TLDR
BonkDAO, the governance maker/">DAO for Solana memecoin Bonk (BONK), has been drained of roughly $20 million through a malicious but technically valid governance proposal.
- An attacker spent about $4 million accumulating BONK, then used that voting power to pass a proposal that moved around 4.4 trillion BONK from the DAO treasury to their wallet.
- Reports say BONK fell roughly 7 to 8 percent, and exchanges including Upbit and Kraken paused BONK deposits and withdrawals as the stolen tokens started heading toward centralized venues.
- BonkDAO is working with law enforcement, exchanges, bridges, and the Solana Foundation, and the incident is already sparking broader debate about DAO governance safeguards across crypto.
Deep Dive
1. Mechanics Of The Governance Attack
Multiple outlets report that an anonymous wallet submitted Bonk Improvement Proposal 76 on June 30, instructing the DAO to transfer about 4.4 trillion BONK, worth roughly $20 million, to its own address. The attacker then spent around $4.4 million buying BONK on exchanges to reach the quorum threshold and cast enough "yes" votes to pass the proposal, exploiting low turnout rather than any code bug. Once the vote passed, the DAO's on chain logic automatically executed the transfer, moving the treasury funds to the attacker, who began routing tokens to a multisig wallet and exchanges as detailed in on chain tracing covered by Coindesk and others (example).
Confidence: high, as BonkDAO's own X statement and several major crypto news outlets report consistent details.
2. Impact On BONK, Exchanges, And Solana
Coverage from Decrypt and Cointelegraph notes BONK dropped about 7 to 8 percent in the 24 hours after the drain, adding stress to an already weak memecoin sector (overview). Major exchanges such as Upbit and Kraken paused BONK deposits and withdrawals, citing user protection after the incident, while some of the stolen tokens were reportedly sent toward exchange wallets. The loss of a large treasury chunk threatens future BONK burn programs and community incentives, even though Solana itself was not technically compromised, which keeps the blast radius more about governance trust than base chain security.
3. Governance Lessons And What To Watch
BonkDAO has said it identified the exchange wallets used to buy BONK before the proposal and has notified law enforcement, while coordinating with exchanges, bridges, and the Solana Foundation to try to freeze or recover funds (BonkDAO statement coverage). The attack highlights structural risks in token weighted DAOs: low turnout, no emergency timelocks, and lack of multisig or security council overrides can let a well funded attacker legally "buy the vote" and drain treasuries. Other DAOs are likely to revisit quorum rules, voting locks, and kill switches, especially where treasuries hold large, liquid memecoin reserves.
If you interact with DAO governed tokens, you should pay as much attention to governance design and safeguards as you do to smart contract audits or exchange listings.
Conclusion
A well funded attacker used BonkDAO's own governance system to turn a $4 million BONK position into control of a roughly $20 million treasury transfer. The fallout is still unfolding, but the incident underlines that in Solana's memecoin ecosystem and beyond, DAO design can be a primary security risk, and future trust will depend on whether projects tighten voting safeguards and successfully recover stolen funds.
