BonkDAO Governance Attack:
$20M Drained via Malicious Proposal
$20M in BONK was drained from BonkDAO through a malicious token-weighted governance proposal; attacker-linked wallets controlled 99.878% of the vote.

- Incident Date: July 6, 2026
- Target: BonkDAO
- Target Overview: BonkDAO is the Solana-based community governance organization responsible for managing a treasury supporting the BONK token ecosystem. Treasury actions are authorized through token-weighted on-chain governance.
- Total Loss: Approximately $20 million in BONK
- Reported Token Amount: Approximately 4.4 trillion BONK
- Reported Recipient Address:
9bxWkNf3BtJ6iehq9KbX9uCWMjem4TFiPZ19T2sYJHvQ - Attack Vector: Governance capture / malicious token-weighted proposal
Incident Review & Technical Details
1. Attack Path
- Voting power was accumulated before the proposal: BonkDAO said it identified exchange wallets used to purchase BONK before the malicious proposal was submitted. Independent reporting estimated that approximately $4 million in BONK was accumulated to build sufficient voting weight, although BonkDAO did not publish a final acquisition-cost figure.
- A treasury-moving proposal was submitted through normal governance: The attacker used BonkDAO's Realms governance process to submit Bonk Improvement Proposal #76, titled “Sowellian BonkDAO.” The proposal presented itself as a governance overhaul and included an instruction capable of moving treasury assets.
- Concentrated voting power approved the proposal: According to SlowMist founder Yu Xian's analysis, only seven addresses participated and attacker-linked addresses supplied 99.878% of the voting weight. The proposal therefore passed through the DAO's authorized token-weighted process rather than through a stolen key or an identified smart-contract exploit.
- The approved instruction transferred the treasury tokens: Reports based on Solana transaction data identified an approximately 4.4 trillion BONK transfer from the BonkDAO treasury to
9bxW...YJHvQ. BonkDAO valued the total drain at approximately $20 million. - The funds were moved to a second address: The first recipient wallet, reportedly funded through a Bybit-linked account, later transferred the BONK to another Solana address ending in
eh42. BonkDAO began coordinating with exchanges, bridges, and the Solana Foundation as the investigation continued.
2. Impact Scope
- Protocol-Level Loss: BonkDAO confirmed that approximately $20 million in BONK was drained from its treasury.
- Affected Component: The failure occurred in the governance and treasury-control process. Public reporting has not identified a private-key theft or conventional smart-contract vulnerability as the cause.
- Governance Concentration: The reported 99.878% attacker-linked voting share meant a nominally valid vote could authorize a treasury transfer without meaningful opposition from other participants.
- Market Impact: BONK fell by roughly 7%–9% after the disclosure, while the stolen token position created additional potential selling pressure.
- Exchange Response: Upbit and Kraken reportedly paused BONK deposits and withdrawals while the incident was investigated.
- Ecosystem Impact: The treasury loss may constrain future ecosystem grants, community programs, and token-burn initiatives until BonkDAO clarifies its remaining assets and recovery plan.
3. Official Statements
- BonkDAO: The organization described the event as a malicious governance proposal that drained an estimated $20 million in BONK. It said investigators had identified exchange wallets used to acquire BONK before the proposal.
- BonkDAO response: The team said it was working with exchanges, bridges, and the Solana Foundation to manage the incident, recover assets, and identify those responsible. Law enforcement was notified.
- Exchange actions: Upbit and Kraken were reported to have suspended BONK deposits and withdrawals as protective measures following the treasury drain.
4. Investigation Progress
The publicly documented trail links the governance proposal, the first recipient address ending in JHvQ, and a later transfer to an address ending in eh42. BonkDAO's identification of exchange wallets used during the pre-vote accumulation phase may give investigators access to account-registration and funding records through participating exchanges. No confirmed fund recovery or attacker attribution had been announced in the reviewed sources at the time of writing.
The final post-mortem should address the governance controls that failed to stop the proposal:
- Publish the complete proposal, vote-account list, voting-power calculation, execution transaction, treasury source address, and downstream recipient addresses.
- Explain the proposal threshold, quorum, voting period, execution delay, and any emergency veto or security-council authority active at the time.
- Add alerts for rapid governance-token accumulation, new-wallet voting concentration, low-participation proposals, and instructions that transfer a material share of treasury assets.
- Require an independently reviewed execution summary and a delay between approval and execution for high-value treasury proposals.
- Separate routine community governance from authority over treasury-critical instructions through spending caps, staged execution, and emergency cancellation controls.
AUTOSEC.DEV Solution
BonkDAO's loss shows that treasury governance must be designed as a privileged control system, not only as a token-holder voting interface.
- Security Strategy & Planning - The malicious proposal reportedly passed with attacker-linked wallets controlling 99.878% of the vote and then authorized a $20 million treasury transfer. AUTOSEC.DEV designs governance guardrails around proposal thresholds, quorum quality, voting-power concentration, execution delays, spending limits, independent review, and emergency cancellation so a formally valid vote cannot immediately become an irreversible treasury drain.
- Incident Response - BonkDAO identified exchange wallets used before the vote and traced the stolen BONK across multiple Solana addresses. AUTOSEC.DEV supports governance-event reconstruction, address clustering, exchange and bridge coordination, evidence preservation for law enforcement, and validation of containment measures before treasury authority is restored.