Need help? Support
BITCOIN
Tether Dominance USDT.D

Memecoin DAO exploit triggers $20M treasury loss

Published 526 words 3 min read

TLDR

BonkDAO, the maker/">DAO behind Solana memecoin Bonk (BONK), has been drained of roughly $20 million via a malicious governance exploit.

  1. An attacker accumulated voting power and passed a proposal that moved about 4.4 trillion BONK from the DAO treasury to their own wallet.
  2. The exploit abused token-weighted governance rather than a smart contract bug, exposing systemic risks in DAO design and low voter participation.
  3. BonkDAO, exchanges and the Solana Foundation are coordinating with law enforcement, while BONK faces selling pressure and potential regulatory scrutiny.

Deep Dive

1. How The Treasury Was Drained

Multiple reports confirm that BonkDAO suffered a governance attack that drained around $20 million worth of BONK from its treasury, equal to about 4.426 trillion tokens. The attacker spent roughly $4.4 million buying BONK to gain enough voting power, then pushed through Bonk Improvement Proposal #76 on the Realms governance platform, which instructed the treasury to send its holdings to a controlled address.

Coverage from outlets such as Bitcoin.com and CoinDesk describes this as a fully on-chain, legitimate sequence of transactions in terms of protocol rules, even though the economic outcome is clearly hostile to the DAO. BONK fell around 7 to 9 percent on the news, with the memecoin already down heavily over the past year, according to recent market commentary.

What this means

The loss is real and already reflected in BONKs treasury and price, even though the attacker technically used normal governance mechanics rather than a code exploit.

2. Governance And Memecoin Risks

This incident did not exploit a bug in BonkDAOs contracts. Instead, it exploited the governance model, where voting power is proportional to token holdings. With very low voter participation, one wallet was able to control almost all effective votes, pass the proposal, and drain the treasury.

Analysts and legal commentators argue this shows how DAOs can be vulnerable when treasuries are directly controlled by token votes and quorum thresholds are weak. Some, including former Ripple CTO David Schwartz, have suggested such actions may be treated as fraud or breach of fiduciary duty, reinforcing that code is law is not a legal shield.

3. What To Watch Next

BonkDAO says it has identified exchange wallets used to buy BONK ahead of the vote and is working with centralized exchanges, bridges and the Solana Foundation to freeze or recover funds, as highlighted in updates from sources like Cointelegraph and Yahoo Finance. Some exchanges, including Upbit and Kraken, have temporarily paused BONK deposits and withdrawals to protect users.

Key open questions are whether the attacker can liquidate a meaningful portion of the stolen tokens, how much can be frozen or clawed back, and whether regulators treat this as a precedent-setting case for DAO governance liability. For BONK holders and memecoin traders, ongoing movement of stolen tokens and any follow-up legal or exchange actions are the main signals to monitor.

Conclusion

A single governance proposal has effectively converted BonkDAOs token treasury into attacker-controlled funds, turning a design weakness in token voting into a $20 million loss. For crypto users, the case is a sharp reminder that DAO treasuries governed directly by lightly participated, token-weighted voting can be as risky as vulnerable smart contracts, and that governance parameters, participation and legal exposure need as much scrutiny as code audits.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top