BonkDAO was attacked by a malicious governance proposal, resulting in the theft of approximately $20 million in BONK.
Related
CertiK: Edel Finance's lending market was attacked, resulting in losses of approximately $204,000.
According to Mars Finance, CertiK monitoring indicates that Edel Finance's lending market has been attacked. Attackers manipulated the collateral price of wGOOGLx (which depends on the balance of its GOOGLx account) to conduct illegal lending, resulting in a loss of approximately $204,000 for the platform. The affected transactions have been flagged, and security agencies are alerting users to the risks.
Data: CertiK monitored an attack on Hinkal Protocol, resulting in the theft of approximately $800,000 in USDC.
According to Mars Finance, CertiK monitoring revealed suspicious transactions occurring on the decentralized privacy protocol Hinkal Protocol. Address (0xbB3...fc20) executed multiple "Transact" transactions after initiating a "Proofless Deposit," withdrawing approximately $800,000 USDC from the Hinkal contract.
Specter reveals clues about a BONK DAO governance attack, suggesting that the financial flows of Realms' founder may be linked to the attackers.
According to Mars Finance, on-chain security firm Specter released preliminary findings of its investigation into the BONK DAO governance attack. Tracing the on-chain fund flow revealed significant suspicious activity: financial transactions were found between Realms founders' and Crypto Notte-related addresses and the wallet of the suspected attacker. The analysis indicates that the attacker released a malicious governance proposal on June 30th, with a pass threshold of 1% of the total circulating supply of BONK. From July 4th to 5th, the attacker used approximately $4 million in cryptocurrency purchases on exchanges and MarginFi lending to acquire sufficient voting power to push the proposal through and complete the governance attack.
Solana has launched an on-chain governance mechanism, requiring proposals to receive 15% staking support before they can be voted on.
ChainCatcher reports that the Solana Foundation has officially launched its on-chain governance mechanism, Solana Governance Proposals (SGP). Validators can now submit, support, and decide on core protocol decisions through SGP. All proposals are conducted on-chain, using a staking-weighted voting mechanism and verified via Merkle proofs. Any validator with at least 100,000 SOL delegates can initiate an SGP. Unlike Solana Improvement Documents (SIMD), which focus on technical and protocol changes, SGP primarily serves to express opinions on ecosystem governance. Proposals must receive at least 15% network staking support before entering the formal voting phase.
SlowMist: npm ecosystem attacked by 30 malicious packages, developer credentials and private keys at risk of being stolen.
PANews reported on July 1st that, according to SlowMist security alerts, its monitoring system detected a coordinated malicious supply chain attack targeting the npm ecosystem. Attackers deployed JavaScript information-stealing programs through forged trading bot repositories and DeFi-themed npm packages, involving 30 malicious npm packages. Among them, stake-math@3.5.4 appeared as a locked dependency in the donoaccestag/forex-mt5-trading-bot repository. This repository exhibited clear anomalies, with approximately 23,000 highly homogeneous forked repositories concentrated under the poly-stocks account. Attackers could steal sensitive local data such as encrypted wallets, browser cookies, passwords, developer credentials, private keys, seed phrase, and API tokens from the source code.
The Ethereum blockchain project BackedFi suffered a suspicious attack, resulting in a loss of approximately $204,200.
PANews reported on July 1 that, according to TenArmorAlert monitoring, the Ethereum blockchain project BackedFi suffered a suspicious attack, resulting in a loss of approximately $204,200.