Skip to main content
Sign in

Audit log

Every state-changing event for BonkDAO Treasury Governance Attack: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-08-02 12:04:24Z
    Score: ?? (no score change)
    anchorpending
    chain
    hash
    9vegpRGpJr6u…D3Vx3jcusha256 → base58
    verifying row…
    canonical bytes (19414 B) ▸
    {"actor":"system:backfill","investigation_id":"3c1969e1-ee54-409a-a92b-1b829b3d76c6","kind":"publish","page_slug":"bonkdao-treasury-governance-attack","published_at":"2026-08-02T12:04:24.242Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"BonkDAO Treasury Governance Attack","sections":[{"content":"On July 6, 2026, BonkDAO confirmed that approximately $20 million in BONK tokens were drained from its treasury following the execution of a malicious governance proposal. The attacker did not exploit any smart contract code vulnerability. Instead, the attacker used BonkDAO's own token-weighted voting system on Solana's Realms governance platform to authorize a treasury transfer to an attacker-controlled wallet. The malicious proposal, designated Bonk Improvement Proposal #76 (BIP-76), was submitted on June 30, 2026, and contained hidden clauses authorizing a transfer of approximately 4.43 trillion BONK tokens. The proposal sat live for six days before execution. Only seven wallet addresses voted; wallets attributed to the attacker controlled approximately 99.878% of participating votes, yielding a 99.9% approval result despite an active community of more than 18,000 eligible voters — a turnout of approximately 2.9%.","heading":"Attack Overview","severity":"critical","sources":[{"credibility":1,"name":"BONK faces $20 million treasury drain after attacker spends $4 million to pass malicious proposal — CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2026/07/07/bonk-faces-usd20-million-treasury-drain-after-attacker-spends-usd4-million-to-pass-malicious-proposal"},{"credibility":1,"name":"BonkDAO loses $20 million following malicious governance proposal attack — The Block","type":"news_article","url":"https://www.theblock.co/post/407343/bonkdao-loses-20-million-following-malicious-governance-proposal-attack"},{"credibility":2,"name":"BonkDAO Hit by $20M Treasury Drain in Governance Attack, BONK Slides — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/07/bonkdao-hit-by-20m-treasury-drain-in-governance-attack-bonk-slides/"}]},{"content":"The attacker acquired approximately 882.38 billion BONK tokens — just over the 1% of circulating supply required to meet BonkDAO's quorum threshold — at a reported cost of approximately $4.4 million. According to blockchain analytics reported by Chainalysis and Lookonchain, the attacker purchased BONK tokens across multiple days, building voting power quietly on exchanges including Bybit and Binance before the proposal's voting window closed. Blockchain analysis identified a Bybit account as funding the attacker's initial wallet. Upon passing, BIP-76 triggered an automated transfer of approximately 4.43 trillion BONK tokens from BonkDAO's treasury to a wallet controlled by the attacker. Post-drain, approximately $5.3 million worth of BONK was reported offloaded to exchanges within hours, with roughly $188,000 sent to an exchange approximately nine hours after the drain, and approximately $19 million moved to a secondary multisig wallet for subsequent disposition.","heading":"Attack Mechanics and Token Acquisition","severity":"critical","sources":[{"credibility":1,"name":"BONK faces $20 million treasury drain after attacker spends $4 million to pass malicious proposal — CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2026/07/07/bonk-faces-usd20-million-treasury-drain-after-attacker-spends-usd4-million-to-pass-malicious-proposal"},{"credibility":2,"name":"BonkDAO Treasury Loses $20M in Malicious Governance Attack, BONK Slides 8% — Bitcoin.com News","type":"news_article","url":"https://news.bitcoin.com/bonkdao-treasury-loses-20m-in-malicious-governance-attack-bonk-slides-8/"},{"credibility":2,"name":"BonkDAO Loses $20M as Attacker Buys Quorum With $4.4M in BONK — TechTimes","type":"news_article","url":"https://www.techtimes.com/articles/319820/20260707/bonkdao-loses-20m-attacker-buys-quorum-44m-bonk.htm"}]},{"content":"Security firm Halborn characterized the incident as enabled directly by three converging design failures in BonkDAO's Realms configuration. First, the quorum floor of 1% of total supply was set low enough that a single actor with approximately $4.4 million in capital could meet it unilaterally. Second, BonkDAO's Realms deployment did not include a timelock — a delay between proposal approval and execution that would have allowed the community or administrators to detect and cancel the malicious transfer before funds were moved. Solana's Realms platform supports timelock configuration, but BonkDAO did not enable it. Third, no multisignature control over large treasury movements served as a backstop against single-proposal execution of a large transfer. Researchers and commentators have noted that these were not smart contract bugs but deliberate governance parameter choices that left the treasury structurally exposed. The attack operates entirely within the system's authorized parameters: token acquisition and vote casting are both permitted actions.","heading":"Structural Vulnerabilities Exploited","severity":"critical","sources":[{"credibility":2,"name":"Explained: The BonkDAO Hack (July 2026) — Halborn Security","type":"research","url":"https://www.halborn.com/blog/post/explained-the-bonkdao-hack-july-2026"},{"credibility":2,"name":"What is a governance attack? How BonkDAO lost $20M in a single vote — crypto.news","type":"news_article","url":"https://crypto.news/what-is-a-governance-attack-how-bonkdao-lost-20m-in-a-single-vote/"},{"credibility":3,"name":"BonkDAO Loses $20M in Governance Attack, Exposing Procedural Flaws — Silicon Report","type":"news_article","url":"https://www.siliconreport.com/bonkdao-loses-20m-in-governance-attack-exposing-procedural-flaws-704960cd"}]},{"content":"BONK token declined more than 9% within hours of the attack becoming public on July 7, 2026, falling from approximately $0.0000044 to lows near $0.0000030. CryptoTimes reported BONK's market capitalization declined to approximately $380 million and trading volume increased over 48% during the incident period. Upbit, a major South Korean exchange, suspended BONK deposits and withdrawals following the event. The attacker's subsequent liquidation of stolen BONK — with 4.43 trillion tokens beginning to move to Binance, Coinbase, and OKX — created additional sustained sell pressure on the token's recovery attempts.","heading":"Market and Price Impact","severity":"high","sources":[{"credibility":2,"name":"BonkDAO Hit by Governance Attack, Loses $20M in BONK as Upbit Pauses Services — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/bonkdao-hit-by-governance-attack-loses-20m-in-bonk-as-upbit-pauses-services"},{"credibility":2,"name":"BonkDAO Hit by $20M Treasury Drain in Governance Attack, BONK Slides — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/07/bonkdao-hit-by-20m-treasury-drain-in-governance-attack-bonk-slides/"},{"credibility":3,"name":"Bonk Price Prediction Wobbles as $20M Governance Attack Rattles Holders — CoinGabbar","type":"news_article","url":"https://www.coingabbar.com/en/price-prediction/bonk-price-prediction-wobbles-20m-governance-attack-rattles"}]},{"content":"BonkDAO officially confirmed the attack, describing the event as a malicious governance proposal that resulted in an unauthorized transfer of approximately $20 million in BONK tokens from the DAO treasury. The organization identified exchange wallets used to purchase BONK prior to proposal submission and engaged exchanges, bridges, and the Solana Foundation to manage the fallout. Law enforcement agencies were notified. The $188,000 sent to an exchange approximately nine hours after the drain, along with the Bybit account identified by Chainalysis as funding the attacker's initial wallet, were cited as potential leads for investigators. As of reporting, no funds had been confirmed recovered. BonkDAO did not immediately announce changes to its governance configuration.","heading":"DAO Response and Recovery Efforts","severity":"high","sources":[{"credibility":1,"name":"BONK faces $20 million treasury drain after attacker spends $4 million to pass malicious proposal — CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2026/07/07/bonk-faces-usd20-million-treasury-drain-after-attacker-spends-usd4-million-to-pass-malicious-proposal"},{"credibility":2,"name":"BonkDAO Hit by $20M Treasury Drain in Governance Attack, BONK Slides — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/07/bonkdao-hit-by-20m-treasury-drain-in-governance-attack-bonk-slides/"}]},{"content":"Legal and regulatory classification of the incident is contested. Criminal defense attorney Carlo D'Angelo published an analysis on July 8, 2026, arguing that formal compliance with on-chain voting protocol does not provide legal immunity, and that the incident may support civil claims for conversion and unjust enrichment regardless of whether the vote was technically authorized by the protocol rules. D'Angelo's analysis invoked the Mango Markets precedent: Avraham Eisenberg was convicted in 2024 for a $110 million governance-adjacent extraction, though wire fraud charges were partially vacated in May 2025. The court in that case reasoned that autonomous code cannot be deceived; prosecutors appealed, leaving this area of law unsettled. No SEC enforcement action or criminal indictment had been announced as of reporting. Commentators across crypto media debated whether the BonkDAO incident constitutes a hack or a permissioned governance action, with no consensus reached. The case is cited as illustrating systemic vulnerability in token-weighted DAO governance models more broadly.","heading":"Legal Classification and Regulatory Implications","severity":"high","sources":[{"credibility":2,"name":"Code Is Not Law: Lessons From the $20M BONK DAO Attack — D'Angelo Legal","type":"other","url":"https://www.dangelolegal.com/legal-insights/code-is-not-law-what-the-20-million-bonk-dao-governance-attack-means-for-crypto-daos"},{"credibility":2,"name":"Was It a Hack or Governance? BONK's $21M Treasury Vote Divides Crypto — CryptoPotato","type":"news_article","url":"https://cryptopotato.com/was-it-a-hack-or-governance-bonks-21m-treasury-vote-divides-crypto/"},{"credibility":2,"name":"BONK DAO Lost $20 Million Without a Hack — CryptoTicker","type":"news_article","url":"https://cryptoticker.io/en/bonk-dao-governance-attack-20-million-treasury-drain/"}]},{"content":"The BonkDAO incident is widely characterized by security researchers and analysts as the most significant governance-attack-as-exploit in Solana DAO history. It demonstrates that token-weighted voting systems with low quorum thresholds and no execution delays are structurally vulnerable to capital-funded takeover without any code exploit. Halborn and crypto.news identified timelocks, higher quorum requirements, and multisig safeguards over large treasury movements as the primary mitigations, noting these controls are available on Realms but rarely fully deployed across vulnerable DAOs. The incident also raises the possibility of flash-loan-based governance attacks, where no upfront capital is required — a variant researchers note does not apply here but represents a related exposure class. The attack adds to a growing list of governance-related incidents across decentralized protocols and is expected to renew industry discussion around minimum governance safeguards for community-controlled treasuries.","heading":"Broader Implications for DAO Security","severity":"medium","sources":[{"credibility":2,"name":"What is a governance attack? How BonkDAO lost $20M in a single vote — crypto.news","type":"news_article","url":"https://crypto.news/what-is-a-governance-attack-how-bonkdao-lost-20m-in-a-single-vote/"},{"credibility":2,"name":"Explained: The BonkDAO Hack (July 2026) — Halborn Security","type":"research","url":"https://www.halborn.com/blog/post/explained-the-bonkdao-hack-july-2026"},{"credibility":2,"name":"BONK Memecoin And Solana Ecosystem's BonkDAO Suffers Significant Treasury Drain In Governance Attack — Crowdfund Insider","type":"news_article","url":"https://www.crowdfundinsider.com/2026/07/290028-bonk-memecoin-and-solana-ecosystems-bonkdao-suffers-significant-treasury-drain-in-governance-attack/"}]}],"sources_used":[{"credibility":1,"name":"BONK faces $20 million treasury drain after attacker spends $4 million to pass malicious proposal — CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2026/07/07/bonk-faces-usd20-million-treasury-drain-after-attacker-spends-usd4-million-to-pass-malicious-proposal"},{"credibility":1,"name":"BonkDAO loses $20 million following malicious governance proposal attack — The Block","type":"news_article","url":"https://www.theblock.co/post/407343/bonkdao-loses-20-million-following-malicious-governance-proposal-attack"},{"credibility":2,"name":"BonkDAO Hit by $20M Treasury Drain in Governance Attack, BONK Slides — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/07/bonkdao-hit-by-20m-treasury-drain-in-governance-attack-bonk-slides/"},{"credibility":2,"name":"BonkDAO Treasury Loses $20M in Malicious Governance Attack, BONK Slides 8% — Bitcoin.com News","type":"news_article","url":"https://news.bitcoin.com/bonkdao-treasury-loses-20m-in-malicious-governance-attack-bonk-slides-8/"},{"credibility":2,"name":"Explained: The BonkDAO Hack (July 2026) — Halborn Security","type":"research","url":"https://www.halborn.com/blog/post/explained-the-bonkdao-hack-july-2026"},{"credibility":2,"name":"What is a governance attack? How BonkDAO lost $20M in a single vote — crypto.news","type":"news_article","url":"https://crypto.news/what-is-a-governance-attack-how-bonkdao-lost-20m-in-a-single-vote/"},{"credibility":2,"name":"BonkDAO Loses $20M as Attacker Buys Quorum With $4.4M in BONK — TechTimes","type":"news_article","url":"https://www.techtimes.com/articles/319820/20260707/bonkdao-loses-20m-attacker-buys-quorum-44m-bonk.htm"},{"credibility":2,"name":"BONK DAO Loses $20 Million in Governance Attack, Token Falls 10% — Yahoo Finance","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/bonk-dao-loses-20-million-180738851.html"},{"credibility":2,"name":"BonkDAO Hit by Governance Attack, Loses $20M in BONK as Upbit Pauses Services — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/bonkdao-hit-by-governance-attack-loses-20m-in-bonk-as-upbit-pauses-services"},{"credibility":2,"name":"Code Is Not Law: Lessons From the $20M BONK DAO Attack — D'Angelo Legal","type":"other","url":"https://www.dangelolegal.com/legal-insights/code-is-not-law-what-the-20-million-bonk-dao-governance-attack-means-for-crypto-daos"},{"credibility":2,"name":"Was It a Hack or Governance? BONK's $21M Treasury Vote Divides Crypto — CryptoPotato","type":"news_article","url":"https://cryptopotato.com/was-it-a-hack-or-governance-bonks-21m-treasury-vote-divides-crypto/"},{"credibility":2,"name":"BONK DAO Lost $20 Million Without a Hack — Here's How a Governance Attack Drained the Treasury — CryptoTicker","type":"news_article","url":"https://cryptoticker.io/en/bonk-dao-governance-attack-20-million-treasury-drain/"},{"credibility":2,"name":"BONK Memecoin And Solana Ecosystem's BonkDAO Suffers Significant Treasury Drain In Governance Attack — Crowdfund Insider","type":"news_article","url":"https://www.crowdfundinsider.com/2026/07/290028-bonk-memecoin-and-solana-ecosystems-bonkdao-suffers-significant-treasury-drain-in-governance-attack/"},{"credibility":2,"name":"Attacker Drains $20M From BonkDAO Treasury Through Token-Weighted Exploit — CoinPedia","type":"news_article","url":"https://coinpedia.org/news/attacker-drains-20m-from-bonkdao-treasury-through-token-weighted-exploit/"},{"credibility":3,"name":"BonkDAO Governance Attack Drains $20M in BONK Tokens — Bitcoin Foundation","type":"news_article","url":"https://bitcoinfoundation.org/news/altcoins/bonkdao-governance-attack-drains-20m-in-bonk-from-treasury/"}],"summary":"On July 6, 2026, an anonymous attacker drained approximately $20 million in BONK tokens from BonkDAO's treasury on Solana's Realms governance platform by spending roughly $4.4 million to acquire just over 1% of BONK's circulating supply, meeting the DAO's quorum threshold and passing Bonk Improvement Proposal #76 with 99.9% approval across only seven voting wallets. The attack exploited structural design failures — no timelock, no multisig safeguard, and a 1% quorum floor — rather than any smart contract code vulnerability. It is widely characterized as the most significant governance-attack-as-exploit in Solana DAO history.","timeline":[{"date":"2026-06-30","event":"Anonymous wallet submitted Bonk Improvement Proposal #76 (BIP-76) containing hidden clauses authorizing a treasury transfer to an attacker-controlled address.","source":"CoinDesk","source_url":"https://www.coindesk.com/markets/2026/07/07/bonk-faces-usd20-million-treasury-drain-after-attacker-spends-usd4-million-to-pass-malicious-proposal"},{"date":"2026-07-04","event":"Attacker began acquiring BONK tokens on Bybit and Binance exchanges over several days to build voting power ahead of the proposal's close.","source":"CoinDesk","source_url":"https://www.coindesk.com/markets/2026/07/07/bonk-faces-usd20-million-treasury-drain-after-attacker-spends-usd4-million-to-pass-malicious-proposal"},{"date":"2026-07-06","event":"BIP-76 passed with 99.9% yes votes across only seven participating wallets (2.9% turnout). Attacker-linked wallets controlled approximately 99.878% of votes cast. Approximately 4.43 trillion BONK (roughly $20 million) transferred from BonkDAO treasury to attacker-controlled wallet.","source":"CoinDesk / The Block / CryptoTimes","source_url":"https://www.coindesk.com/markets/2026/07/07/bonk-faces-usd20-million-treasury-drain-after-attacker-spends-usd4-million-to-pass-malicious-proposal"},{"date":"2026-07-06","event":"Approximately $188,000 in BONK sent to a centralized exchange roughly nine hours after the treasury drain; approximately $5.3 million offloaded to exchanges. Approximately $19 million moved to a secondary multisig wallet.","source":"CoinDesk","source_url":"https://www.coindesk.com/markets/2026/07/07/bonk-faces-usd20-million-treasury-drain-after-attacker-spends-usd4-million-to-pass-malicious-proposal"},{"date":"2026-07-07","event":"BonkDAO publicly confirmed the attack. BONK token fell more than 9% on the news. Upbit suspended BONK deposits and withdrawals. BonkDAO announced coordination with exchanges, the Solana Foundation, bridges, and law enforcement.","source":"CryptoTimes / KuCoin / Bitcoin.com News","source_url":"https://www.cryptotimes.io/2026/07/07/bonkdao-hit-by-20m-treasury-drain-in-governance-attack-bonk-slides/"},{"date":"2026-07-08","event":"Security firm Halborn published technical postmortem identifying three design failures: low 1% quorum threshold, absence of timelock on Realms, and no multisig safeguard over treasury movements. Attorney Carlo D'Angelo published legal analysis arguing on-chain compliance does not preclude criminal or civil liability.","source":"Halborn / D'Angelo Legal","source_url":"https://www.halborn.com/blog/post/explained-the-bonkdao-hack-july-2026"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 7fdec80e-7061-437c-ad4c-537ada1c612f
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.