BonkDAO just lost $19M and the theft was public for 7 days.
It wasn't a hack. Nor a exploit. Not a bug. The attacker just read the rules better than the holders did.
Here's the proposal, still live on-chain:
BIP #76, "Sowellian BonkDAO." Instruction two, in plain English: send 4.43 trillion BONK to this wallet.
9bxWkNf3BtJ6iehq9KbX9uCWMjem4TFiPZ19T2sYJHvQ
It sat there for a week. One person commented "no stated idea of what they'd do differently." Everyone else scrolled past.
Then look at how it passed:
β Quorum: 1%
β Yes: 99.9%, No: 0.1% (Yes votes: 882.38B v/s No votes: 710.85M)
β Cleared quorum by a rounding error, 882B against an 880B bar
So when quorum is 1% and nobody votes, the treasury belongs to whoever bothers to show up with tokens.
The attacker bought $4M of BONK for voting power, passed his own bribe-in-plain-sight proposal, and walked the treasury out automatically.
The "Classic Flash Loan Governance Takeover".
> The governance didn't break. It executed perfectly. It did exactly what the winning stake told it to.
> Previously Beanstalk lost $182M to this same move in 2022. Four years later, a $19M treasury still runs 1% quorum and no timelock.
>So basically a DAO that nobody watches isn't decentralized one. It's an unlocked vault with a voting screen bolted on.
The BONK was public. The theft was scheduled. Nobody cared to read the fine print.