BonkDAO governance exploit illustration showing a BONK treasury vault drained through a malicious DAO proposal.
Image by CryptoSlate

BonkDAO’s treasury raided for $20M due to lack of governance interest

The malicious proposal shows how token-weighted votes can become a treasury access path when DAO review controls are too thin.

Quick Take

  1. BonkDAO says a malicious governance proposal drained about $20 million worth of BONK from its treasury.
  2. The incident turns token-weighted voting into a treasury security risk for DAOs holding liquid memecoin reserves.
  3. Investigators are tracing exchange wallets, while BonkDAO weighs tighter controls like timelocks and review windows.

BonkDAO said a governance proposal drained about $20 million in BONK from its treasury, exposing how DAO votes can become a path to treasury funds.

The group behind BONK said the proposal was malicious and that investigators had identified exchange wallets that had been used to buy BONK ahead of the vote.

It added that investigators had identified exchange wallets used to buy BONK ahead of the proposal and that the DAO was working with exchanges, bridges, the Solana Foundation, and law enforcement to manage the aftermath and pursue recovery.

The disclosed path points to the vote itself as a security boundary: a proposal moving through the DAO's own decision system, with treasury assets on the other side.

For DAOs with liquid treasuries, participation levels and execution delays become core security controls.

Flow diagram showing how BonkDAO's estimated $20 million treasury drain moved from BONK accumulation to a malicious proposal, vote execution, recovery response, and DAO governance safeguards.

Related Reading

Build Finance DAO hostile takeover, treasury drained

Why governance became the attack surface

Attackers reportedly gathered about $4 million in BONK before the proposal.

Wu Blockchain post reported the vote-weight details, including a small number of voting addresses and an overwhelming amount of attacker-linked voting power.

The problem is clear. If a DAO treasury can be reached through token-weighted approval alone, an attacker can bypass many technical defenses by gathering enough influence, achieving low participation, and using a proposal path that allows a vote to become execution before the community or signers can stop it.

BonkDAO's own background material describes it as the decentralized arm of BONK with a substantial BONK-denominated treasury and a mission to fund BONK utility, Solana public goods, and ecosystem projects.

Related Reading

Solana-based memecoin BONK adds $1B to market cap following exchange listings

The loss could therefore affect resources available for grants, integrations, community programs, and the credibility of the governance model itself.

The next security test for memecoin DAOs is as much operational as it is technical. Large treasury movements may face more pressure to sit behind timelocks, higher quorum thresholds, voting-concentration alerts, proposal review windows, multisig or council checkpoints, and separated treasury buckets that limit how much a single vote can move.

Related Reading

Crypto hacks hit a record count but the biggest threat isn’t smart contracts

Those controls reduce the promise of instant, frictionless community execution. After BonkDAO, that friction may be the point.

A DAO treasury is only as decentralized as its voting, and only as secure as the delay, review, and failure points between a vote and the funds.

Article context

Mentioned in this article

Related Asset Solana SOL $95.23 24-hour change: up 0.89%