BonkDAO said attackers used a malicious governance proposal to drain about $20 million in BONK tokens from its treasury, in what appears to be a governance-takeover attack rather than a smart-contract exploit. The organization said the perpetrators accumulated a large BONK position in advance, then used that voting power to approve a proposal that minted or transferred additional tokens to wallets under their control, affecting the BONK ecosystem on Solana and contributing to an approximately 7% price drop after disclosure.
BonkDAO said it identified exchange wallets allegedly used to acquire BONK before the proposal and has notified law enforcement while coordinating with exchanges, bridges, and the Solana Foundation to trace and recover funds. South Korean exchange Upbit temporarily suspended BONK deposits and withdrawals following the incident, while BonkDAO had not yet publicly identified a suspect or disclosed the precise governance mechanism, on-chain transaction hashes, or independent confirmation of the theft.

Track how attackers are adapting to this technology.
5 events from the most recent confirmed update back to the earliest known activity.
After draining BonkDAO's treasury, the attacker moved most of the stolen BONK into a multisig tied to a newly created shadow DAO dubbed 'BONK 2.0,' according to Chainalysis. The report also said the attacker sent about $188,000 to an exchange and began liquidating roughly $5.3 million in BONK used to secure voting power, while about $19 million remained in the new multisig.
Following the incident, South Korean exchange Upbit temporarily halted BONK deposits and withdrawals.
After identifying wallets tied to BONK purchases before the proposal, BonkDAO said it notified law enforcement and began coordinating with exchanges, bridges, and the Solana Foundation to recover funds and identify the perpetrators.
BonkDAO disclosed that attackers used a malicious governance proposal to mint or transfer roughly $20 million in BONK tokens to wallets they controlled. The organization said the incident was a governance-takeover style attack rather than a smart-contract vulnerability.
BonkDAO said the attackers built a large BONK position in advance, allegedly using identified exchange wallets to pre-position for influence over a governance vote.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
thedefiant.io
Open sourcetherecord.media
Open sourcethedefiant.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.