Skip to main content
Sign in

BonkDAO Treasury Governance Attack

avoid.net/bonkdao-treasury-governance-attack3/100·88% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Summary

On July 6, 2026, an anonymous attacker drained approximately $20 million in BONK tokens from BonkDAO's treasury on Solana's Realms governance platform by spending roughly $4.4 million to acquire just over 1% of BONK's circulating supply, meeting the DAO's quorum threshold and passing Bonk Improvement Proposal #76 with 99.9% approval across only seven voting wallets. The attack exploited structural design failures — no timelock, no multisig safeguard, and a 1% quorum floor — rather than any smart contract code vulnerability. It is widely characterized as the most significant governance-attack-as-exploit in Solana DAO history.

Have evidence about BonkDAO Treasury Governance Attack?

Timeline(6 events)

2026-06-30

Anonymous wallet submitted Bonk Improvement Proposal #76 (BIP-76) containing hidden clauses authorizing a treasury transfer to an attacker-controlled address.

CoinDesk

2026-07-04

Attacker began acquiring BONK tokens on Bybit and Binance exchanges over several days to build voting power ahead of the proposal's close.

CoinDesk

2026-07-06

BIP-76 passed with 99.9% yes votes across only seven participating wallets (2.9% turnout). Attacker-linked wallets controlled approximately 99.878% of votes cast. Approximately 4.43 trillion BONK (roughly $20 million) transferred from BonkDAO treasury to attacker-controlled wallet.

CoinDesk / The Block / CryptoTimes

2026-07-06

Approximately $188,000 in BONK sent to a centralized exchange roughly nine hours after the treasury drain; approximately $5.3 million offloaded to exchanges. Approximately $19 million moved to a secondary multisig wallet.

CoinDesk

2026-07-07

BonkDAO publicly confirmed the attack. BONK token fell more than 9% on the news. Upbit suspended BONK deposits and withdrawals. BonkDAO announced coordination with exchanges, the Solana Foundation, bridges, and law enforcement.

CryptoTimes / KuCoin / Bitcoin.com News

2026-07-08

Security firm Halborn published technical postmortem identifying three design failures: low 1% quorum threshold, absence of timelock on Realms, and no multisig safeguard over treasury movements. Attorney Carlo D'Angelo published legal analysis arguing on-chain compliance does not preclude criminal or civil liability.

Halborn / D'Angelo Legal
Provenance & Audit Trail
15 Wayback Archives

Decision Log

  • #1publish⛓ pending8/2/2026, 12:04:24 PM
    hash: 9vegpRGpJr6uMAD7jjb71M6Wko5z9xuLudbuD3Vx3jcu

15 of 15 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 8/2/2026, 12:04:14 PM

last updated: 8/2/2026, 5:16:07 PM

avoid.net — verified advice for a post-truth world