h hoge.gg
Subscribe
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
● Security & Exploits

Governance Attacks in 2026: When the Vote Is the Exploit

In 2026, attackers stopped breaking DAO code and started buying the votes instead. From BonkDAO's $20 million minute to Beanstalk's $182 million flash loan, governance itself became the exploit.

On July 6, 2026, someone spent about four million dollars, followed the rules exactly, and walked out of a decentralized autonomous organization with roughly twenty million dollars in tokens. No smart contract was broken. No private key was stolen. No server was breached. The attacker bought a pile of BONK, used it to control almost the entirety of a seven-wallet vote, and let the DAO’s own code hand over the treasury. When it was over, the on-chain record showed a proposal that passed with 99.878 percent support, an execution that ran without a single error, and a treasury that was suddenly much lighter, according to a breakdown published by crypto.news.

This is a governance attack, and in 2026 it has become one of the most uncomfortable categories in crypto security, precisely because it so rarely looks like a crime. The other exploits in this cluster involve something obviously wrong: a reentrancy bug, a spoofed address, a leaked key. A governance attack uses the protocol as intended. The votes are real, the quorum is met, the transaction is valid. The only thing that went wrong is that the people who wrote the rules never imagined anyone would follow them all the way to this conclusion. This piece walks through what a governance attack actually is, the 2026 wave that put a dollar price on a DAO vote, the historical cases that defined the category, the legal gray zone where following the rules may not be a crime, and the defenses that genuinely work.

What a governance attack actually is

A DAO hands control of a protocol to token-weighted voting. Depending on the design, the vote can move a treasury, mint new tokens, swap out an oracle, change a fee, or upgrade the code that runs the whole thing. A governance attack is what happens when an actor acquires enough of that voting power to pass a proposal that benefits them at the protocol’s expense, then lets the governance machinery execute it on their behalf. The distinction from a conventional exploit matters: in a smart-contract hack, the code does something its authors did not intend. In a governance attack, the code does exactly what it was told. The exploit is the governance, not the bug.

Security firms have started treating governance as a first-class attack surface rather than an afterthought. Broadly, the attacks fall into four shapes. The first is vote acquisition, where the attacker simply buys or borrows a controlling stake. The second is the malicious payload, where a proposal looks benign but carries a hidden action. The third is the hostile takeover of admin or mint keys, where a single proposal transfers the crown jewels. The fourth is legal capture, where a well-funded bloc steers emissions or the treasury toward itself without ever breaking a rule. What unites them is that nothing is technically hacked, which puts them in the same awkward family as address poisoning, another 2026 exploit where the victim’s own valid actions do the damage. The blockchain security company Blockaid counted at least seven governance takeovers between June and August 2026, with roughly twenty-two million dollars drained across them.

The 2026 wave that put a price on a DAO vote

What makes 2026 different is not that governance attacks are new, but that they have become routine, cheap, and openly transactional. The BonkDAO drain was the clearest example. On July 6, an attacker bought roughly one percent of the BONK supply for about four million dollars, which was enough to control 99.878 percent of a vote in which only seven wallets participated, then passed a proposal that sent about twenty million dollars out of the treasury. There was no meaningful quorum requirement and no timelock, so by the time anyone noticed, the transfer had already settled. As crypto.news put it bluntly, someone spent about four million dollars, controlled almost the whole of a seven-wallet vote, and legally walked off with twenty million from the DAO’s treasury.

Weeks later, in late August 2026, the Ethereum lending protocol Term Finance lost about eight and a half million dollars to the same basic move. According to The Crypto Times, the attacker used just two ETH routed through Tornado Cash to accumulate a majority of a thinly held governance token, then passed proposals that seized control of Term’s vaults and drained 2,843 ETH and 1.68 million dollars in USDC, later swapped for DAI. The loss came to about 68 percent of the roughly 12.45 million dollars the protocol held, and while the affected strategy vaults ran on Yearn V3 infrastructure, Yearn said the hole was in Term’s custom governance layer, not its standard vaults. The blockchain analytics firms PeckShield and CertiK both confirmed the incident.

Not every attempt succeeds. In August 2026, Binance’s security team said its monitoring flagged a suspicious DAO governance proposal apparently designed to capture a treasury worth about 1.2 million dollars, with fewer than 48 hours left before it could take effect. The near-miss is instructive: the same automation that makes on-chain governance efficient also removes the human review that might otherwise catch a malicious proposal before execution. The through-line across all of them, from a meme-coin treasury to a lending vault, is the same soft underbelly that has been reshaping crypto risk all year, one HOGE Wire traced in its account of how DeFi lending broke in 2026: control has become the thing worth stealing, and control is for sale.

TargetWhenLossHow control was wonWhat the vote executed
Beanstalk FarmsApril 2022~$182M$1B Aave flash loan bought ~67% of votes in one transactionDrained the entire protocol treasury
Build FinanceFebruary 2022~$470KQuietly accumulated BUILD until a proposal passedSeized mint keys, minted BUILD, drained liquidity
Tornado CashMay 2023~$2.2MMalicious proposal self-minted ~1.2M votesTook governance, drained TORN from the vault
BonkDAOJuly 2026~$20MBought ~1% of supply for ~$4M, controlled a 7-wallet voteTransferred the treasury
Term FinanceAugust 2026~$8.5MBought a majority of a thin governance token (2 ETH via Tornado Cash)Seized the vaults, drained ETH and USDC

Anatomy of a takeover: the four-step playbook

Strip the cases down and nearly all of them follow the same four steps.

  1. Acquire voting power cheaply. Buy the token on the open market, borrow it for a single block with a flash loan, or exploit a thin float where a small absolute stake is a large share of the votes actually cast.
  2. Submit a proposal. Where scrutiny is low, the proposal can be openly extractive, meaning it simply sends the treasury somewhere. Where scrutiny is higher, the proposal is disguised to look identical to a benign one.
  3. Meet quorum. This is usually the easy part, because quorum is measured against votes cast, not against the full membership, and turnout in most DAOs is dismal.
  4. Let it execute. On-chain governance auto-executes an approved proposal. Without a timelock, execution is instant and irreversible.

The economics are the whole story. An attack is profitable whenever the cost of acquiring control is less than the value that control can extract. When a treasury holds twenty million dollars and one percent of a cheap token buys a decisive share of a near-empty vote, the arithmetic is not close. Low turnout is the silent enabler, because a quorum threshold that sounds strict on paper collapses when almost no one shows up. Governance, in the end, is a fight over who gets paid, the same dynamic HOGE Wire has documented inside Bittensor’s Yuma Consensus, where the mechanics of who receives emissions are themselves the object of a years-long power struggle.

Beanstalk: how a billion-dollar loan drained $182 million in a minute

The Beanstalk exploit of April 17, 2022 remains the textbook flash-loan governance attack, and it is still the largest by dollar value. Days earlier, the attacker had seeded two governance proposals, BIP-18 and BIP-19, dressed up as donations to Ukraine, which lulled the community into treating them as harmless. On execution day, the attacker borrowed about one billion dollars in DAI, USDC, and USDT from Aave, converted the funds into Beanstalk’s governance token in a single transaction, and instantly controlled roughly two-thirds of the vote. That was enough to pass a malicious proposal transferring the protocol’s assets to the attacker, who then repaid the flash loan and kept the difference. Beanstalk lost about 182 million dollars, and the attacker netted roughly 76 million after settling the loan, as CoinDesk reported at the time.

The fatal flaw was that Beanstalk counted a voter’s power in the same transaction the vote was cast, with no flash-loan-resistant snapshot and an emergency-execution path that let a supermajority proposal run immediately. Same-block voting power is the vulnerability the entire defensive playbook has been built to close ever since. It is why serious DAOs now snapshot voting power from an earlier block, and why vote-escrow designs that lock tokens for years exist at all: if you cannot borrow a majority for a single block, the flash-loan express stops running.

Tornado Cash: the malicious proposal with a hidden trapdoor

The Tornado Cash governance attack of May 20, 2023 used a different vector, and it is the reason experienced voters now insist on reading what a proposal’s code does, not what its description claims. Rather than buy votes, the attacker smuggled a payload. The malicious proposal was made to look identical to a previously approved one, so voters trusted it and passed it. But the deployed logic contract contained a hidden self-destruct function, and through a delegate call the attacker swapped in malicious logic that granted 10,000 votes to each of a set of controlled addresses, about 1.2 million votes in total, far more than the legitimate votes then in circulation. That handed the attacker total control of governance, which was used to drain 483,000 TORN, worth roughly 2.2 million dollars at the time, from the governance vault. Security firm Halborn published a technical teardown of exactly how the hidden logic worked.

Then the story turned strange. Having seized the protocol, the attacker submitted Proposal 21 to restore normal governance and set their own inflated voting balance back to zero, and the community passed it. The episode is a warning about delegated execution as an attack surface, the same broad class of risk that makes account delegation such a double-edged upgrade elsewhere in the stack, a tension HOGE Wire examined in its look at EIP-7702’s dark side. A proposal is only as trustworthy as the exact bytecode it will run, and a delegate call to attacker-controlled logic is a backdoor that no amount of quorum will close.

BonkDAO and Term Finance, up close

The two flagship attacks of 2026 sit at opposite ends of subtlety while sharing the same DNA. BonkDAO was brute force. There was no clever payload and no disguise, because none was needed: quorum was a formality, there was no meaningful timelock, and the proposal simply moved the treasury. The attacker bought roughly one percent of the supply on the open market, showed up to a vote where almost no one else did, and executed. Term Finance was surgical. The attacker spent only about two ETH, routed through Tornado Cash to obscure the trail, to buy a controlling share of a thinly held governance token, then passed proposals that seized the vaults directly. Yearn was careful to note that its standard V3 vaults were unaffected and that the weakness lived in Term’s bespoke governance, a distinction that matters for every protocol bolting a custom voting layer onto shared infrastructure.

Different budgets, different targets, one recipe: a low float, a low turnout, and fast or nonexistent execution delay. The table below lines the two up.

MetricBonkDAOTerm Finance
DateJuly 6, 2026Late August 2026
Reported loss~$20 million~$8.5 million
Cost to attacker~$4 million in BONK~2 ETH via Tornado Cash
Vote acquisition~1% of supply, open marketMajority of a thin governance token
Turnout7 wallets; 99.878% controlledSparse; attacker held the majority
TimelockNo meaningful delayNo effective delay on vault control
Assets takenBONK from the treasury2,843 ETH and $1.68M USDC (to DAI)
Confirmed bycrypto.news, BlockaidPeckShield, CertiK

Steem versus Hive: the takeover that used your exchange balance

Long before flash loans, the archetype of a governance takeover played out on a social blockchain. In February 2020, Justin Sun’s Tron acquired Steemit, the flagship app on the Steem chain, and with it a large pre-mined stake the community had long treated as off-limits. Fearing that stake would be turned against them, Steem’s node operators executed a soft fork to freeze it. The response, around March 2, is the part that still gets cited in security circles: three major exchanges, Binance, Huobi, and Poloniex, staked their customers’ deposited STEEM to vote out the community’s elected witnesses, then hastily withdrew the votes claiming they had not understood what they were backing. The community’s answer was the nuclear option in governance, exit: they hard-forked to a new chain called Hive on March 20 with a one-for-one airdrop that pointedly excluded the Steemit stake and the accounts that had proxied to it, as CoinDesk chronicled.

The lesson has aged well. When an exchange custodies a governance token, it holds your vote, and delegated-proof-of-stake designs concentrate that power further. Steem predates the DeFi flash-loan era, yet it rhymes with everything that came after: whoever can assemble the stake, by purchase or by borrowing someone else’s coins, controls the outcome. And when capture becomes unavoidable, forking away is the only defense that cannot be voted down.

Build Finance and Compound’s Golden Boys: theft versus capture

Two cases mark the ends of a spectrum from outright theft to legal capture. Build Finance DAO, in February 2022, was theft. A user operating as Suho.eth quietly accumulated the BUILD token, then passed a proposal handing over full control of the governance contract, the minting keys, and the treasury. With the keys in hand, the attacker minted 1.1 million BUILD, drained the liquidity pools on Balancer and Uniswap, took 130,000 METRIC from the treasury and sold it, then minted a further billion BUILD for good measure, netting the equivalent of about 160 ETH, or roughly 470,000 dollars. The founders could only watch and warn of a hostile governance takeover, because there was no timelock and no circuit breaker, as Decrypt reported.

Compound’s Golden Boys episode, in July 2024, was capture, and it never involved a bug at all. A voting bloc associated with a whale known as Humpy narrowly passed Proposal 289, by 682,191 votes to 633,636, to route 499,000 COMP, worth around twenty-four million dollars, into a wrapped goldCOMP vault the group would steer. Michael Lewellen, a security advisor for Compound, publicly warned that several accounts had been amassing COMP specifically to swing votes toward the proposal, framing it as a governance attack in all but name. After the backlash, Humpy agreed to rescind the proposal in exchange for a sanctioned staking product that would distribute 30 percent of Compound’s reserves to staked COMP holders. No rule was broken; a well-capitalized bloc simply used the rules, which is exactly what makes capture harder to police than theft.

The institutionalized version of vote-buying is the Curve wars. Curve’s vote-escrow model, veCRV, requires locking tokens for up to four years for voting power that decays over time, which binds voters to long-term exposure and, usefully, makes one-block flash-loan capture impossible. But it did nothing to stop bribery. Convex Finance aggregated veCRV until it held more than half the voting power and became known as the Curve kingmaker, and marketplaces like Votium, launched in September 2021, and later Hidden Hand turned vote-buying into an open market where protocols pay roughly 0.50 to 1.50 dollars for every dollar of emissions they can direct, as ChainCatcher has documented. Vote-escrow defeats the flash loan; it does not defeat the checkbook.

Is a governance attack even a crime? The Mango precedent

The most consequential legal ruling for this whole category came out of a case that was only partly a governance attack. In October 2022, the trader Avraham Eisenberg extracted about 110 million dollars from Mango Markets by manipulating the price oracle for the MNGO perpetual, inflating his own collateral, and borrowing the treasury dry. He then used his MNGO holdings to vote on a DAO proposal over how much to give back, keeping a chunk as a self-declared bounty, and publicly called the whole thing a highly profitable and legal trading strategy. A jury convicted him in 2024, but in May 2025 US District Judge Arun Subramanian vacated the convictions, finding both that New York was the wrong venue, since Eisenberg traded from Puerto Rico, and, more damaging for prosecutors, that an automated smart contract could not have been the target of a false representation. You cannot, in that reasoning, deceive code.

Prosecutors have appealed, arguing the ruling would unsettle traditional understandings of fraud, and Eisenberg remains imprisoned on unrelated charges. But the takeaway for governance attacks is stark. If following a protocol’s published rules is not fraud, and the victim is code that executed as written, then the deterrence-by-prosecution model has a hole in it. In the United States, prosecutors and the SEC have leaned on wire fraud, commodities fraud, and market-manipulation theories, and the SEC and CFTC both brought civil cases against Eisenberg framing the maneuver as manipulation. Yet the code-did-what-it-was-told defense now has a district-court ruling behind it, under appeal though it is. For anyone building a DAO, the message is that the fix cannot wait on the courts; it has to be technical and structural, built into the governance itself.

Why coin voting is the attack surface

Every case here rhymes because they share a root cause, and Ethereum co-founder Vitalik Buterin named it years ago. In his essay on moving beyond coin-voting governance, he argued that a token in a coin-voting protocol is a bundle of two separate rights, economic exposure and the right to vote, and that these are very easy to unbundle from each other through lending, wrapper contracts, or centralized exchanges. Once the vote can be rented apart from the risk, votes become cheap to buy. Worse, an attacker who bribes or borrows a majority captures the entire benefit of a corrupt decision while bearing only their proportional share of the resulting harm, a tragedy of the commons baked directly into one-token-one-vote.

Layered on top is plutocracy in the ordinary sense. Whales dominate, small holders are rationally apathetic, turnout craters, and quorum becomes trivial to meet. That is the mechanism that turned a seven-wallet vote into a twenty-million-dollar payout at BonkDAO. Buterin’s proposed directions point away from pure coin voting: non-token signals, proof-of-personhood, skin-in-the-game designs that punish bad decisions, and, above all, limiting how much a vote is allowed to do in the first place. That last idea, governance minimization, is the one the strongest protocols have quietly embraced, because a treasury a vote cannot touch is a treasury a vote cannot steal.

The defender’s playbook: what actually works

No single control stops a governance attack, but layered together they change the economics enough to make most protocols a poor target. The essentials are a timelock so nothing executes instantly, flash-loan-resistant vote snapshots, quorum and deposit thresholds high enough that buying control costs more than the treasury is worth, and hard limits on what a single proposal can reach. Isolating the dangerous powers, minting, treasury movement, and code upgrades, behind a multisig or an independent security council shrinks the blast radius of any one bad vote. Anomaly monitoring, the kind that flagged the Binance near-miss, buys defenders time even when it cannot stop the vote itself. The biggest lending protocols, whose governance sits on billions in deposits, have leaned hard on timelocks and security-council vetoes, an architecture HOGE Wire compared in its breakdown of Aave and Morpho.

DefenseWhat it stopsWhat it does not stopAnchor case
Timelock plus guardian vetoInstant execution; buys time to reactThe vote itself; slow accumulationBuild Finance had none
Past-block snapshot / vote-escrowFlash-loan and one-block vote rentingPatient buyers; briberyBeanstalk; veCRV
Higher quorum plus proposal depositCheap majorities and spam proposalsA determined, funded whaleBonkDAO’s ~1% was too low
Isolating mint / treasury / upgradeSingle-proposal blast radiusCapture of the isolated body itselfTerm Finance vault access
Anomaly monitoringNothing directly, but flags attacks earlyThe underlying economics of captureThe Binance near-miss
Governance minimizationEverything, by removing the targetAdaptability; demands foresightImmutable contracts

The experimental lane: futarchy, AI delegates, and legal wrappers

Beyond patching coin voting, a more experimental set of ideas tries to change the game itself. Futarchy, the mechanism economist Robin Hanson proposed, splits governance into two questions: vote on the values you want, then use prediction markets to bet on which proposal will actually deliver them. Because you have to back your bet with capital and be right to profit, it is harder to bribe, though it remains niche. A second lane is AI delegates, automated or model-assisted voters that follow published mandates, which can lift turnout and consistency while introducing fresh questions about who writes the mandate and audits the model. A third is quadratic voting paired with proof-of-personhood, which weights influence by the number of distinct humans rather than the size of a wallet, and which lives or dies on sybil resistance.

The most concrete change may be legal rather than cryptographic. Wyoming’s Decentralized Unincorporated Nonprofit Association Act, signed in March 2024 and effective July 1, 2024, lets a DAO with at least 100 members form a DUNA, giving it legal personhood, limited liability for members, and, crucially, the standing to sue. A DUNA does not stop a governance attack, but it changes the aftermath: instead of a leaderless community with no legal existence, there is an entity that can take an attacker to court and defend its members. That matters more now that the criminal path has narrowed. It sits against a still-unsettled US backdrop, where the SEC has not fully resolved when a governance token is itself a security, a question that shadows every reform on this list.

How to read a DAO’s governance risk before you buy in

For a token holder, a governance token is a claim on control, and control is only as safe as the cheapest path to a majority. A few questions cut through most of the risk before you commit capital.

  • Turnout and concentration. How many wallets actually vote, and what share does the top holder control? BonkDAO’s seven-wallet vote was a flashing red light.
  • Cost of control versus the treasury. What would a controlling stake cost on the open market, and is that more or less than the treasury holds? If control is cheaper than the prize, that gap is the entire risk.
  • Timelock and veto. Is there an execution delay, an emergency pause, or a guardian that can stop a malicious proposal in flight?
  • Flash-loan resistance. Does the protocol snapshot voting power from an earlier block or use vote-escrow lockups?
  • Scope of a single vote. Can one proposal move the treasury, mint tokens, or upgrade the code directly, or are those powers isolated behind a multisig or council?
  • Legal wrapper and monitoring. Is there a DUNA or comparable entity, and does the project use a security partner watching for vote concentration and unusual payloads?

The uncomfortable truth of 2026 is that the treasury door is increasingly opened from the inside, by the rules, with a valid signature and a passing vote. The exploits that dominate this cluster are no longer only about broken code. They are about broken incentives, and the protocols that survive will be the ones that treated their own governance as the most dangerous contract they ever deployed.

Frequently Asked Questions

What is a governance attack in crypto?

A governance attack is when someone acquires enough of a DAO’s voting power to pass a proposal that benefits them at the protocol’s expense, then lets the DAO’s own smart contracts execute it. Nothing is technically hacked; the votes are valid and the code runs as written, which is exactly what makes these incidents hard to prevent and hard to prosecute.

How did BonkDAO lose $20 million?

On July 6, 2026, an attacker spent about four million dollars buying BONK on the open market, roughly one percent of the supply, which was enough to control 99.878 percent of a vote in which only seven wallets participated. The proposal transferred about twenty million dollars from the treasury, and because there was no meaningful quorum or timelock, the transfer executed before anyone could intervene.

Are governance attacks illegal?

It is unsettled. US prosecutors won a conviction against the Mango Markets exploiter in 2024, but a federal judge vacated it in May 2025, partly on the reasoning that an automated smart contract cannot be deceived the way a person can. The ruling is under appeal, and the SEC and CFTC have pursued civil cases, but the code-did-what-it-was-told defense now carries real legal weight.

Can flash loans still be used to take over a DAO?

They can wherever a protocol counts voting power in the same block a vote is cast, which is what let an attacker borrow one billion dollars and seize about 67 percent of Beanstalk in 2022. Most serious DAOs now snapshot voting power from an earlier block or use vote-escrow lockups, which defeats one-block borrowing but not patient accumulation.

How can a DAO protect itself from a governance attack?

The core defenses are a timelock with an emergency veto so malicious proposals cannot execute instantly, flash-loan-resistant vote snapshots, quorum and deposit thresholds high enough that buying control costs more than the treasury is worth, isolating dangerous powers like minting and treasury access behind a multisig or security council, and monitoring for sudden vote concentration. A legal wrapper such as Wyoming’s DUNA does not stop an attack but gives the DAO standing to pursue the attacker afterward.

By Anneke de Vries, DeFi and regulation correspondent at HOGE Wire.

Share 𝕏 Post Telegram