
Binance flagged a malicious DAO proposal with less than 48 hours to execution. The community voted it down; verification of the $1.2M figure is still pending.
Binance said on Aug. 18 that its security team helped stop a malicious governance proposal that could have exposed roughly $1.2 million in tokens from the treasury of an unnamed decentralized autonomous organization (DAO).
Binance's monitoring systems independently identified the proposal when less than 48 hours remained before execution, the exchange said. Binance then contacted the project and coordinated with other centralized exchanges to close deposits for the affected token. The proposal's submission date and the exact execution deadline were never disclosed.
The project's community voted against the proposal before it could execute, according to Binance's published account. No funds were lost. Binance did not say how many votes rejected it or whether delegates had changed earlier positions. Whether project administrators used emergency authority went unstated too.
The attacker exploited a weakness in the project's on-chain governance mechanism. Binance said the threshold for creating a proposal was low enough to bypass the protocol's intended requirements.
Binance did not explain what those requirements were or how the proposal would have accessed the treasury. It also did not say whether the attacker had accumulated governance tokens or borrowed voting power. Whether the attacker concealed malicious instructions inside executable code went unanswered.
Governance systems let token holders vote on treasury spending and protocol changes. Low proposal thresholds and weak participation give attackers an opening. Execution delays too short for delegates to respond leave little time to mount a defense. Binance said the affected DAO's voting process left enough time for the community to intervene.
Binance and the other exchanges closed deposits as a precaution in case the proposal passed and the attacker tried to move treasury tokens through centralized venues. Deposit closures would not have stopped the proposal from executing. They cut off one route for selling or converting compromised tokens afterward.
Binance Chief Security Officer Jimmy Su said the team identified a threat that "no external security provider had flagged." Neither the unnamed project nor independent security firms have confirmed that claim.
The exchange did not identify the project, the affected token, the governance platform, or the cooperating exchanges.
No proposal identifier, contract address, vote record, or blockchain transactions were published either. Independent verification of the $1.2 million exposure and the intervention timeline is impossible without those details.
Because the affected asset remains undisclosed, no identifiable market reaction followed. No funds moved under the proposal. The case registers as an attempted attack, not a completed treasury theft.
The incident follows other governance attacks on protocol treasuries. Attackers drained roughly $20 million from BonkDAO through a malicious proposal in July, as crypto.news previously reported. In another case, concerns about purchased voting power affecting DAO decisions showed how low participation and delegated votes can weaken governance protections without exploiting contract code.
Stopping a repeat means changing the rules that let the proposal reach a vote. Controls include higher submission thresholds, longer timelocks, quorum requirements, and independent review of executable proposals.
Emergency cancellation authority can also stop malicious actions. That power introduces centralized control, so projects weigh rapid intervention against the governance model promised to token holders.
Binance has not said whether the affected project completed those changes. It also has not announced plans to publish further technical details or identify the project once the immediate risk passes. A public postmortem would confirm the vote and show whether the same attack path remains open. Until then, the intervention and the $1.2 million figure rest mainly on Binance's account.
Prepared with AlphaScala editorial tooling from the source reporting linked above. Indexable analysis may include a cited Alpha Score value. Publishing checks screen each story before release. Educational coverage, not personalized advice.