BonkDAO lost roughly $20 million in BONK on July 6 after an attacker used the project’s own governance process to pass a proposal authorizing the transfer. The incident did not involve a smart contract exploit, compromised private keys, or hacked user wallets. Instead, it exposed how a large on-chain treasury can be taken over when token voting power is cheap to assemble and basic governance safeguards are absent.
The proposal that moved the funds
The chain of events began on June 30, when an anonymous wallet submitted BIP #76 to BonkDAO through Realms, the standard Solana governance platform. The proposal presented itself as a governance renewal plan, but included the instruction that mattered most: the transfer of 4.43 trillion BONK, described as the bulk of the treasury, to a wallet controlled by the proposer.
The measure remained open for six days. During that period, the attacker accumulated enough BONK to control the outcome. On-chain researchers including SlowMist founder Yu Xian and analyst Yu Jin later said the wallet spent about $4.4 million buying BONK through exchange wallets. That amount represented just over 1% of total supply, but it was sufficient to clear the DAO’s quorum threshold.
How the vote passed
When voting closed on July 6, BIP #76 had 882.38 billion BONK in favor, narrowly above the 879.95 billion BONK quorum. Only seven wallets participated. Turnout was reported at 2.9%, and more than 18,000 members did not vote.
The proposal then executed automatically through Realms. There was no timelock between approval and execution, no council review, and no veto mechanism to stop the treasury transfer after the vote passed. The BONK was sent to a wallet ending in JHvQ, which investigators linked to funding from a Bybit account. Some of the tokens began moving toward exchanges within hours.
Why the DAO was vulnerable
The incident has prompted scrutiny of BonkDAO’s governance design rather than its code. According to the source article, three protections were missing: a delay before execution, an emergency multisig or council brake, and quorum rules better aligned with the size of the treasury.
BonkDAO’s treasury reportedly held about 15% of circulating BONK, while the cost of obtaining decisive voting power was far lower than the value that could be extracted. The attacker’s estimated $4.4 million outlay against roughly $20 million in treasury assets has been cited as a clear example of what governance researchers describe as the “cost of corruption” problem.
The article also argues that the attack was made easier by weak participation. In practice, the attacker did not need to overcome broad opposition; they only needed to outvote an absent electorate. That dynamic has renewed concern across the DAO sector over declining turnout and token-weighted voting systems where treasury security depends heavily on holder attention.
Response and wider debate
BonkDAO has said no user wallets were affected and the BONK token contract was not compromised. Initial response efforts focused on exchange coordination and fund tracing. Upbit suspended BONK deposits and withdrawals, while BonkDAO notified law enforcement and coordinated with exchanges, bridges, and the Solana Foundation, according to the source article.
The event has also triggered a broader argument over whether the transfer should be treated as theft or as a governance outcome produced by flawed rules. One side argues the attacker followed the protocol as written and exploited negligence rather than a bug. The other argues that a proposal that allegedly misrepresented its purpose and transferred treasury assets to its author should still be seen as fraud, even if the transactions were technically valid.
That dispute matters because it affects where defenses are expected to sit: entirely on-chain through timelocks, vetoes, and quorum reforms, or also off-chain through exchange freezes, law enforcement referrals, and potential legal claims. Either way, the case has intensified calls for DAOs to review how easily voting power can be assembled relative to the value held in treasury.
In the immediate aftermath, the incident became a warning for treasury-holding DAOs across Solana and other networks. The source article says emergency reviews are already pushing projects toward stronger default protections, including timelocks, proposal review friction, and governance designs that account for low participation and the market price of control.
Source: crypto.news