomous organization (DAO) governance system. The scheme turned out to be surprisingly simple and effective: the hacker spent $4.4 million to acquire tokens, then gained control over the vote and withdrew assets worth $21.2 million. The net profit from the operation amounted to $16.8 million.
The attack was made possible due to a fundamental feature of many DAOs: voting power is directly tied to the number of tokens in a wallet. To pass a decision, only a certain quorum is needed. The attacker took advantage of this by pre-purchasing 882 billion BONK on the Bybit and Binance exchanges. This volume was enough to exceed the required quorum of 879 billion BONK.
After submitting a proposal to transfer 4.426 trillion BONK ($21.2 million) to a controlled wallet (9bxW…JHvQ), the hacker voted "yes" with their entire 882 billion BONK. The proposal passed, and the funds were automatically transferred.
Distribution of Stolen Funds
At the time of publication, some of the assets had already changed addresses. Data on the distribution of stolen tokens:
| Amount in Tokens | Amount in $ | Status / Location |
| 40 billion BONK | $188 thousand | Transferred to OKX exchange |
| 4.386 trillion BONK | $19.3 million | Remaining on wallet EXaJnm…eh42 |
It appears the hacker is not in a hurry to withdraw the remaining funds. Analysts continue to monitor the specified address. Members of the crypto community noted that this time the root of the problem lay in the project's governance system, while the code itself remained secure.
Expert Commentary from Cryptalist: This incident is not just another hack, but a stark demonstration of a systemic vulnerability in many DAOs. When governance is reduced to a simple majority vote, and votes are bought with tokens, any sufficiently wealthy or coordinated player can seize control. BONK was lucky that the attack was aimed at theft rather than the complete destruction of the protocol. Projects using DAOs urgently need to implement mechanisms to protect against "capital voting"—for example, temporary token lock-ups before voting or participant verification. Otherwise, such attacks will become the norm.