How a $4.4 Million Token Buy Let One Wallet Vote Itself BonkDAO's Treasury
No exploit, no bug, no stolen key — just a wallet that bought enough votes and then voted itself the money.
On July 6, 2026, an anonymous actor spent $4.4 million acquiring a little over one percent of BONK's circulating supply, then used that stake to push through a governance proposal handing the DAO's own treasury to itself. The instant the vote closed, 4.426 trillion BONK — worth about $19.3 million — left the treasury in a single transaction.

The decision was effectively made by seven wallets; an estimated 18,000 BonkDAO members never cast a ballot.
The winning proposal, called "Sowellian BonkDAO," had been filed on June 30, framed as a reform initiative that promised to "rebuild from the ashes" — language that masked a full treasury-transfer instruction buried in its body.
Every step of the process functioned exactly as coded: the token purchase settled, the vote tallied correctly, quorum was legitimately reached. Nothing malfunctioned. That is precisely the uncomfortable part — a system that followed its own rules to the letter still ended with an empty treasury, raising the question of whether this counts as theft or as governance behaving exactly as it was built to behave.
Timeline of the drain
The proposal vote closed at 09:42 UTC on July 6, and the treasury emptied within that same block.
QuillAudits reconstructed the mechanics within hours: the attacker had accumulated 882.1 billion BONK on Bybit and Binance over the prior two days — just enough to clear the 879.95 billion quorum requirement. Only three wallets voted yes, turnout sat at 2.9%, and the proposal passed regardless.
Bonk's team acknowledged the incident roughly eight hours after the vote closed, via a single social media post confirming a malicious governance proposal, an estimated $20 million loss, identification of the exchange wallets involved, and that law enforcement had been contacted. The post included no transaction hash, no proposal ID, and no wallet addresses — all of which had already been public on-chain for hours.
About an hour after the treasury drain, the wallet that had cast the winning vote began selling, offloading $5.3 million of the BONK it had used to secure quorum — well before BonkDAO issued any public statement. Later that same afternoon, after the official acknowledgment had gone out, the drained treasury funds moved a second time, to an address ending in "eh42".
Notably, none of the rewards the proposal had promised to yes-voters ever appeared.
On-chain investigator SpecterAnalyst began tracing the voting wallets through shared exchange deposit addresses, eventually connecting them to identities familiar to the BONK community. QuillAudits co-founder Preetam summarized the technical finding plainly: there was no smart contract bug and no compromised key — just roughly $4 million spent to pass a proposal that most voters never read past the headline of.
Upbit suspended BONK withdrawals in response; Kraken followed with the same restriction.
A governance setup built for this exact outcome
BonkDAO ran its governance through Solana's Realms platform, the SPL Governance interface used across hundreds of Solana-based DAOs. Its voting model was purely token-weighted — one token, one vote — which makes no distinction between a broad community and a single wallet executing a plan.
Preetam described the specific configuration as "a loaded gun": a 1% quorum threshold, a proposal-creation minimum of only 100 million BONK, direct treasury-transfer capability through Realms, and — critically — an instruction hold-up time of zero seconds. That last setting meant there was no delay between a proposal passing and its instructions executing: no review period, no window to veto, no chance for anyone to intervene once the vote concluded.
The proposal itself, BIP #76, listed only two actions: an "Add Metadata" call, and a transfer instruction moving 4,426,104,450,305 BONK to a wallet the submitter controlled. It remains publicly viewable on Realms. Anyone who read past its title would likely have spotted the transfer clause immediately — but apparently no one did, for six days.
The wallet that submitted the proposal has been flagged by SpecterAnalyst as 8xxRdtzsw1CJWfEahViqNjZwh5dYJAdSbBctWwcbycVo.
Separately, over July 4 and 5, another wallet assembled the voting position needed to win — buying BONK on exchanges and borrowing additional supply through marginfi until it held the roughly 1% required to clear quorum. Two wallets ultimately cast that stake on July 6: one supplying 882.2 billion BONK (99.87% of the yes vote) and a second supplying 97.8 million BONK (0.011%).
The final result: 882,383,387,283 BONK voted in favor versus 710,848,288 against — a margin of roughly 1,241 to 1 — just clearing the 879.95 billion quorum bar.
Voting Wallet 1 (99.87% of YES): CyEE7oHVDaFJ5xZLbXY3h2Z2uk1VwhTkdy72kPUEtypQ
Voting Wallet 2 (0.011% of YES): FQnQYaYe1UiQZiokdDH39ybRbhJYfzzwXSghnA32pWxc
None of this involved circumventing code — the governance system executed precisely as designed. The design itself was the flaw.
Where the money went
The 4,426,104,450,305 BONK left the treasury the moment the vote closed, worth approximately $19.3 million at that instant, landing in the attacker's wallet. That wallet carries a "funded by Bybit" tag on Solscan — a detail that was visible before the vote closed, not just after.
BonkDAO Treasury: F8FqZuUKfoy58aHLW6bfeEhfW9sTtJyqFTqnxVmGZ6dU
Attacker Wallet: 9bxWkNf3BtJ6iehq9KbX9uCWMjem4TFiPZ19T2sYJHvQ
Treasury Transfer Transaction: 5tPU1srcRcnmibB7KJi2WQ7cK4zuq5iKTMrSCLjq7hvGjuK4KUTmaHfwicixkJa5jZJmp3y98T7r2qecKV5mWw8P
About ten hours later, the full balance moved again, this time to a second address ending in "eh42":
Second Attacker's Wallet: EXaJnmrLf7RAKLfn1hehoKX94keKYmvZm5H5zuYVeh42
None of the funds reached the 18,000 members who didn't vote, and none reached the yes-voters the proposal had promised compensation to.

Nine hours after the drain, the attacker sent a test transfer of $188,000 to an exchange, then moved the remaining roughly $19 million into a newly created multisig wallet. Chainalysis identified this structure as "BONK 2.0," controlled by three keys: the wallet that cast the malicious vote, the wallet that executed the exploit, and a third wallet with financial links to the voting wallet. As of reporting, the funds sit untouched there — not cashed out, not run through a mixer.
Aftermath and unresolved threads
BONK's price fell by double digits over the following day, settling roughly 93% below its all-time high. Upbit and Kraken both froze BONK deposits and withdrawals, though neither exchange had a specific account to lock — they simply stopped processing activity around the token entirely.
SpecterAnalyst continued tracing the funds and found that both voting wallets routed funds to a shared exchange deposit address. That same address, dating back to 2023, had previously received transfers from a wallet publicly associated with crypto notte and from a wallet that Realms founder deanmachine had once publicly rewarded during an early governance test. None of this proves authorship of BIP #76, but it does suggest the wallets involved are not unconnected to the Realms ecosystem.
No one has been charged, and no funds have been frozen. Bonk's public statement said law enforcement had been informed and that recovery efforts were underway — standard language for a case with no bug to patch, no key to revoke, and no clear path to reverse a vote that was never invalid on-chain. BIP #76 itself remains permanently viewable on Realms, still titled "Sowellian BonkDAO."
The bigger picture
BonkDAO wasn't hacked so much as outvoted. A $4.4 million purchase secured a majority no one contested, and that majority moved roughly $19.3 million through a door the DAO's own configuration had left wide open for six days. No smart contract broke, no private key was compromised, and no audit could have flagged the issue — the vulnerability was a governance model that treated a well-funded wallet with an agenda identically to a genuine community consensus.
Blockchain investigator Taylor Monahan summarized the underlying critique sharply: token-weighted governance effectively grants voting power to whoever buys in, and that structure was never going to end anywhere else.
The stolen treasury now sits in the three-key "BONK 2.0" multisig, and the wallets tied to it trace back through years of deposit history to names already present inside Solana's governance ecosystem — none of whom have had to answer for it.
More than 800 DAOs run the same Realms infrastructure with the same 1% quorum design, and most have never had their members check whether their own treasuries are exposed to precisely this kind of purchase-a-majority attack.
Get new scam files the moment we publish them — usually 2–3 emails a week.