Key highlights:

  • BonkDAO lost $20 million through a governance exploit
  • An attacker spent about $4.4 million buying tokens to gain enough voting power
  • BONK dropped around 8% as the stolen funds began moving toward exchanges

The Solana-based memecoin BONK came under pressure late Monday after BonkDAO confirmed that its treasury had been drained in a governance attack worth at least $20 million.

This led to the coin falling about 8% as investors reacted to the news.

 

What makes this case interesting is that the attacker did not break into wallets or exploit a software bug. They used the DAO's own voting system to gain control of treasury funds.

According to blockchain investigators and BonkDAO, the attacker spent days building enough voting power before submitting and approving a proposal that moved billions of tokens out of the treasury.

BONK governance system was used against itself

BonkDAO operates as a decentralized autonomous organization. This basically means decisions are made through community voting rather than by the team itself.

Lookonchain shared on X that the attack actually started on June 30 when one anonymous wallet submitted a proposal that was aimed at changing governance. However, hidden right in the proposal was an instruction to transfer treasury funds to a wallet controlled by the attacker.

The entity needed enough voting power to reach the DAO's approval threshold to make the proposal pass.

Data shows the attacker spent $4 million to $4.4 million buying large amounts of BONK tokens. By July 6, they had bought enough voting influence to push the proposal through.

The proposal, titled "BIP #76 - Sowellian BonkDAO," passed with support from only seven wallets. More than 18,000 members did not participate in the vote.

BonkDAO malicious proposal

Source: Lookonchain

The final result was quite close. The proposal got support equal to 882.38 billion tokens. This is just above the required quorum of 879.95 billion. Once approved, the system automatically transferred 4.426 trillion BONK tokens, which were valued at $20 million, from the treasury to the attacker's wallet.

Selling pressure sends the token lower

The token reacted almost immediately after the news became public. Data shows that some of the stolen tokens were moved to exchanges right after the attack. $188,000 was moved to an exchange, while most of the remaining funds were transferred into a multisignature wallet.

Source: Lookonchain

The attacker also started selling the tokens they got to gain voting power, which was worth around $5.3 million. BONK had dropped more than 8% as of press time, erasing part of the rally it had enjoyed only days earlier. Right before the exploit, the token had rallied about 14% in just a day.

In the meantime, BonkDAO shared that it is working with exchanges, blockchain bridges, the Solana Foundation, security researchers, and law enforcement agencies to track and possibly get back the stolen funds.

"Law enforcement has been notified. BonkDAO continues to work with relevant parties to recover funds and identify those responsible," they wrote.

Another warning for the crypto industry

The new incident comes during a year that has continued to see a surge in crypto-related security breaches. Industry reports show us that 83 crypto exploits happened during the second quarter of 2026 alone, making Q2 the busiest quarter on record for hacking incidents. 

Meanwhile, blockchain security firm CertiK reported $1.3 billion in losses across 344 Web3 security incidents during the first half of the year.

Some security experts have come out to say that the reason why this happened is that BonkDAO does not employ protections commonly used by large DAOs. For example, execution delays that allow communities to review approved proposals before they take effect. 

Also, the DAO apparently does not have an emergency override mechanism that can stop suspicious transactions. Without these, the attacker was able to move from proposal approval to treasury transfer with no issues.