Loading IndicatorLoading Indicator

PiCK

Bonk DAO Governance Attack Drains $20 Million, Sends Meme Coin Down 18%

Doohyun Hwang

Summary

  • About $20 million in tokens was stolen after governance voting at Solana meme coin Bonk (BONK) was exploited, sending the price down 18%.
  • The attacker used Proposal BIP #76, hidden smart-contract code and large-scale token buying to dominate the vote and transfer about 5% of total supply (4.426 trillion tokens) through a legitimate process.
  • The incident has fueled debate over wire fraud, Bonk’s report to judicial authorities, the Mango Markets precedent and the need for tighter DeFi governance and regulation.

Forecast Trend Report by Period

Loading IndicatorLoading Indicator

DAO voting rules exploited in $20 million drain

Bonk tumbles 18% in one day

Debate grows over whether deceptive proposal constitutes fraud


Photo: Shutterstock
Photo: Shutterstock

A major theft struck Bonk, a leading meme coin in the Solana ecosystem, after an attacker exploited the decentralized autonomous organization’s governance voting system to siphon off about $20 million in tokens. Because the scheme used a formally valid voting process and concentrated voting power through capital, the incident laid bare weaknesses in decentralized decision-making structures.

On July 6, Bonk DAO said a malicious governance proposal, BIP #76, drained about 4.426 trillion tokens from its community vault. That was roughly 5% of Bonk’s total supply of 87.99 trillion tokens. The tokens were funneled to a single wallet, jolting the market. Bonk, which had traded around $0.0000049 before the incident, plunged about 18% immediately after the news broke.

Smart-contract loophole used to steal $20 million

Photo: Bonk DAO
Photo: Bonk DAO

The attack was carefully planned. On June 30, the attacker submitted a proposal titled “BIP #76 - Sowellian BonkDAO.” It was presented as a plan to introduce a so-called Sowellian governance model, create new members and committees, rebuild the DAO, and liquidate holdings to prevent further losses. The proposal also promised token rewards to anyone who voted yes, drawing in retail investors.

The attacker also concealed a smart-contract execution command that transferred tokens to a specific wallet within the proposal’s surface-level language. The person then bought about 88.23 billion tokens on major crypto exchanges including Binance and Bybit to secure voting power.

That holding easily overwhelmed the 710 million votes cast against the measure and pushed it through. Just 49 seconds after voting ended on July 6, 4.426 trillion tokens were moved to the attacker’s wallet. The fee for stealing the $20 million was just 0.000105 SOL. The attacker then withdrew the tokens used in the vote. No action was taken to stop the proposal even though it had been posted for six days.

Weak settings in Bonk DAO’s governance system also played a role. At the time, the quorum requirement was only 1% of total supply. There was no timelock function to delay execution after passage, and liquid tokens that had not been staked could still be used for voting. In the end, tokens worth about $14 million were transferred to the attacker through a legitimate voting process.

Fraud or lawful transaction?

As the fallout grew, Bonk said it had reported the case to judicial authorities and was working with crypto exchanges and the Solana Foundation to track the funds. The incident has also reignited debate in legal and industry circles over the gray area surrounding decentralized finance ecosystems run purely by code. The central question is whether the theft can be prosecuted as wire fraud under US federal law.

A wire-fraud case requires proof of intent to deceive and a material false statement. Views in the industry are split. Supporters of prosecution argue that the proposal’s stated plan to introduce Sowellian governance referred to a named, identifiable system rather than a loose idea. Because the execution code included no instructions for building that governance structure, they say the proposal amounted to a clear false promise. Under that view, the defense that the code executed transparently as written tells only half the story because the proposal itself was designed to mislead investors.

Others argue that a fraud case would be difficult to make. The attacker had already secured enough voting power through advance purchases to pass the proposal alone. That could make it legally difficult to prove causation — whether the misleading language actually caused the fund transfer or was merely ornamental wording that did not affect the outcome.

The biggest variable may be the precedent from the Mango Markets case. In that incident, Avraham Eisenberg inflated the price of the Mango token through futures trading and then took about $110 million in crypto assets using it as collateral. His initial guilty verdict was later overturned, and he was ultimately acquitted. The court found insufficient evidence of falsity because Mango Markets had no explicit borrowing guidelines or terms of use. The ruling did not mean code exploits are legal in themselves. Rather, it said legal deception is difficult to establish without clearly written rules or promises.

An industry official said the case raised fresh questions about how code-based decentralized ecosystems should be regulated under the law. Regulatory changes are urgently needed to prevent what amounts to legally engineered fraud exploiting smart-contract loopholes, the person added.

#DAO Governance
#Incidents
#Memecoin
Doohyun Hwang

Doohyun Hwang

cow5361@bloomingbit.ioKEEP CALM AND HODL🍀

What do you think about this news?








PiCK News






Hashtag News