BONK Faces $20M Treasury Threat After Attacker Spends $4M to Pass Malicious Proposal

Quick Reads:
- Attacker spent ~$4.4 million buying BONK to hit the 1% quorum needed to pass a proposal
- “BIP #76” passed with just 7 wallets voting yes against 18,000+ inactive members
- $20 million in treasury tokens moved to the attacker’s wallet on July 6
- ~$188,000 already cashed out; remaining ~$19 million parked in a multisig wallet
- BONK price down 7% in 24 hours following the news
The BONK treasury drain has become the latest cautionary tale in crypto governance, after an attacker legally and quietly bought their way into control of a DAO vote, then walked away with roughly $20 million in stolen tokens.
The Solana-based memecoin’s decentralized autonomous organization, BONK DAO, confirmed late Monday that its treasury had been drained through a malicious governance proposal. Unlike a typical hack involving stolen keys or exploited code, this BONK treasury drain relied entirely on legitimate, onchain transactions, buying tokens, casting a vote, and executing a payout that the system itself approved.
It began on June 30, when an anonymous wallet submitted a proposal, later titled “BIP #76 – Sowellian BonkDAO”, that would transfer treasury holdings to a wallet it controlled. To pass, the proposal needed yes votes equal to just 1% of BONK’s total supply, the quorum threshold set for the DAO. Over July 4 and 5, a separate wallet spent about $4.4 million buying BONK tokens on Bybit and Binance, reportedly supplementing the purchase with borrowed funds from DeFi lending platforms, according to blockchain analytics firm Lookonchain.
By July 6, that wallet held exactly enough tokens to tip the vote. The proposal passed with a razor-thin margin, 882.38 billion BONK in favor against an 879.95 billion threshold, with only seven wallets voting out of more than 18,000 DAO members, a turnout of just 2.9%. The “yes” result came in at 99.9%, effectively one voter agreeing with itself.
Shortly after the vote passed, about $20 million in BONK automatically left the treasury for the attacker’s wallet, as confirmed by Chainalysis. Nine hours later, roughly $188,000 was moved to an exchange, likely to begin cashing out, while the remaining $19 million was routed to a multisig wallet requiring multiple approvals to access. The attacker also began offloading the BONK tokens bought to engineer the vote, selling around $5.3 million worth within an hour of the drain, keeping the stolen treasury funds but liquidating the position used to steal them.
BONK DAO has since confirmed the attack publicly, saying it has identified the exchange wallets used ahead of the vote and is working with exchanges, bridges, and the Solana Foundation to contain the fallout. BONK’s price fell 7% in the 24 hours following the incident.
The episode has reignited a familiar debate in crypto circles: since every step of the attack was a valid onchain transaction, some observers argue the attacker simply exploited a poorly designed governance system rather than committing outright theft. BONK DAO and analytics firms, however, are treating it as an attack, a distinction reflected in the involvement of blockchain forensics teams and law enforcement.
Whichever side of that argument one takes, the lesson from the BONK treasury drain is hard to ignore: a treasury guarded only by a public vote is only as secure as the cost of buying a majority, and in this case, that cost was far cheaper than the prize.





