No hack. No exploit. No stolen keys. An attacker bought enough BONK to pass a governance proposal, voted “yes” to send the DAO’s $20 million treasury to their own wallet, and the code did exactly what it was told. The only opposition was six people holding $3,762 between them.
Every few months crypto invents a new way to lose money, and this one might be the most darkly elegant yet. Because nobody broke into BonkDAO. There was no clever bit of code, no phishing link, no compromised private key. The attacker just… used the rules. Correctly. And the rules handed over $20 million.
Here’s how you ‘legally’ rob a DAO.
The heist, step by step
On June 30, an anonymous wallet submitted a governance proposal to BonkDAO, the treasury behind the Solana memecoin BONK. The proposal, cheerfully titled “Sowellian BonkDAO,” pitched itself as a plan to “rebuild from the ashes” and “stop the bleeding.” What it actually did, buried in the instructions, was authorise a transfer of 4.4 trillion BONK, the treasury’s holdings, to a wallet the proposer controlled.
For a proposal to pass, it needed “yes” votes equal to just 1% of BONK’s supply. That’s the quorum. So over July 4 and 5, per Lookonchain, a second wallet went shopping. It spent around $4.4 million buying BONK on Bybit and Binance, accumulating just enough to clear that 1% bar. Then it voted yes with the entire stack.
The whole thing, on-chain, in daylight.
The proposal passed with seven wallets voting, against more than 18,000 members who didn’t. Turnout: 2.9%. It cleared the threshold by a hair: 882.38 billion BONK in favour against an 879.95 billion requirement, almost exactly the pile the attacker had spent two days assembling. The “99.9% yes” result was, functionally, one person nodding at their own idea.
The timelock, the delay that would have let anyone notice and react, was set to zero. So within one minute of voting closing on July 6, the proposal executed itself and 4.4 trillion BONK left the treasury. Then the attacker withdrew their vote and unstaked the BONK they’d bought. Total profit, by Lookonchain’s maths: $16.8 million on a $4.4 million outlay.
The detail that says everything
You can read the full mechanics above and still not feel it until you see the opposition.
The attacker spent $4.4 million to win this vote. The community that voted against them, the resistance, the last line of defence for a $20 million treasury, was six wallets holding a combined $3,762 of BONK.
$4.4 million versus $3,762. It was not a close game.
That’s not a robbery. That’s a walkover. Somewhere in there is the entire promise and the entire problem of on-chain governance in a single ratio.
Is it even theft?
Here’s where it gets genuinely philosophical, and why the trenches can’t stop arguing about it. Every single step was a valid, permitted transaction. Nobody bypassed anything. The attacker bought tokens anyone could buy, submitted a proposal anyone could submit, and voted exactly as the system allows. The code ran flawlessly. By the letter of the protocol, this wasn’t an exploit at all. It was participation.
And plenty of people are pointing exactly that out.
He’s not entirely wrong, and that’s the uncomfortable part.
The argument goes like this: someone legitimately bought a lot of tokens, proposed a vote, the vote passed with almost no opposition, and the proposal executed. Where, exactly, is the crime? If a DAO’s whole premise is that token-holders decide by vote, then the token-holders decided by vote. The system didn’t fail. It ran.
BonkDAO, understandably, does not see it that way. It’s called the incident a “malicious governance proposal,” said it’s identified the exchange wallets used to buy the voting power, and confirmed it’s working with exchanges, bridges, the Solana Foundation and law enforcement to trace the funds.
The treasury’s official position: this was an attack, not a vote.
Upbit and Kraken have both paused BONK deposits and withdrawals. Around $148,000 of the stolen BONK has already been traced moving to OKX, per PeckShield, with the rest sitting in a wallet ending eh42. BONK’s price fell roughly 9% on the news.
So the law will likely treat it as theft, because intent obviously matters and “I followed the rules” is not a defence a courtroom accepts. But on-chain, in the place where the whole point was that code is law and the rules are the rules, the attacker has a genuinely uncomfortable argument: they didn’t break the system. They read it more carefully than anyone else.
The lesson nobody in a DAO wants to hear
This wasn’t a BONK-specific flaw. It’s a design pattern sitting under a huge share of token-weighted governance: if voter turnout is low, if there’s no timelock to catch anomalies, and if there’s no multisig backstop for emergencies, then a treasury isn’t protected by its community. It’s protected by the price of a temporary voting majority. And for BonkDAO, that price turned out to be $4.4 million for a $20 million prize, a trade any rational thief takes all day.
Governance attacks are rising for exactly this reason. They need less technical skill than a smart-contract exploit, the tokens are just sitting on exchanges waiting to be bought, and the “vulnerability” is the voting system working as designed. The uncomfortable truth is that a lot of DAO treasuries are one quiet accumulation away from the same afternoon.
The old slogan was code is law. This week, someone read the law, found it fully enforceable, and enforced it right into their own wallet. The treasury was on-chain, transparent, and decentralised. It was also, apparently, for sale.
18,000 DAO members. Six of them showed up.
Figures are from BonkDAO’s public statements and on-chain analysis by Lookonchain, PeckShield and others at the time of writing; funds have not been recovered and the investigation is ongoing. Whether this constitutes theft or rule-exploitation is genuinely disputed on-chain and is a matter for the relevant authorities. Nothing here is financial advice, and no, buying a DAO is not a recognised investment strategy.