After being "brazenly robbed" of 20 million dollars, Upbit has completely abandoned BONK.

CN
2 hours ago
Funds recovery still has no results.

Written by: Mah, Foresight News

On August 7, South Korea's largest cryptocurrency exchange Upbit officially announced that it would terminate trading support for BONK on September 7 at 15:00 (Korea Standard Time), involving the BONK/KRW and BONK/USDT trading pairs, with withdrawal services available until October 7. Upbit stated that after evaluating BONK, it found that the operators used distributed ledgers for issuing, transmitting, and storing virtual assets which experienced unexplained or unresolved hacking incidents and other security incidents, and that the issuer or operator did not timely disclose important matters regarding virtual assets through appropriate electronic transmission media. After comprehensive consideration, it confirmed the existence of numerous deficiencies that could lead to user losses.

After the announcement, the price of BONK fell from $0.0000028 to $0.0000025, a drop of about 10%, with its current market capitalization at $222.26 million.

Foresight News previously reported on this incident in detail titled "4.4 million leveraged 20 million: BONK encountered a legal theft." A month ago, BonkDAO had just experienced a shocking governance attack, where about $20 million of treasury assets were "legally" transferred away.

BONK attackers cash out approximately $13.58 million

On June 30, the attacker submitted proposal BIP #76 through the Solana ecosystem's Realms governance platform, titled "Sowellian BonkDAO." The proposal was superficially packaged as a governance optimization plan, but the core directive was to directly transfer approximately 4.426 trillion BONK from the BonkDAO treasury to an address controlled by the attacker. At that time, the circulating supply of BONK was about 88 trillion, with a 1% voting threshold of approximately 8.8 trillion. Between July 4 and 5, the attacker acquired about 882.85 billion BONK by trading on exchanges such as Binance and Bybit, supplemented by some DeFi lending, at a cost of approximately $4.4 million, just enough to meet the quorum requirement.

On July 6, the proposal went to a vote. Only 7 addresses participated in the entire process, with the address controlled by the attacker contributing 99.878% of the votes in favor. After the vote passed, the smart contract immediately executed the transfer, with approximately 4.426 trillion BONK (worth about $20 million at the time) transferred from the treasury to the attacker’s wallet. The entire process did not trigger any timelock or additional multisignature or manual review steps.

Once the funds were secured, the attacker acted quickly. About 9 hours after the transfer was completed, approximately $190,000 worth of BONK was transferred to OKX. The remaining approximately $19 million was transferred to a newly created multisignature wallet, which Chainalysis described as the "BONK 2.0" shadow DAO, controlled by malicious voting wallets, funds receiving wallets, and a third-party address financially associated with the voting address.

Meanwhile, the attacker began to sell off the portion of BONK used to acquire voting rights. Approximately 1 hour after the vote was completed, the relevant address began liquidating a position of about $5.3 million. In the following weeks, on-chain monitoring showed that the attacker continued to transfer funds to platforms like Coinbase.

On July 17, the attacker transferred 1.186 trillion BONK (worth about $4.11 million) into Binance.

On July 19, according to on-chain analyst Yu Jin's monitoring, the BONK treasury attacker again transferred 400 billion BONK to Coinbase, worth about $1.11 million. In the 12 days since the related tokens were transferred from the treasury, the price of BONK dropped from $0.0000047 to $0.0000027, a cumulative decrease of about 41%.

On July 20, that attacker had completed liquidation; 30 minutes prior, the last 400 billion BONK (worth $1.17 million) was also deposited to Coinbase.

Data statistics show that the attacker cashed out approximately $13.58 million in total.

High difficulty, funds recovery still has no results

The Bonk team quickly responded after the incident, confirming that "BonkDAO encountered malicious governance proposals, leading to approximately $20 million worth of BONK being transferred from the treasury." The team stated that it had identified the exchange wallet addresses used by the attacker for preemptive accumulation and had notified law enforcement, while maintaining communication with exchanges, cross-chain bridges, and the Solana Foundation in an attempt to recover funds and identify the liable parties.

On July 13, BonkDAO released a follow-up update: the relevant wallets had been marked and were under continuous monitoring, with the team exploring all possible avenues for recovery; emphasizing that the BONK token itself and users' personal assets were unaffected, the token contract was secure; and a formal post-incident analysis report would be released, while also urging the community to pay attention to improvements in governance mechanisms.

On July 23, the official position further confirmed that recovery efforts were still ongoing.

As of now, there has been no official announcement of substantial funds successfully returned to the treasury through public channels, nor has there been formal confirmation of large amounts of funds being successfully frozen or recovered.

On July 7, several exchanges almost simultaneously listed BONK as a trading caution target, and a month later, Upbit determined that the issues had not been resolved and was the first to officially decide to terminate trading support. South Korea is implementing the "Virtual Asset Investor Protection Law" from July 2024, after which DAXA (Korea Digital Asset Exchange Association) has strict legal obligations regarding projects with significant governance flaws and security risks. Upbit removed BONK due to compliance and legal risk scrutiny.

Currently, other exchanges have not yet taken action.

It should be noted that since the transfer was fully executed according to on-chain governance rules, the difficulty of recovery is significantly higher than traditional hacking incidents.

The attacker acquired sufficient voting rights (about 1% of the supply), submitted a proposal, and voted to pass it, with the smart contract then executing the transfer automatically. The entire process was in full compliance with the governance rules of BonkDAO on Realms at that time. There was no private key leak, no contract vulnerability, and no unauthorized calls. Most jurisdictions still maintain a conservative stance regarding pure governance attacks, with courts more inclined to view "code is law + vote passed" as valid internal decisions rather than traditional theft, which significantly weakens the efficacy of criminal cases and civil freezing.

From on-chain data, the attacker has also completed part of the asset sale and transfer, further compressing the scale of assets that can be frozen. Additionally, the attacker's identity is undisclosed, and the high costs and lengthy duration of cross-border enforcement make the likelihood of recovering most of the losses low.

Governance issues need urgent resolution

The core controversy of this incident is that when the voting threshold is too low, participation rate is extremely low (only about 2.9% of members participated), and there is a lack of time locks and abnormal proposal interception mechanisms, the attacker leveraged $4.4 million to manipulate $20 million in assets, yielding a high return on investment and full compliance throughout the process.

Any DAO holding a large treasury, if it has a long-term very low voting participation rate and a very low quorum requirement, essentially exposes the control of the treasury to the open market. Whoever can concentrate enough minimum threshold tokens in a short time can potentially take control of the treasury. This is not a theoretical risk but a proven executable path.

If the treasury had set execution delays of 3-7 days or longer, the community and project team would at least have time to detect anomalies, initiate emergency votes to veto, or intervene through multisignatures. In reality, many mature DAOs (especially those with significant treasuries) will impose time locks on proposals involving the treasury.

When community activity has been persistently low, merely relying on token weighting effectively decides governance through "money" rather than "people." For projects with larger treasury sizes, project teams should consider introducing higher quorum requirements and dual thresholds (to meet a certain voting power ratio and a certain number of independent addresses), in addition to adding extra approval mechanisms for large proposals, such as multisignature committees.

Governance security can never be fully resolved through remedial actions; it must be considered according to the "worst-case scenario" during the design phase.

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink