Back to News
机制解读By Mr.Xuan · 2026-08-08

Governance Attack Textbook: How BonkDAO Lost $19.3M with 2.9% Voting Rate

Governance Attack Textbook: How BonkDAO Lost $19.3M with 2.9% Voting Rate

Governance Attack Textbook: $19.3M Stolen with 2.9% Voting Rate

In August 2026, BonkDAO experienced a textbook governance attack:

  • Attacker bought only 1% BONK tokens
  • Embedded treasury transfer in a seemingly boring proposal
  • Passed with 2.9% voting rate
  • Successfully stole $19.3M

This case exposes DAO governance's fatal vulnerability: low voting rate = manipulatable.

1. Attack Process Reconstructed

Step 1: Buy Tokens Cheaply

Attacker quietly bought 1% of BONK tokens on the market. Since BONK's market cap was large, 1% cost was relatively low.

Step 2: Submit "Boring" Proposal

Attacker submitted a seemingly harmless proposal, like "update website domain" or "modify social media links." But in the detailed terms, embedded treasury fund transfer content.

Step 3: Exploit Low Voting Rate

Since the proposal seemed boring, most holders didn't vote. Final voting rate was only 2.9%, attacker controlled the result with 1% of tokens.

Step 4: Execute Transfer

After proposal passed, smart contract automatically executed treasury transfer, $19.3M was moved.

2. Why DAO Governance Is Vulnerable?

2.1 Voting Rates Generally Low

Most DAOs have voting rates below 10%. Reasons:

  • Holders don't care about governance (only care about price)
  • Voting requires gas fees (small holders unwilling to participate)
  • Too many proposals (information overload)

2.2 Insufficient Proposal Review

Most holders don't carefully read proposal details. Attackers exploit this by embedding malicious content in "boring" proposals.

2.3 Low Token Concentration

If tokens are distributed among many holders, attackers only need to buy small amounts to gain relative majority.

3. Other Historical Governance Attack Cases

ProjectTimeLossAttack Method
BonkDAOAug 2026$19.3MMalicious proposal passed with low voting rate
BeanstalkApr 2022$182MFlash loan + governance proposal
Rari CapitalMay 2022$80MGovernance proposal authorized transfer
Wormhole (governance-related)Feb 2022$320MValidator signature forgery

4. Why FunDAO Doesn't Need Voting?

FunDAO's mechanism design fundamentally eliminates governance attack possibilities:

4.1 Rules Fixed, Immutable

FunDAO's deflation rules, dividend rules, and circuit breaker rules are all written in smart contracts, immutable after deployment. No "proposal" mechanism means no room for governance attacks.

4.2 No Human Intervention

All operations are automatically executed by smart contracts — deflation auto-burns, dividends auto-distribute, circuit breakers auto-trigger. No one behind the scenes manipulating.

4.3 Ownership Renounced

Contract Owner permissions have been renounced, meaning no one can modify rules, transfer funds, or mint tokens. Even if someone wanted to launch a malicious proposal, there's no contract to execute it.

4.4 Circuit Breaker Protection

Even in extreme market conditions, FunDAO's circuit breaker mechanism auto-triggers to protect holders' interests. No vote needed — rules execute automatically.

5. What Should Investors Focus On?

Three Risk Signals in DAO Governance

  • Voting rate below 10% — Most people don't care, easily manipulated
  • Overly complex proposals — Deliberately hard to understand, hiding malicious content
  • Core team controls large token supply — Governance is just "fake democracy"

FunDAO's "No Governance" Advantage

DimensionTraditional DAOFunDAO
Rule ChangesCan be modified via proposalsImmutable, permanently fixed
Fund UsageVoted onAuto-executed by contract
Governance Attack RiskHigh (low voting rate = easy to manipulate)Zero (no governance mechanism)
Human InterventionProposal + vote = human decisionsFully automatic, no intervention
TransparencyVoting results verifiableAll operations on-chain verifiable

6. Core Conclusion

BonkDAO's $19.3M loss tells us: DAO governance is not a safety guarantee — it may be the biggest vulnerability.

When voting rate is only 2.9%, "decentralized governance" actually becomes "1% of people control 100% of funds."

FunDAO chose a different path: no governance needed because rules are fixed; no voting needed because contracts auto-execute. This is true decentralized security.

When choosing DeFi projects, investors should not only look at "whether there's DAO governance," but whether the governance mechanism truly protects holders, or just gives attackers an opportunity.