
De BonkDAO-aanval: hoe iemand $20 miljoen uit de kas stemde zonder één regel te brekenThe BonkDAO attack: how someone voted $20 million out of the treasury without breaking a single rule
$20 miljoen uit de kas gestemd — zonder hack: zo werkt een governance-aanval$20 million voted out of the treasury — with no hack: how a governance attack works
BonkDAO beheert de kas achter BONK, een van de bekendste memecoins op Solana. Op 6 juli kocht een aanvaller voor ~$4,4 miljoen aan BONK — net genoeg om in zijn eentje het stemquorum te halen. Daarna diende hij één voorstel in: maak de hele kas over naar mijn wallet. Slechts 7 wallets stemden, meer dan 18.000 leden deden niets, en het voorstel werd automatisch uitgevoerd. Resultaat: ~$20 miljoen weg, ~5x rendement voor de aanvaller. Geen code gekraakt — de regels van het systeem waren zélf de zwakke plek.BonkDAO manages the treasury behind BONK, one of the best-known memecoins on Solana. On 6 July an attacker bought ~$4.4 million in BONK — just enough to meet the voting quorum single-handedly. Then they submitted one proposal: send the entire treasury to my wallet. Only 7 wallets voted, more than 18,000 members did nothing, and the proposal executed automatically. Result: ~$20 million gone, a ~5x return for the attacker. No code was cracked — the system’s own rules were the weak spot.
Wat is er precies gebeurd?What exactly happened?
BONK is een van de grootste memecoins op de Solana-blockchain. Rondom dat token zit een DAO: een “decentrale autonome organisatie”. Simpel gezegd is dat een gemeenschapskas waarover de tokenhouders samen stemmen. Wie tokens heeft, mag meebeslissen — hoe meer tokens, hoe zwaarder je stem. Op 6 juli 2026 werd precies dat systeem tegen zichzelf gebruikt.BONK is one of the largest memecoins on the Solana blockchain. Around that token sits a DAO: a “decentralised autonomous organisation”. In plain terms, that is a community treasury the token holders vote on together. Whoever holds tokens gets a say — the more tokens, the heavier your vote. On 6 July 2026, that exact system was turned against itself.
Om te voorkomen dat één iemand alles beslist, had de DAO een quorum: er moest voor minstens 1% van alle tokens worden meegestemd voordat een voorstel geldig was. Klinkt veilig. Maar de aanvaller kocht simpelweg voor ~$4,4 miljoen aan BONK — net iets meer dan die 1% — en had zo in zijn eentje genoeg stemkracht om het quorum te halen.To stop any one person deciding everything, the DAO had a quorum: at least 1% of all tokens had to vote before a proposal was valid. Sounds safe. But the attacker simply bought ~$4.4 million in BONK — just over that 1% — giving them, alone, enough voting power to meet the quorum.
Vervolgens diende hij één voorstel in: maak ~4,426 biljoen BONK (ongeveer $20 miljoen) over van de gemeenschapskas naar zijn eigen wallet. Slechts 7 wallets stemden mee, en de aanvaller was goed voor 99,9% daarvan. Meer dan 18.000 leden stemden helemaal niet — een opkomst van amper 2,9%. Het voorstel “won” dus met 99,9% ja-stemmen en werd automatisch uitgevoerd. Er zat geen vertraging (timelock) of noodrem op om zo’n voorstel nog te blokkeren.Then they submitted one proposal: transfer ~4.426 trillion BONK (around $20 million) from the community treasury to their own wallet. Only 7 wallets voted, and the attacker accounted for 99.9% of them. More than 18,000 members did not vote at all — a turnout of barely 2.9%. So the proposal “won” with 99.9% yes votes and executed automatically. There was no delay (timelock) or emergency brake to block such a proposal.
Het bijzondere — en verontrustende — is dat er geen enkele regel werd gebroken. Geen gehackte code, geen gestolen wachtwoord. De aanvaller volgde precies de spelregels van de DAO en verdiende zo ongeveer 5x zijn inleg. De koers van BONK zakte 8 tot 10%. Op het moment van schrijven staat het grootste deel van de buit (~$19 miljoen) nog stil in de wallet van de aanvaller; BonkDAO probeert samen met de Solana Foundation, exchanges en justitie het geld te bevriezen en terug te halen.The striking — and unsettling — part is that no rule was broken. No hacked code, no stolen password. The attacker followed the DAO’s rules to the letter and earned roughly 5x their stake. BONK’s price fell 8 to 10%. At the time of writing, most of the proceeds (~$19 million) still sit untouched in the attacker’s wallet; BonkDAO is working with the Solana Foundation, exchanges and law enforcement to freeze and recover the funds.
“Geen code gehackt, geen wachtwoord gestolen. De aanvaller volgde de regels — en dat was precies het probleem. Als bijna niemand stemt, is een DAO-kas te koop.”“No code hacked, no password stolen. The attacker followed the rules — and that was exactly the problem. When almost no one votes, a DAO treasury is for sale.”
De tijdlijn — stap voor stapThe timeline — step by step
De rode vlaggen — waar je op moet lettenThe red flags — what to watch for
Beleg je in een token met een DAO of gemeenschapskas? Dan bepalen de stemregels mee hoe veilig je geld is. Deze signalen vergroten het risico op een governance-aanval — en de meeste kun je vooraf checken:Investing in a token with a DAO or community treasury? Then the voting rules help decide how safe your money is. These signals raise the risk of a governance attack — and most you can check in advance:
Vijf gouden regels die je hiertegen beschermenFive golden rules that protect you
Had de scam checker dit gevonden?Would the scam checker have caught this?
De aanval zelf niet — er werd geen contract gehackt en geen wallet-drainer gebruikt. Maar de scam checker kijkt wél naar signalen die de macht rond een token te veel bij één partij leggen, en dát was hier de kern van het probleem.Not the attack itself — no contract was hacked and no wallet drainer was used. But the scam checker does look at signals that concentrate power around a token in one party’s hands, and that was exactly the heart of the problem here.
Doe vóór je in een token met een DAO stapt deze drie checks:Before you buy a token with a DAO, do these three checks:
✓ Bekijk de tokenverdeling — houden een paar adressen zoveel dat ze in hun eentje een stemming kunnen winnen?
✓ Zoek de stemregels op — hoe hoog is het quorum, en zit er een timelock (vertraging) op de uitvoering?
✓ Check de opkomst — worden voorstellen steeds door een handjevol wallets aangenomen?✓ Look at the token distribution — do a few addresses hold so much that they can win a vote alone?
✓ Look up the voting rules — how high is the quorum, and is there a timelock (delay) on execution?
✓ Check the turnout — do proposals keep passing with just a handful of wallets?
De kern: concentratie is risico. Of het nu sleutels, tokens of stemmen zijn — als weinigen alles kunnen bewegen, kan één partij de hele kas meenemen.The bottom line: concentration is risk. Whether it’s keys, tokens or votes — if a few can move everything, one party can walk off with the whole treasury.
Plak het contract-adres in de gratis scam checker en krijg direct een risicoscore op basis van 20+ controles — inclusief tokenverdeling en of het contract upgradebaar is.Paste the contract address into the free scam checker for an instant risk score based on 20+ checks — including token distribution and whether the contract is upgradeable.
🔍 Open scam checker →Bronnen:Sources: CoinDesk (7 jul. 2026) · News.Bitcoin.com (7 jul. 2026) · crypto.news (7 jul. 2026)