TLDR
BonkDAO, which governs Solana memecoin Bonk (BONK), has been drained of roughly $20 million via a malicious governance proposal, not a traditional smart contract hack.
- An attacker bought about $4 million of BONK, gained voting control, and passed a proposal that moved around 4.4 trillion BONK, worth about $20 million, from the maker/">DAO treasury to their wallet.
- BONK fell roughly 8 to 9 percent on the news, some exchanges paused BONK deposits and withdrawals, and the incident highlights how DAO voting itself can be a core security risk.
- BonkDAO has alerted law enforcement and is working with Solana and exchanges to recover funds, while the wider DeFi and memecoin space is likely to face renewed scrutiny of governance design.
Deep Dive
1. How The Attack Worked
Reports from multiple outlets say BonkDAO was hit by a governance attack in which an unknown actor accumulated significant BONK holdings and then pushed a malicious governance proposal to drain the treasury. The attacker spent roughly $4.04.4 million buying BONK, reached quorum, and passed a proposal that transferred about 4.426 trillion BONK tokens, valued near $20 million, to a wallet they controlled on Solana.
Crucially, this did not exploit a bug in the code. It exploited the rules of token weighted voting, using the Realms governance platform to push through a treasury transfer that the smart contract then executed automatically as designed.
The attack was essentially buying votes in an underparticipated DAO and using them to seize the treasury, showing that governance mechanics can be as exploitable as code.
2. Impact On BONK And Memecoins
Following the disclosure, BONK dropped around 8 to 9 percent and saw a sharp wave of selling, as noted in several market reports, with traders pricing in treasury depletion and reputational damage. The stolen tokens have begun moving toward exchanges, prompting platforms such as Upbit and Kraken to temporarily pause BONK deposits and withdrawals as a precaution, according to coverage on Solana meme coin Bonks treasury drain.
This comes at a time when memecoin market capitalization was already under pressure, so an incident of this size reinforces the narrative that memecoins carry elevated governance and security risk, not just price volatility.
Holders face both immediate price shock and longer term uncertainty around future burns, incentives, and whether stolen tokens will be dumped into the market.
3. Governance And Legal Fallout
BonkDAO has said it identified exchange wallets used to accumulate BONK, notified law enforcement, and is coordinating with exchanges, bridges, and the Solana Foundation to trace and potentially freeze assets, as reported in BonkDAO treasury loses $20M in malicious governance attack. Legal commentators, including Ripples former CTO, have argued this constitutes corporate style fraud and that DAO participants and voters may have fiduciary duties despite code is law rhetoric.
For other DAOs, this incident will likely accelerate moves to raise quorum thresholds, limit single wallet voting power, add multi step treasury controls, or introduce council review layers before large transfers.
Governance tokens and DAOs should be assessed not just on tokenomics but on whether a motivated actor can cheaply buy enough votes to control the treasury.
Conclusion
The BonkDAO exploit shows that a memecoin treasury can be drained without breaking the code, simply by gaming token weighted voting in a low participation DAO. For crypto users, the key takeaway is that governance design, quorum, and voter distribution are now critical parts of security, especially where large treasuries back high profile memecoins. Watching how BonkDAO reforms its governance and whether stolen BONK is recovered or sold will help gauge both the projects resilience and how seriously the wider market treats DAO governance risk after this incident.
