
Binance found a malicious DAO proposal targeting $1.2 million in treasury tokens and coordinated exchange deposit closures before a vote blocked the transfer.
Alpha Score of 52 reflects moderate overall profile with strong momentum, poor value, moderate quality, strong sentiment.
Binance's security team found a malicious DAO proposal targeting an unnamed project and coordinated with other exchanges to freeze deposits before a vote killed the transfer. The exchange disclosed the incident on Aug. 18, saying roughly $1.2 million in treasury tokens were at risk with less than 48 hours left before execution.
Chief Security Officer Jimmy Su described the response as security that extends beyond the exchange's own infrastructure. "Our team and systems identified a threat that no external security provider had flagged and moved proactively to protect ecosystem users," Su said.
The proposal exploited a low submission barrier in the project's on-chain governance system. DAOs use smart contracts and token-based voting to manage proposals, upgrades and treasury assets. Concentrated voting power can leave those systems open to manipulation. Binance did not name the affected project or token.
A completed governance attack can drain a treasury quickly. BonkDAO confirmed in July that a malicious proposal stole about $20 million in BONK tokens after the attacker amassed enough voting power to authorize the transfer. The KelpDAO bridge incident, while not a governance vote, showed how fast coordination can contain losses after detection. Chainalysis reported attackers stole roughly $292 million from KelpDAO's bridge after compromising off-chain infrastructure. The response blocked another $95 million theft and froze 30,766 ETH.
Su said the incident demonstrated that governance weaknesses can expose users without a conventional code exploit. "The biggest risks in crypto today increasingly target people, access, and behaviors rather than code vulnerabilities," he said. "In this case, the attack stemmed from an underlying governance vulnerability."
Early warnings have also limited losses in consumer-focused crypto scams, though those schemes differ from protocol governance attacks. The FBI's Operation Level Up had notified 8,103 potential cryptocurrency investment fraud victims by December 2025. The agency said 77% were unaware of the scams and estimated its intervention prevented about $511.5 million in losses.
Binance has expanded its monitoring, compliance and recovery operations as attacks increasingly cross protocols, exchanges and off-chain systems. The exchange spends roughly $300 million annually on compliance, with nearly 1,500 employees in related roles, the company said. Its fraud detection operations intercepted $10.53 billion in potential fraud from 2025 through the first quarter of 2026.
Binance will stop processing transactions involving 16 crypto platforms following regulatory developments. Transfers attempted after the applicable deadlines may be reversed or frozen.
Prepared with AlphaScala editorial tooling from the source reporting linked above. Indexable analysis may include a cited Alpha Score value. Publishing checks screen each story before release. Educational coverage, not personalized advice.