DeFi Governance Attack Wave 2026
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·2gKy6J…A7WHSummary
Between June and August 2026, at least seven DeFi protocols and DAOs across Ethereum, Solana, and Base suffered governance attacks in which attackers accumulated or borrowed voting tokens to pass malicious proposals, draining approximately $22 million to $30 million in total. The affected protocols include BonkDAO, Term Finance, Token of Power, BarnBridge SMART Yield, Panther Protocol, Unicly, and others. The attacks exploited structurally low governance participation, insufficient quorum thresholds, absent or ineffective timelocks, and legacy token approvals — rather than smart-contract code bugs.
Connected Entities
1 entitiesTimeline(9 events)
9 June 2026
Token of Power (TOP) governance attack on Ethereum: attacker acquires majority of 16,384-token supply through Tornado Cash-funded wallet, passes and executes a proposal minting 10 billion new tokens in a single transaction with no timelock, extracting approximately $1.58 million in ETH via Balancer V1.
CryptoTimes / Blockaid6 July 2026
BonkDAO governance attack on Solana: attacker spends approximately $4.4 million to purchase over 1 percent of BONK supply, meeting quorum threshold and controlling ~99.878 percent of votes cast, passing a malicious proposal that transfers approximately 4.43 trillion BONK (~$20 million) from the treasury instantly.
CoinDesk6 July 2026
Attacker deposits 320,000 BOND tokens into BarnBridge staking contract, acquiring voting power in preparation for the subsequent BarnBridge SMART Yield governance attack.
BlockSec7 July 2026
BonkDAO confirms attack publicly; states coordination with exchanges, Solana Foundation, and law enforcement. BONK token falls 8–10 percent.
Bitcoin.com News15 July 2026
BarnBridge SMART Yield governance attack on Ethereum: attacker submits malicious governance proposal replacing the CompoundProvider controller with a malicious contract, sweeping approximately $776,000 from roughly 50 wallets holding legacy USDC approvals.
BlockSec / KuCoin6 August 2026
Panther Protocol governance attack on Base: attacker exploits Reality.eth optimistic oracle with a misconfigured Base deployment, submitting malicious 'zkp-reexploit' upgrade proposal, allowing it to finalize unchallenged and draining 5.12 million ZKP (~$17,900). No user funds compromised.
CryptoTimes17 August 2026
Term Finance attacker purchases approximately 0.4852 tmvETH for roughly 0.5 ETH, quietly accumulating approximately 90.66 percent of staked vault share voting power — six days before the attack execution.
CoinDesk / SpotedCrypto23 August 2026
Term Finance governance exploit: attacker passes malicious proposals with 91–100 percent voting control across strategy vaults, withdrawing approximately 2,843 ETH and 1.68 million USDC ($8.5 million total). USDC swapped for DAI. PeckShield traces initial attacker funding to Tornado Cash.
The Block / CoinDesk24 August 2026
Term Labs publicly confirms the exploit, shuts down Meta Vaults permanently, revokes DAO governance roles, and states that core lending markets remain unaffected and withdrawals are preserved.
CryptonomistDecision Log
- hash: BXJTG6n53yqSzWpJmnVLSuq2CqDapgnQ6NfTv51qBhH4
- hash: Ad25RpqzNqBzEDkHE2yUvWdGqW27Bu4iNNMBFFgZwgqM
- hash: ZzGikF9SK4ABXimPUpYxU9ghkji4dWQea3WX8A4Nkms
This investigation is cryptographically anchored to the Solana blockchain (3 events). 19 of 20 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/26/2026, 11:23:53 PM
last updated: 9/1/2026, 4:58:32 AM
4 viewsavoid.net — verified advice for a post-truth world