#BONK Delisting Risk#Exchange Compliance Pressure
Upbit Delists BONK After $20M Governance Hack, Highlighting DAO Security Flaws
WooFun2026-08-07 17:00
Key Takeaways
South Korea's Upbit halts BONK trading following a $20 million treasury heist via governance attack. The incident exposes critical risks in low-quorum DAOs, with funds largely unrecovered and regulatory compliance driving the exchange's decision.
Woofun AI reports that Upbit, South Korea's largest cryptocurrency exchange, announced on August 7 the complete cessation of trading support for BONK, effective 15:00 on September 7 (Korean Standard Time). This decisive move, attributed to unresolved security vulnerabilities and governance failures within the project, affects both BONK/KRW and BONK/USDT trading pairs, while withdrawal services remain operational until October 7.
The delisting follows a comprehensive evaluation by Upbit, which identified critical shortcomings in the distributed ledger systems used for issuing, transmitting, and storing virtual assets, alongside a failure by operators to disclose material information through appropriate electronic channels in a timely manner. These deficiencies, combined with the recent high-profile governance attack, were deemed sufficient to pose significant loss risks to users, prompting the exchange to prioritize regulatory compliance and user protection over continued listing.
The announcement, detailed in a report by Mah for Foresight News, underscores the growing scrutiny of decentralized autonomous organizations (DAOs) with weak security frameworks.
The market reaction to Upbit's delisting announcement was immediate and pronounced, reflecting broader investor concerns about the token's stability and governance integrity. Following the news, the price of BONK plummeted from $0.0000028 to $0.0000025, representing a sharp decline of approximately 10% in a short timeframe. This drop further eroded the token's market capitalization, which currently stands at $222.26 million, signaling sustained pressure on the asset's valuation. The volatility highlights the sensitivity of the market to exchange listings and the perceived security posture of the underlying project. Investors, already wary of the recent governance exploit, viewed the delisting as a confirmation of systemic risks, leading to accelerated selling pressure. The impact on the BONK/KRW and BONK/USDT pairs was particularly acute, as liquidity dried up in anticipation of the trading halt.
The core catalyst for this market turmoil was a sophisticated governance attack on BonkDAO, previously reported under the headline '$4.4 Million to Steal $20 Million: BONK Suffers a Legitimate Heist.' In this incident, attackers successfully transferred approximately $20 million in treasury assets through a technically 'legal' governance proposal, exploiting the DAO's low quorum requirements and lack of protective mechanisms. The attackers managed to cash out around $13.
58 million in total, demonstrating the severe financial consequences of inadequate governance safeguards. This event shocked the industry, revealing how easily a well-funded actor could manipulate decentralized decision-making processes to siphon funds. The attack was not a traditional hack involving private key theft or contract vulnerabilities, but rather a strategic exploitation of the governance rules themselves, making it particularly difficult to challenge legally or technically.
The attack began on June 30, when the perpetrators submitted a proposal titled 'Sowellian BonkDAO' via Solana's Realms governance platform under BIP 76. While the proposal superficially appeared to be a governance optimization plan, its true intent was to transfer around 4.426 trillion BONK tokens from BonkDAO's treasury directly to addresses controlled by the attackers. At the time, the circulating supply of BONK was approximately 88 trillion tokens, and the governance rules required a 1% voting threshold, equating to roughly 880 billion tokens. This low threshold, combined with low overall participation, created a critical vulnerability that the attackers exploited. The proposal's legitimacy was never questioned during the voting period, as it adhered strictly to the existing governance framework, highlighting the dangers of overly simplistic voting mechanisms in large-treasury DAOs.
Between July 4 and July 5, the attackers executed a coordinated accumulation strategy, purchasing BONK tokens through major exchanges such as Binance and Bybit, supplemented by DeFi lending platforms. They amassed approximately 882.285 billion BONK tokens at a cost of around $4.4 million, just enough to meet the quorum requirement. On July 6, the proposal entered the voting phase, with only 7 addresses participating in the process. The address controlled by the attackers accounted for a staggering 99.878% of the affirmative votes, ensuring the proposal's passage. This manipulation was possible due to the extremely low participation rate, which allowed a single entity to dominate the voting outcome. The ease with which the attackers accumulated sufficient voting power underscores the fragility of governance systems that rely solely on token holdings without additional safeguards.
Woofun AI data shows that once the vote passed, the smart contract automatically executed the transfer, moving around 4.426 trillion BONK tokens (worth approximately $20 million at the time) from the treasury to the attackers' wallets. No timelock was activated during this process, nor were there any additional multisig mechanisms or manual review steps to prevent such a large transfer. Within about 9 hours after the transfer, the attackers began cashing out, sending around $190,000 worth of BONK to OKX.
The remaining approximately $19 million was sent to a newly created multisig wallet, which Chainalysis described as a 'BONK 2.0' shadow DAO. This wallet was controlled jointly by malicious voting wallets, fund-receiving wallets, and a third-party address linked financially to the voting address, indicating a highly organized and premeditated operation. The speed and efficiency of the cash-out highlight the attackers' preparedness and the lack of immediate countermeasures by the DAO.
The attackers then began liquidating the BONK tokens they had used to gain voting rights, starting about 1 hour after the voting concluded. They sold holdings worth around $5.3 million, initiating a downward pressure on the token's price. On-chain monitoring showed that the attackers continued to transfer funds to platforms such as Coinbase in the weeks that followed. On July 17, the attacker transferred 1.186 trillion BONK tokens (worth approximately $4.11 million) to Binance. On July 19, another 400 billion BONK tokens, valued at around $1.
11 million, were transferred to Coinbase. Within 12 days of the tokens being removed from the treasury, the price of BONK dropped from $0.0000047 to $0.0000027, a cumulative decline of around 41%. By July 20, the attacker had completed the sale of all their holdings, with the last 400 billion BONK tokens (worth $1.17 million) deposited into Coinbase just 30 minutes earlier. Statistics show that the attacker totaled around $13.58 million in recovered funds, leaving the majority of the stolen assets unrecovered.
The Bonk team responded quickly to the incident, issuing a statement confirming that 'BonkDAO suffered a malicious governance proposal, resulting in around $20 million worth of BONK being transferred from the treasury.' The team identified the exchange wallet addresses used by the attackers to build up positions in advance and informed law enforcement. They also maintained communication with exchanges, bridges, and the Solana Foundation in an attempt to recover the funds and identify those responsible. On July 13, BonkDAO released an update stating that the relevant wallets had been flagged and were under continuous monitoring, and the team was exploring all possible ways to recover the funds.
They emphasized that the BONK tokens themselves and users' personal assets remained unaffected, and the token contract was secure. The team planned to release a formal post-incident analysis report later, while also urging the community to focus on improving governance mechanisms. On July 23, the official team reiterated that efforts to recover the funds were still ongoing, but to date, there have been no official announcements indicating that large amounts of funds have been successfully returned to the treasury, nor any confirmation that significant funds have been frozen or recovered.
The regulatory context surrounding this incident is critical, particularly in South Korea, where the Virtual Asset Investor Protection Act was implemented in July 2024. Under this law, DAXA (the Korean Digital Asset Exchange Association) has strict legal obligations regarding projects with serious governance flaws and security risks. Upbit's decision to delist BONK was driven by the need to comply with these regulations and avoid legal scrutiny. On July 7, several exchanges had already listed BONK as a trade cautionary asset, signaling growing concern about the token's security. A month later, Upbit decided that the issues had not been resolved and officially ended trading support.
The difficulty of recovering the funds is compounded by the fact that the transfer was fully automated in accordance with on-chain governance rules, making it significantly more challenging to pursue legal action compared to traditional hack incidents. There were no private key leaks, no contract vulnerabilities, and no unauthorized access, meaning the attackers operated within the bounds of the existing governance framework. In many jurisdictions, courts tend to consider 'code as law + approved voting' as a valid internal decision rather than traditional theft, which significantly weakens the possibility of criminal prosecution and civil asset freezing.
This incident serves as a stark warning for DAOs with large treasuries and low voting participation rates. The core controversy is that when the voting threshold is too low, participation rates are extremely low (only around 2.9% of members participated), and there are no timelocks or mechanisms to block abnormal proposals, attackers can use $4.4 million to control $20 million worth of assets, achieving a very high return on investment while staying within regulatory bounds.
Any DAO with a large treasury that has consistently low voting participation rates and a low quorum requirement essentially exposes control over the treasury to the open market. Whoever can purchase the minimum required number of tokens quickly enough can take control of the treasury. This is not just a theoretical risk but a proven feasible scenario. If the treasury transactions had a 3–7 day or longer execution delay, the community and project team would have had time to detect abnormalities, initiate emergency votes to reject the proposals, or intervene through multisig mechanisms.
In reality, many mature DAOs (especially those with large treasuries) enforce timelocks on proposals involving the treasury. When community activity remains low for long periods, relying solely on token weighting essentially means letting 'money' determine governance rather than 'people.' For projects with large treasuries, project teams should consider setting higher quorum requirements and dual thresholds (both a certain percentage of voting rights and a certain number of independent addresses).
Additionally, extra approval mechanisms such as a multisig committee can be implemented for large-scale proposals. Governance security cannot be fully resolved through post-incident remedies; it must be designed with the 'worst-case scenario' in mind from the start.
Comments
No comments yet.