On June 30, a large-scale attack targeted the treasury of the BONK memecoin. The attacker managed to withdraw tokens worth $21.2 million, spending only $4.4 million on preparation. The hacker's net profit amounted to $16.8 million. The incident was made possible due to a vulnerability in the governance mechanism of the decentralized autonomous organization (DAO).
The essence of the attack lay in vote manipulation. In DAO systems, it is enough to reach a certain quorum of votes tied to the number of tokens in a wallet. The hacker pre-purchased 882 billion BONK on the Bybit and Binance exchanges for $4.4 million. This volume was sufficient to exceed the required quorum of 879 billion BONK.
Attack Details
The attacker submitted a proposal to the DAO to transfer 4.426 trillion BONK ($21.2 million) from the treasury to their controlled wallet (9bxW…JHvQ). They then voted "yes" with their entire volume of 882 billion BONK. The proposal passed automatically, and the tokens were transferred.
Fund Distribution
Part of the stolen assets has already changed addresses. As of the time of publication, the data looks as follows:
| Amount in Tokens | Amount in $ | Status / Location |
| 40 billion BONK | $188 thousand | Transferred to OKX exchange |
| 4.386 trillion BONK | $19.3 million | Remaining on wallet EXaJnm…eh42 |
It appears the hacker is in no hurry to withdraw the remaining funds. Analysts continue to monitor the specified address.
Members of the crypto community noted that this time the root of the problem lay in the project's governance system. The code itself remained secure. This is a classic example of a governance attack, where the attacker exploits flaws in the voting mechanism rather than vulnerabilities in smart contracts.
My comment: This incident is a stark reminder that the security of a DAO depends not only on the quality of the code but also on the thoughtfulness of its governance mechanisms. Projects need to implement more complex voting schemes, including time delays and multi-level checks, to prevent such manipulation. Otherwise, trust in decentralized systems will be undermined.