On June 30, a large-scale attack targeted the treasury of the BONK memecoin. The attacker managed to withdraw tokens worth $21.2 million, spending only $4.4 million on preparation. The hacker's net profit amounted to $16.8 million. The incident was made possible due to a vulnerability in the governance mechanism of the decentralized autonomous organization (DAO).

The essence of the attack lay in vote manipulation. In DAO systems, it is enough to reach a certain quorum of votes tied to the number of tokens in a wallet. The hacker pre-purchased 882 billion BONK on the Bybit and Binance exchanges for $4.4 million. This volume was sufficient to exceed the required quorum of 879 billion BONK.

Attack Details

The attacker submitted a proposal to the DAO to transfer 4.426 trillion BONK ($21.2 million) from the treasury to their controlled wallet (9bxW…JHvQ). They then voted "yes" with their entire volume of 882 billion BONK. The proposal passed automatically, and the tokens were transferred.

Screenshot of one of the stages of the attacker's operation
Screenshot of one of the stages of the attacker's operation.

Fund Distribution

Part of the stolen assets has already changed addresses. As of the time of publication, the data looks as follows:

Amount in TokensAmount in $Status / Location
40 billion BONK$188 thousandTransferred to OKX exchange
4.386 trillion BONK$19.3 millionRemaining on wallet EXaJnm…eh42

It appears the hacker is in no hurry to withdraw the remaining funds. Analysts continue to monitor the specified address.

Members of the crypto community noted that this time the root of the problem lay in the project's governance system. The code itself remained secure. This is a classic example of a governance attack, where the attacker exploits flaws in the voting mechanism rather than vulnerabilities in smart contracts.

My comment: This incident is a stark reminder that the security of a DAO depends not only on the quality of the code but also on the thoughtfulness of its governance mechanisms. Projects need to implement more complex voting schemes, including time delays and multi-level checks, to prevent such manipulation. Otherwise, trust in decentralized systems will be undermined.