BonkDAO Lost $20M After an Attacker Bought His Way Into a Vote

iEXExchanger
BonkDAO Lost $20M After an Attacker Bought His Way Into a Vote

An attacker bought $4M in BONK tokens, reached quorum with just seven wallets, and drained $20 million from BonkDAO's treasury. The token fell 8.5%; Upbit froze deposits.

Whoever designed token-based governance never planned for voter apathy turning into a $20 million gift to a stranger. On July 6, that is exactly what happened to BonkDAO on Solana.

The attacker spent roughly $4 million buying up BONK tokens over several days, building a position just above the governance quorum threshold. When Bonk Improvement Proposal number 76 came to a vote — titled "Sowellian BonkDAO," calling for new council members and a treasury restructure — only seven wallets cast ballots out of more than 18,000 registered participants. The attacker controlled 99.878% of those votes and cleared quorum by fewer than three billion tokens. Minutes later, the smart contract automatically transferred 4.43 trillion BONK to the attacker's wallet. About $20 million, gone.

The math is brutal in its simplicity: $4 million in, $20 million out. And there is no protocol bug to point to. The vote was legitimate. Quorum was met. The contract executed exactly as written. That is what makes this attack so hard to unwind — there is no undo for a governance decision that followed the rules.

BONK slid roughly 8.5% after the news broke. South Korea's Upbit immediately suspended BONK deposits and withdrawals. BonkDAO says it has traced the attacker's exchange accounts and is cooperating with the Solana Foundation, crypto bridges, and law enforcement to recover the funds — though nothing has been returned yet.

The deeper issue is structural. Low participation in DAO votes is the norm across the industry, not the exception. Defenders of the model will point to delegation systems, time-locked execution, and higher participation minimums as fixes — tools that exist in mature DAOs like Compound and Aave. For BonkDAO, those tools came one governance proposal too late.

Questions and answers

Frequently asked questions about this article

What is a DAO governance attack?

An attacker legally buys enough governance tokens to gain voting power in a DAO, then passes a proposal that benefits them directly. There is no code exploit involved — the attack works entirely within the system's own rules.

How did the attacker accumulate enough votes?

He gradually bought BONK on exchanges, spending roughly $4 million. His position slightly exceeded the 879.95 billion token quorum threshold. Over 18,000 registered members did not vote, so his seven wallets were more than enough.

Can BonkDAO recover the stolen funds?

Recovery is difficult. BonkDAO has traced the attacker's exchange accounts and is working with the Solana Foundation and law enforcement. Upbit has frozen BONK operations. Some funds may be recovered through centralized exchanges, but since the transfer was technically legitimate, legal recourse is harder than in a typical hack.

How can DAOs defend against governance attacks?

Common defenses include timelocks — mandatory delays between a proposal passing and its execution — vote delegation so passive holders assign votes to active participants, higher quorum thresholds, and token lock-ups after voting. These are standard in mature protocols like Compound and Aave.