A "legal" robbery? Attackers emptied the BonkDAO treasury by buying tickets
Author: Chloe, ChainCatcher
In the early hours of July 6, 2026, the community governance organization BonkDAO of the Solana ecosystem meme coin BONK suffered a governance attack. The attacker emptied approximately 4.4 trillion BONK tokens from the treasury through a "legitimate" governance proposal. The most striking aspect of the entire incident was not any smart contract vulnerability, but rather that the attacker only spent about $4.4 million to "buy votes" in exchange for assets worth approximately $20 million, and every step from buying tokens, voting, to allocating funds was technically a completely valid transaction.
BonkDAO Suffers Governance Attack, Treasury Emptied of Approximately $20 Million
BonkDAO's official X account confirmed the attack on July 6, stating that it was a "malicious governance proposal," estimating that approximately $20 million worth of BONK was transferred from the treasury. As the stolen tokens quickly flowed to exchanges, market selling pressure emerged, causing the BONK price to drop by about 7% to 10% within 24 hours, falling to around $0.0000043, approximately 93% lower than its historical high of $0.000058.
The tokens transferred amounted to 4.4 trillion BONK. Due to varying valuations over time and from different sources, descriptions of the amount range from about $19.3 million to $21.2 million, generally summarized as "approximately $20 million."
BONK is a well-known dog meme coin launched on Solana in December 2022, famous for its large-scale community airdrop, and has long been regarded as one of the representative meme coins in the market, even being included in some ETFs.

Attack Mechanism: Proposal #76 "Sowellian BonkDAO" Contains Malicious Instructions
The core tool of the attack was a governance proposal titled "BIP #76 - Sowellian BonkDAO." On the surface, it advocated for the introduction of "Sowellian governance," replacement of committee members and directors, reconstruction, monetization of holdings, stop-loss measures, and a series of reform themes. Viewed in terms of wording, it resembled a passionate declaration rather than a governance motion, even stating the intention to "rebuild from the ashes, monetize holdings, and stop the bleeding," and promised that all participants who voted "yes" would be eligible to receive BONK token rewards.
The real issue lay in the actual execution instructions hidden beneath the proposal, which included a transfer that directly moved 4.43 trillion BONK into the attacker's wallet. This was the only action in the entire proposal that had substantive effects and was the true purpose set from the beginning; according to BonkDAO's explanation, this instruction to empty the treasury was buried in the second execution step, rather than being placed in the most conspicuous position, further reducing the likelihood of being easily spotted. In other words, this was a proposal for misappropriating funds, merely cloaked in the guise of governance reform.
Once the attacker used the purchased votes to pass the proposal, this instruction would be automatically executed on-chain without anyone needing to confirm it again. Therefore, the funds flowed directly into the attacker's wallet ending in "JHvQ" around 4 AM Eastern Time on July 6; as for the promised token rewards to the "yes" voters, they would, of course, not be distributed.

Attacker "Buys Votes" in Advance, Bypasses Community Monitoring
According to on-chain analyses from Chainalysis, Lookonchain, and others, the entire attack was a premeditated action lasting about a week:
As early as June 30, an anonymous wallet submitted this proposal on the governance platform, which required a minimum of 1% of the token supply to pass, approximately 879.95 billion BONK votes in favor.
Thus, on July 4 and 5, another wallet purchased approximately 882.38 billion BONK through the exchanges Bybit and Binance, spending about $4.4 million, just enough to accumulate the votes needed to surpass the threshold; according to Lookonchain, the attacker may have also borrowed more tokens through DeFi lending platforms. This series of actions was carried out through exchange wallets, allowing the attacker to quietly accumulate enough holdings to sway the voting outcome without the community noticing.

The final proposal passed by a very narrow margin: 882.38 billion votes in favor against the threshold of 879.95 billion, almost exactly equal to the holdings accumulated by the attacker over several days. Even more noteworthy was the voting structure itself: only 7 wallets voted, while over 18,000 members did not participate at all, resulting in a voting rate of only about 2.9%, yet the "yes" proportion was as high as 99.9%. In other words, this so-called "community consensus" was essentially just an agreement reached by the attacker with themselves.
After emptying the treasury, the attacker handled the tokens in two completely different ways.
For the approximately $20 million worth of BONK stolen from the treasury, the attacker did not immediately liquidate the majority. According to Chainalysis, about 9 hours after the theft, only about $188,000 was sent to exchanges (possibly for liquidation), while the remaining approximately $19 million was transferred to a "multi-signature wallet" that required multiple approvals for custody; during this time, the funds were also temporarily transferred to another address ending in "eh42."
For the batch of BONK initially purchased to buy votes, the attacker was eager to sell: about an hour after emptying the treasury, they began to sell this batch of tokens, liquidating approximately $5.3 million. In other words, they kept the stolen treasury tokens but quickly disposed of the holdings used to seize the treasury.
Exchanges and officials responded immediately. Upbit and Kraken suspended the deposit and withdrawal of BONK following security incident protocols; BonkDAO officials stated they had reported the incident to law enforcement and locked the exchange wallets used by the attacker to buy tokens before voting, and were collaborating with exchanges, cross-chain bridges, and the Solana Foundation to recover funds and clarify responsibility.
Conclusion
This incident has reignited an old debate. Since every step—buying tokens, voting, allocating funds—was technically a legitimate and valid transaction, some on-chain observers believe that the attacker merely exploited a weak governance design rather than "breaking in"; however, BonkDAO and several analytical institutions still clearly define it as an attack, and the involvement of law enforcement reflects this stance.
On-chain governance was once hailed as the future of community autonomy, symbolizing the ideal of having token holders, rather than corporate executives, decide the direction of funds. However, the BonkDAO incident highlights a core issue in the crypto industry: handing the keys to the treasury over to a public vote where "anyone can spend money to participate," without sufficient oversight mechanisms—such as substantive review of proposal content, higher passing thresholds, or time locks and manual reviews before allocations—can turn even the most legitimate governance ideals into tools readily exploited by attackers.












