TLDR
BonkDAO, the maker/">DAO behind Solana meme coin Bonk (BONK), was hit by a malicious governance attack that drained about $20 million from its treasury.
- Reports say an attacker used voting power to pass a malicious proposal that moved roughly 4.4 trillion BONK (about $20 million) from the DAO treasury to their own wallet.
- BONK dropped around 7 to 8 percent on the news, exchanges like Upbit and Kraken paused BONK deposits, and the loss weakens the DAOs ability to fund burns and ecosystem incentives.
- BonkDAO says it is working with law enforcement, the Solana Foundation, and exchanges to trace and freeze funds, and other DAOs are reexamining governance defenses against similar attacks.
Deep Dive
1. How The Exploit Worked
Multiple outlets report that BonkDAO suffered a roughly $20 million loss after an attacker passed a malicious governance proposal that transferred around 4.4 trillion BONK from the treasury to a controlled address. Articles from Bitcoin.com and Decrypt describe how the proposal, known as Bonk Improvement Proposal 76, was passed using token-weighted voting on Bonks Realms governance platform, then executed a transfer to a wallet ending in JHvQ.
Coverage notes that this was not a smart contract bug in the usual DeFi sense but a governance-level exploit, where the attacker accumulated enough BONK to control the vote and route treasury funds to themselves. Cointelegraph and The Defiant both frame it as a malicious governance proposal that drained the DAO treasury, with BonkDAO confirming the attack in a statement on X.
Governance itself became the attack surface, showing that legit proposals can be weaponized if a single actor can cheaply buy voting power.
2. Impact On BONK And Holders
News reports say BONK fell about 7 to 8 percent after the incident, with one piece noting the token is already down more than 80 percent over the past year. Decrypt reports that over 4.4 trillion BONK, valued at roughly $19.3 million at the time, left the DAO treasury, directly shrinking the pool used for burns, grants, and future incentives.
Yahoo and Decrypt also report that exchanges including Upbit and Kraken paused BONK deposits and withdrawals as a user-protection measure while the situation is investigated. That pause can temporarily limit liquidity and arbitrage, adding volatility for existing holders.
Even if you were not in the DAO, a treasury drain can hurt long term support for the token, while short term exchange pauses and uncertainty can magnify price swings.
3. Recovery Efforts And Governance Risks
BonkDAO says it has identified exchange wallets used to buy BONK ahead of the proposal and is actively working with exchanges, bridges and Solana Foundation to manage the situation, according to Bitcoin.com and The Defiant. Law enforcement has been notified, and the attackers funds have reportedly begun moving toward centralized exchanges, where cooperation from venues could enable freezes or partial recovery.
Analysts highlight this as part of a broader pattern of governance attacks, similar to earlier DAO proposal exploits. Any DAO that relies on pure token-weighted voting without safeguards like quorum, time-locks, or delegated security councils may face similar risks, especially in speculative memecoin ecosystems where whales can accumulate control quickly.
For DAO participants, smart contract audits are not enough; you also need to assess how hard it is for a single actor to buy or borrow enough tokens to push through a self-serving proposal.
Conclusion
The BonkDAO exploit shows how a memecoin treasury can be drained without a line of code being hacked, simply by capturing governance and passing a malicious proposal. That hits BONKs funding base, shakes confidence, and pushes other DAOs to rethink how they balance open voting with guardrails against capture. The key variables now are how much of the stolen BONK can be frozen or recovered and whether BonkDAO and similar projects strengthen their governance before the next attacker tries the same route.
