DAOs collectively control over $26 billion in on-chain treasuries as of Q2 2026, according to DeepDAO analytics. Less than 1% of token holders control approximately 90% of voting power across major protocols. Average voter participation sits at 17%. These three numbers define the governance attac...
"The security council must exist as a backstop against compromise and violations of the ENS constitution, not as political officers." — Nick Johnson, ENS Labs Founder and Lead Developer
DAOs collectively control over $26 billion in on-chain treasuries as of Q2 2026, according to DeepDAO analytics. Less than 1% of token holders control approximately 90% of voting power across major protocols. Average voter participation sits at 17%. These three numbers define the governance attack surface that cost BonkDAO $20 million on July 6, 2026, and prompted ENS DAO to approve an eight-member Security Council with veto authority on July 20, 2026.
The pattern is now well-established: an attacker accumulates governance tokens through open-market purchases, submits a proposal to drain the treasury, and lets the DAO's own rules execute the theft. No smart contract exploit is required. The attack vector is the voting mechanism itself. Beanstalk lost $182 million in 2022. Tornado Cash governance was seized in 2023. Compound DAO approved a controversial $24 million transfer in 2024. BonkDAO marks the latest and most cleanly executed instance: $4 million in BONK purchased over several days yielded a $20 million treasury drain through a single legitimate vote.
The response across the ecosystem is converging on a single architectural pattern: the security council — a multisig body with limited veto power that sits between a passed governance vote and its execution. Arbitrum, Optimism, and now ENS have implemented variants. The question is no longer whether DAOs need centralized safety mechanisms, but how to constrain them.
On July 6, 2026, an attacker drained approximately $20 million in BONK tokens from the BonkDAO treasury on Solana. The method required no code exploit, no flash loan, and no vulnerability in any smart contract. The attacker used the DAO's governance system exactly as designed.
According to reporting by CryptoNews and Bitcoin.com, the attacker purchased roughly $4 million worth of BONK tokens on exchanges over several days, using multiple wallets to avoid detection. Once the attacker had accumulated sufficient tokens, they submitted a governance proposal directing treasury funds to wallets under their control.
When the vote closed, wallets linked to the attacker controlled approximately 99.878% of the votes cast, according to on-chain data reviewed by SigIntZero. The proposal passed. The treasury drained. BONK fell 8-10% on the news.
BonkDAO had no timelock between vote approval and execution. No Security Council existed to review or block the proposal. The community had no window to detect and respond to the malicious instruction. The attacker's total cost — approximately $4 million in token purchases — yielded a 5:1 return on a perfectly legal use of the DAO's own governance mechanism.
The Solana Foundation and exchanges are coordinating efforts to track and freeze the stolen assets. As of July 22, 2026, no recovery has been confirmed.
The BonkDAO attack follows a pattern documented across at least three prior major incidents:
Beanstalk — April 2022 ($182 million): An attacker used Aave flash loans to borrow over $1 billion in assets, temporarily acquired a governance supermajority, and passed a proposal to drain the protocol's treasury in a single Ethereum transaction. The entire attack executed within one block. This remains the largest governance attack by dollar value.
Tornado Cash — May 2023 (governance seizure): An attacker purchased TORN governance tokens and submitted a proposal designed to resemble previously approved proposals. The community approved it. Hidden code within the proposal self-destructed the existing governance contract and replaced it with a malicious version, granting the attacker the ability to mint unlimited TORN tokens and take control of the DAO's governance.
Compound Finance — 2024 ($24 million): A whale known as "Humpy" delegated enough COMP tokens to meet quorum and pushed through a proposal directing 499,000 COMP tokens — valued at approximately $24 million — to a yield-farming vehicle the whale's group controlled. This case blurred the line between a governance attack and a legitimate (if controversial) proposal, highlighting the ambiguity inherent in token-weighted voting.
The cumulative total across these four incidents exceeds $226 million. Each attack used the DAO's own rules. None required a software vulnerability.
The root cause is architectural. Most DAOs use token-weighted voting: one token, one vote. This creates three compounding vulnerabilities:
Low participation rates. Average voter turnout across DAOs sits at 17%, according to DeepDAO data from Q1 2026. Even top-performing DAOs like Aave and MakerDAO achieve only 22-28% participation on critical votes. This means a governance attacker does not need to outweigh the entire token supply — only the small fraction that actively votes.
Concentrated ownership. Less than 1% of token holders control approximately 90% of voting power in major protocols, per DeepDAO analytics. This concentration is both a defense (if whales vote against malicious proposals) and a vulnerability (if whales are the attackers, or simply absent).
Insufficient quorum design. Token-weighted quorum measures how many tokens voted, not how many independent participants. A single wallet holding a majority of active voting power satisfies quorum alone. The BonkDAO attacker controlled 99.878% of votes cast — a seven-wallet vote that met all of the DAO's formal requirements.
Decentraland's June 2026 governance vote to lower its proposal passage threshold from 6 million to 5 million Voting Power illustrates the tension. Lowering thresholds increases governance throughput but also increases susceptibility to whale capture. Raising thresholds creates gridlock when participation is already low.
The median DAO treasury in 2026 holds approximately $2.3 million, per DeepDAO. But the top five — Uniswap ($4.8 billion), Sky/MakerDAO ($3.9 billion), Optimism ($2.1 billion), Arbitrum ($1.7 billion), and Lido ($1.4 billion) — hold assets that make governance attacks economically rational at scale. When a $4 million token purchase yields a $20 million treasury drain, the incentive structure is clear.
ENS DAO approved its new Security Council on July 20, 2026, two weeks after the BonkDAO attack. The council is an eight-member body requiring a 5-of-8 supermajority to veto any timelocked governance proposal flagged as malicious. Its mandate specifically covers attacks involving stolen governance credentials, fraud, vote buying, flash loans, and other methods used to gain voting power outside ordinary market participation.
The path to approval was not straightforward. In June 2026, ENS founder and lead developer Nick Johnson used approximately 3.26 million ENS tokens — roughly 50% of the active delegated voting power despite representing only 3% of total supply — to block an earlier proposal to renew the existing Security Council. Johnson argued the prior council members had signaled intent to use veto power beyond its intended scope, vetoing proposals they personally disagreed with rather than limiting intervention to clear constitutional violations.
The episode itself demonstrated the governance vulnerability it sought to address. A single individual, holding a minority of total tokens but a majority of active voting power, could unilaterally determine governance outcomes. Johnson's vote controlled roughly 80% of the "no" tally.
The replacement proposal Johnson backed passed with different structural constraints. The new council cannot move funds from the ENS DAO treasury, cannot create governance proposals, and cannot replace a canceled transaction with another action. Members must complete identity verification and background checks and sign appointment agreements with the ENS Foundation. The term expires automatically on July 16, 2028.
ENS also proposed a separate 5-million-token delegation plan designed to dilute any single participant's ability to dominate future votes, directly addressing the concentration of voting power that allowed Johnson to block the initial renewal.
Three major DAOs now operate Security Councils with distinct designs:
| Feature | Arbitrum | Optimism | ENS | |---|---|---|---| | Members | 12 | 8+ | 8 | | Emergency threshold | 9 of 12 | 75% of members | 5 of 8 | | Rotation | Semi-annual cohort elections | Elected terms | 2-year fixed term | | Emergency powers | Upgrade contracts, pause systems | Enact protocol upgrades | Veto-only on timelocked proposals | | Treasury access | Limited | Limited | None |
Arbitrum operates the most expansive model: a 12-member council divided into two cohorts elected every six months. A 9-of-12 threshold enables emergency actions including contract upgrades and system pauses. A lower 7-of-12 threshold covers routine upgrades that bypass standard DAO votes.
Optimism requires a 75% signing threshold from a minimum of eight independent elected members for protocol upgrades. The council operates within a bicameral governance structure alongside the Token House and Citizens' House.
ENS has adopted the most constrained model: veto-only authority, no treasury access, no proposal creation. The design explicitly prevents the council from becoming a shadow governance body.
All three models share a common principle: a trusted multisig sits between a passed vote and its execution, creating a review window that does not exist in pure token-weighted governance. The variation lies in how much authority that multisig holds and how its members are selected and rotated.
Security councils introduce a measurable centralization vector into systems designed to minimize trust assumptions. An eight-member body with veto power over passed governance proposals is, by definition, a centralized checkpoint. The ENS design constrains this — veto-only, no treasury access, automatic term expiry — but the constraint is itself a governance decision that a future council could seek to modify.
The counter-argument is empirical. Four governance attacks totaling over $226 million in four years demonstrate that pure token-weighted governance without centralized safety mechanisms exposes treasuries to rational economic attacks. The cost of buying quorum is quantifiable. The cost of a governance attack is quantifiable. When the ratio favors the attacker, the attack happens.
Alternative approaches exist but remain largely theoretical or early-stage. Quadratic voting, reputation-based voting, conviction voting, and time-weighted snapshot mechanisms have been proposed in academic literature, including papers from Frontiers in Blockchain and arXiv. None has been deployed at scale in a protocol managing more than $1 billion in treasury assets.
The current industry trajectory favors the security council model: a human layer of review between code-executed governance and treasury movements, with explicit constraints on scope and tenure. Whether this represents a pragmatic maturation of DAO governance or a retreat from decentralization depends on whether the constraints hold.
The BonkDAO attack crystallized a vulnerability that has been documented since Beanstalk in 2022: token-weighted governance with low participation, concentrated ownership, and no execution delay is an invitation to rational economic exploitation. The cost of buying quorum is lower than the value of most DAO treasuries.
The industry response — security councils with constrained veto power — is pragmatic but introduces the centralization it was designed to prevent. ENS DAO's July 20 vote approved precisely the kind of trusted intermediary that DAOs were created to eliminate. The constraints are meaningful: veto-only authority, no treasury access, automatic term expiry, identity verification. Whether those constraints endure through the council's two-year term remains to be seen.
The $26 billion sitting in DAO treasuries is governed by mechanisms that have been exploited four times for a combined $226 million. The question is not whether another governance attack will occur. The question is whether the security council model — adopted by three of the largest DAOs in the ecosystem — will stop it before execution.