Specter reveals clues about a BONK DAO governance attack, suggesting that the financial flows of Realms' founder may be linked to the attackers.
Related
BonkDAO was attacked by a malicious governance proposal, resulting in the theft of approximately $20 million in BONK.
According to Odaily Odaily, Bonk Inu's official X account stated that BonkDAO suffered a malicious governance proposal attack, resulting in the theft of approximately $20 million worth of BONK tokens from its DAO vault. Attackers allegedly transferred BonkDAO vault assets through a questionable governance proposal. The stolen BONK subsequently began flowing into exchanges, putting downward pressure on the BONK price. Data from The Block shows that the BONK price has fallen by more than 9%. South Korean exchange Upbit subsequently issued a statement saying it had temporarily suspended BONK deposits and withdrawals in response to the incident and to guard against potential risks. (The Block)
The ENS governance crisis has escalated, and the community plans to propose delegating 5 million ENS tokens to reform the allocation of voting rights.
According to Foresight News , AvsA, a core contributor to the ENS DAO, recently released a draft proposal on the forum, suggesting reforming the DAO governance structure by delegating (rather than distributing) 5 million ENS tokens. According to the draft, the 5 million ENS tokens will be transferred from the DAO treasury to a multi-delegation contract, with 1 million tokens allocated to each of five stakeholder groups (users, integrators, developers, traditional domain name system participants, and the governance community). A maximum of 10 candidates from each group will be selected based on criteria. The delegated parties will not receive any financial rights in the tokens, only voting rights. If a party does not participate in voting for more than 6 months, their voting rights will be redistributed. The proposal is based on the fact that ENS governance is in crisis, with a single proxy holding enough voting power to pass any proposal independently, and total delegated votes continuing to decline, resulting in significantly low participation in recent proposal voting. This proposal is currently in the feedback collection phase and has not yet entered the formal voting process.
PeckShield: In June 2026, the crypto space experienced 40 major hacking attacks, resulting in total losses of $75.87 million.
According to Foresight News and PeckShield monitoring, 40 major hacking incidents occurred in the cryptocurrency sector in June 2026, with total losses of approximately $75.87 million, a 7.13% decrease compared to $81.7 million in May. The largest losses were seen in the Humanity Protocol attack, with approximately $31 million; Syscoin Bridge suffered approximately $10 million; and the MEV bot suffered approximately $7.5 million. Other affected entities included Secret Network, Polymarket users, SecondFi, TESSERA, Aztec Bridge, and Aztec Connect. Notably, Aztec Bridge and Aztec Connect were attacked within the same month, resulting in a combined loss of approximately $4 million. PeckShield also pointed out that the Humanity Protocol attackers actively laundered the stolen funds through multiple chains, including BTC, Solana, Hyperliquid, and BNB Chain, and that these funds showed signs of being mixed with the stolen money from the KelpDAO attackers, suggesting a possible connection between the threat actors behind both incidents.
KelpDAO sues LayerZero, CEO over $292M rsETH bridge exploit
KelpDAO says LayerZero endorsed its bridge setup before the attack, while CEO Bryan Pellegrino has dismissed the lawsuit as meritless.
CertiK Hack3D Report: Web3 Losses Exceed $1.3 Billion in the First Half of 2026, Attacks Are Accelerating Towards High-Value Targets
Odaily Odaily reports that Web3 security company CertiK released its "Hack3D: First Half of 2026 Report." The report shows that 344 security incidents occurred in the Web3 ecosystem in the first half of 2026, resulting in a total loss of approximately $1.32 billion. While this figure represents a 46.8% decrease compared to the same period last year, if the impact of the $1.45 billion security incident involving Bybit is excluded, the actual loss in the first half of this year increased by approximately 28% year-on-year, indicating that the overall security environment of the industry has not seen substantial improvement. The report points out that wallet theft has become the type of attack causing the biggest financial loss, resulting in approximately $450 million in losses in the first half of the year. Meanwhile, although the number of phishing attacks decreased by more than 50% year-on-year, the amount of losses only decreased by about 10.8%, reflecting that attackers are shifting their focus to high-net-worth individuals and institutions, launching more targeted and high-value attacks. Furthermore, code vulnerabilities remain the most frequent type of attack, with 204 related incidents. CertiK believes that attackers are increasingly targeting long-running smart contracts that lack re-auditing. The report also shows that large-scale attacks continue to dominate industry losses, with the Kelp DAO and Drift Protocol incidents causing approximately $577 million in losses, accounting for 44% of total losses in the first half of the year. In terms of the number of incidents, the impact of individual attacks, and changes in attack patterns, the Web3 industry is facing increasingly complex and continuously escalating security challenges.
The Fabric Foundation has launched the ROBO governance system and established a Foundation Security Committee.
According to Foresight News , the Fabric Foundation announced that the ROBO governance system has been officially launched. The team has opened a dedicated governance space on the Snapshot platform and established a Foundation Security Committee to oversee overall management, thus initiating co-governance with the community. ROBO holders can vote free of charge on Snapshot, with voting weight calculated based on token holdings. All proposals, votes, and decisions are publicly recorded. Proposals undergo preliminary evaluation, community discussion, a five-day snapshot voting period, council review, and final decision announcement. The council is also responsible for preventing risks such as bribery and Sybil attacks. Founding members of the Foundation's Security Committee include Jerry Huang, founder of Silicon Valley Center of Robotics; Shivani Phull, director of HashPoint Advisory; and Clara Cheng, business head of Thrive Horizon Ltd. The first proposal is a preliminary evaluation of the first phase of the ROBO governance system, which the community can view and vote on in the official Snapshot space.