Foto: persoon aan laptop — symbolisch bij een governance-aanval op een crypto-kas
Speciale editieSpecial edition  ·  Editie #006Edition #006  ·  Governance-aanval

De BonkDAO-aanval: hoe iemand $20 miljoen uit de kas stemde zonder één regel te brekenThe BonkDAO attack: how someone voted $20 million out of the treasury without breaking a single rule

Boven: Een aanvaller kocht voor ~$4,4 miljoen aan BONK-tokens, haalde in zijn eentje het stemquorum en stemde ~$20 miljoen uit de BonkDAO-kas naar zijn eigen wallet. Geen hack — een governance-aanval binnen de regels van het systeem.Above: An attacker bought ~$4.4 million in BONK tokens, met the voting quorum single-handedly and voted ~$20 million out of the BonkDAO treasury into their own wallet. Not a hack — a governance attack within the system’s own rules.
Home Scam van de Week Editie #006Edition #006

$20 miljoen uit de kas gestemd — zonder hack: zo werkt een governance-aanval$20 million voted out of the treasury — with no hack: how a governance attack works

BonkDAO beheert de kas achter BONK, een van de bekendste memecoins op Solana. Op 6 juli kocht een aanvaller voor ~$4,4 miljoen aan BONK — net genoeg om in zijn eentje het stemquorum te halen. Daarna diende hij één voorstel in: maak de hele kas over naar mijn wallet. Slechts 7 wallets stemden, meer dan 18.000 leden deden niets, en het voorstel werd automatisch uitgevoerd. Resultaat: ~$20 miljoen weg, ~5x rendement voor de aanvaller. Geen code gekraakt — de regels van het systeem waren zélf de zwakke plek.BonkDAO manages the treasury behind BONK, one of the best-known memecoins on Solana. On 6 July an attacker bought ~$4.4 million in BONK — just enough to meet the voting quorum single-handedly. Then they submitted one proposal: send the entire treasury to my wallet. Only 7 wallets voted, more than 18,000 members did nothing, and the proposal executed automatically. Result: ~$20 million gone, a ~5x return for the attacker. No code was cracked — the system’s own rules were the weak spot.

Feiten op een rijKey facts
~$4,4M
Kosten voor de aanvallerAttacker’s cost
~$20M
Uit de kas gestemdVoted out of treasury
~5x
Rendement aanvallerAttacker’s return
7
Wallets die stemdenWallets that voted
~2,9%
Opkomst · chain: SolanaTurnout · chain: Solana

Wat is er precies gebeurd?What exactly happened?

BONK is een van de grootste memecoins op de Solana-blockchain. Rondom dat token zit een DAO: een “decentrale autonome organisatie”. Simpel gezegd is dat een gemeenschapskas waarover de tokenhouders samen stemmen. Wie tokens heeft, mag meebeslissen — hoe meer tokens, hoe zwaarder je stem. Op 6 juli 2026 werd precies dat systeem tegen zichzelf gebruikt.BONK is one of the largest memecoins on the Solana blockchain. Around that token sits a DAO: a “decentralised autonomous organisation”. In plain terms, that is a community treasury the token holders vote on together. Whoever holds tokens gets a say — the more tokens, the heavier your vote. On 6 July 2026, that exact system was turned against itself.

Om te voorkomen dat één iemand alles beslist, had de DAO een quorum: er moest voor minstens 1% van alle tokens worden meegestemd voordat een voorstel geldig was. Klinkt veilig. Maar de aanvaller kocht simpelweg voor ~$4,4 miljoen aan BONK — net iets meer dan die 1% — en had zo in zijn eentje genoeg stemkracht om het quorum te halen.To stop any one person deciding everything, the DAO had a quorum: at least 1% of all tokens had to vote before a proposal was valid. Sounds safe. But the attacker simply bought ~$4.4 million in BONK — just over that 1% — giving them, alone, enough voting power to meet the quorum.

Vervolgens diende hij één voorstel in: maak ~4,426 biljoen BONK (ongeveer $20 miljoen) over van de gemeenschapskas naar zijn eigen wallet. Slechts 7 wallets stemden mee, en de aanvaller was goed voor 99,9% daarvan. Meer dan 18.000 leden stemden helemaal niet — een opkomst van amper 2,9%. Het voorstel “won” dus met 99,9% ja-stemmen en werd automatisch uitgevoerd. Er zat geen vertraging (timelock) of noodrem op om zo’n voorstel nog te blokkeren.Then they submitted one proposal: transfer ~4.426 trillion BONK (around $20 million) from the community treasury to their own wallet. Only 7 wallets voted, and the attacker accounted for 99.9% of them. More than 18,000 members did not vote at all — a turnout of barely 2.9%. So the proposal “won” with 99.9% yes votes and executed automatically. There was no delay (timelock) or emergency brake to block such a proposal.

Het bijzondere — en verontrustende — is dat er geen enkele regel werd gebroken. Geen gehackte code, geen gestolen wachtwoord. De aanvaller volgde precies de spelregels van de DAO en verdiende zo ongeveer 5x zijn inleg. De koers van BONK zakte 8 tot 10%. Op het moment van schrijven staat het grootste deel van de buit (~$19 miljoen) nog stil in de wallet van de aanvaller; BonkDAO probeert samen met de Solana Foundation, exchanges en justitie het geld te bevriezen en terug te halen.The striking — and unsettling — part is that no rule was broken. No hacked code, no stolen password. The attacker followed the DAO’s rules to the letter and earned roughly 5x their stake. BONK’s price fell 8 to 10%. At the time of writing, most of the proceeds (~$19 million) still sit untouched in the attacker’s wallet; BonkDAO is working with the Solana Foundation, exchanges and law enforcement to freeze and recover the funds.

“Geen code gehackt, geen wachtwoord gestolen. De aanvaller volgde de regels — en dat was precies het probleem. Als bijna niemand stemt, is een DAO-kas te koop.”“No code hacked, no password stolen. The attacker followed the rules — and that was exactly the problem. When almost no one votes, a DAO treasury is for sale.”

De tijdlijn — stap voor stapThe timeline — step by step

🛒rond 1 juli 2026around 1 July 2026
De aanvaller koopt stemkrachtThe attacker buys voting power
Over enkele dagen koopt iemand voor ~$4,4 miljoen aan BONK — net boven de 1%-drempel die nodig is om het stemquorum in zijn eentje te halen.Over a few days someone buys ~$4.4 million in BONK — just above the 1% threshold needed to meet the voting quorum single-handedly.
🗳️6 juli 20266 July 2026
Het kwaadaardige voorstelThe malicious proposal
Hij dient één voorstel in: maak de hele kas (~4,426 biljoen BONK, ~$20M) over naar zijn eigen wallet. Het voorstel gaat de stemming in.They submit a single proposal: transfer the entire treasury (~4.426 trillion BONK, ~$20M) to their own wallet. The proposal goes to a vote.
😴6 juli 20266 July 2026
Bijna niemand stemtAlmost no one votes
Slechts 7 wallets brengen een stem uit; de aanvaller is goed voor 99,9% van de stemkracht. 18.000+ leden negeren de stemming — opkomst amper 2,9%.Only 7 wallets cast a vote; the attacker holds 99.9% of the voting power. 18,000+ members ignore the vote — turnout barely 2.9%.
💸6 juli 20266 July 2026
Voorstel voert automatisch uit — kas leegProposal auto-executes — treasury emptied
Zonder timelock of noodrem wordt het voorstel meteen uitgevoerd. ~$20 miljoen verlaat de kas in seconden. De aanvaller verdient ~5x zijn inleg.With no timelock or emergency brake, the proposal executes at once. ~$20 million leaves the treasury in seconds. The attacker earns ~5x their stake.
🚨7 juli 20267 July 2026
BONK zakt, jacht op het geld begintBONK slides, the hunt for the money begins
Het nieuws komt naar buiten en BONK daalt 8–10%. Het grootste deel van de buit (~$19M) staat nog stil in de wallet; BonkDAO schakelt Solana Foundation, exchanges en justitie in om te bevriezen.The news breaks and BONK falls 8–10%. Most of the proceeds (~$19M) still sit untouched in the wallet; BonkDAO calls in the Solana Foundation, exchanges and law enforcement to freeze it.

De rode vlaggen — waar je op moet lettenThe red flags — what to watch for

Beleg je in een token met een DAO of gemeenschapskas? Dan bepalen de stemregels mee hoe veilig je geld is. Deze signalen vergroten het risico op een governance-aanval — en de meeste kun je vooraf checken:Investing in a token with a DAO or community treasury? Then the voting rules help decide how safe your money is. These signals raise the risk of a governance attack — and most you can check in advance:

01
Een lage stemdrempel bij een grote kasA low voting threshold on a big treasury
Hier was 1% van de tokens genoeg om een quorum te halen, terwijl de kas ~$20 miljoen waard was. Als je met een paar miljoen de controle kunt kopen over een veel grotere pot, is dat een uitnodiging voor misbruik.Here 1% of tokens was enough to reach quorum, while the treasury was worth ~$20 million. If a few million can buy control over a much larger pot, that is an invitation to abuse.
02
Bijna niemand stemt (lage opkomst)Almost no one votes (low turnout)
Met een opkomst van 2,9% kon één grote stem álles beslissen. Kijk in de stemgeschiedenis van een DAO: als voorstellen steeds met een handjevol wallets worden aangenomen, is de kas kwetsbaar.With a 2.9% turnout, one large vote could decide everything. Check a DAO’s voting history: if proposals keep passing with a handful of wallets, the treasury is vulnerable.
03
Geen timelock of vertraging op uitvoeringNo timelock or delay on execution
Dit voorstel werd meteen uitgevoerd. Veilige DAO’s bouwen een vertraging (timelock) van bijvoorbeeld 24–72 uur in, zodat de gemeenschap een kwaadaardig voorstel nog kan tegenhouden. Ontbreekt die pauze, dan is er geen noodrem.This proposal executed immediately. Safe DAOs build in a delay (timelock) of, say, 24–72 hours, so the community can still stop a malicious proposal. Without that pause, there is no emergency brake.
04
Één stem kan de hele kas verplaatsenOne vote can move the entire treasury
Als een enkel voorstel het volledige vermogen in één keer kan overmaken, is het risico maximaal. Veiligere systemen gebruiken limieten of een multisig waarbij meerdere onafhankelijke partijen moeten tekenen.If a single proposal can move all the funds at once, the risk is at its highest. Safer systems use limits, or a multisig where several independent parties must sign off.
05
Stemkracht puur op basis van tokens (te koop)Voting power purely by tokens (buyable)
Als stemrecht alleen afhangt van hoeveel tokens je hebt, kan een rijke aanvaller macht simpelweg kopen op de markt. Zeker bij memecoins met veel losse liquiditeit is dat goedkoop en snel te doen.If voting rights depend only on how many tokens you hold, a wealthy attacker can simply buy power on the market. Especially with memecoins that have plenty of loose liquidity, that is cheap and fast to do.
06
“Herstel”-hulp ná het incident“Recovery” help after the incident
Na elk groot verlies duiken nep-“recovery”-diensten op die beloven je geld terug te halen — tegen een voorschot. Dat is een tweede scam bovenop de eerste. Niemand kan gestolen crypto tegen betaling voor je terughalen.After every big loss, fake “recovery” services appear promising to get your money back — for an upfront fee. That is a second scam on top of the first. No one can recover stolen crypto for you in exchange for a fee.

Vijf gouden regels die je hiertegen beschermenFive golden rules that protect you

1Een DAO is niet automatisch veilig. “Decentraal” en “community-gestuurd” klinken mooi, maar als bijna niemand stemt, ligt de macht juist bij wie het meeste kan kopen.A DAO is not automatically safe. “Decentralised” and “community-driven” sound great, but if almost no one votes, power ends up with whoever can buy the most.
2Bewaar je crypto zelf, niet in de kas. Geld in een gemeenschapskas of protocol is nooit “van jou” op de manier waarop munten in je eigen wallet dat zijn. Houd grote bedragen in eigen beheer.Hold your crypto yourself, not in the treasury. Money in a community treasury or protocol is never “yours” the way coins in your own wallet are. Keep large amounts under your own control.
3Niet elk verlies is een hack. Soms wordt er niets gekraakt en volgt de aanvaller gewoon de regels. Lees hoe het stemsysteem van een project werkt vóór je instapt.Not every loss is a hack. Sometimes nothing is cracked and the attacker just follows the rules. Read how a project’s voting system works before you invest.
4Memecoins = extra risico. Veel losse liquiditeit en weinig actieve stemmers maken zo’n project een makkelijk doelwit. Steek er niet meer in dan je kunt missen.Memecoins = extra risk. Lots of loose liquidity and few active voters make such a project an easy target. Don’t put in more than you can afford to lose.
5Trap niet in “recovery”-scams. Niemand haalt gestolen crypto tegen betaling voor je terug.Don’t fall for “recovery” scams. No one recovers stolen crypto for you in exchange for a fee.

Had de scam checker dit gevonden?Would the scam checker have caught this?

De aanval zelf niet — er werd geen contract gehackt en geen wallet-drainer gebruikt. Maar de scam checker kijkt wél naar signalen die de macht rond een token te veel bij één partij leggen, en dát was hier de kern van het probleem.Not the attack itself — no contract was hacked and no wallet drainer was used. But the scam checker does look at signals that concentrate power around a token in one party’s hands, and that was exactly the heart of the problem here.

Doe vóór je in een token met een DAO stapt deze drie checks:Before you buy a token with a DAO, do these three checks:

Bekijk de tokenverdeling — houden een paar adressen zoveel dat ze in hun eentje een stemming kunnen winnen?
Zoek de stemregels op — hoe hoog is het quorum, en zit er een timelock (vertraging) op de uitvoering?
Check de opkomst — worden voorstellen steeds door een handjevol wallets aangenomen?
Look at the token distribution — do a few addresses hold so much that they can win a vote alone?
Look up the voting rules — how high is the quorum, and is there a timelock (delay) on execution?
Check the turnout — do proposals keep passing with just a handful of wallets?

De kern: concentratie is risico. Of het nu sleutels, tokens of stemmen zijn — als weinigen alles kunnen bewegen, kan één partij de hele kas meenemen.The bottom line: concentration is risk. Whether it’s keys, tokens or votes — if a few can move everything, one party can walk off with the whole treasury.

Twijfel je over een token?Not sure about a token?

Plak het contract-adres in de gratis scam checker en krijg direct een risicoscore op basis van 20+ controles — inclusief tokenverdeling en of het contract upgradebaar is.Paste the contract address into the free scam checker for an instant risk score based on 20+ checks — including token distribution and whether the contract is upgradeable.

🔍 Open scam checker →

Bronnen:Sources: CoinDesk (7 jul. 2026)  ·  News.Bitcoin.com (7 jul. 2026)  ·  crypto.news (7 jul. 2026)

Volgende editieNext edition

Editie #007 verschijnt volgende maandag — elke week een nieuwe crypto scam geanalyseerd.Edition #007 arrives next Monday — a new crypto scam analysed every week.

← Alle edities bekijken← View all editions