
A hacker spent $4M to acquire voting power and pass a malicious proposal, draining $20M from BonkDAO. The incident highlights the growing risk of governance manipulation over smart contract bugs.
A hacker spent roughly $4 million to acquire enough voting power to pass a malicious governance proposal during a period of low participation, draining about $20 million from BonkDAO’s treasury. The underlying smart contracts functioned exactly as designed, Immunefi said. The vulnerability sat entirely in the governance framework, where low turnout made influence cheap to buy.
A similar pattern hit Humanity Protocol earlier this year, with losses exceeding $30 million. In that case, a compromised private key belonging to a team member was the entry point, not any code flaw, Immunefi noted.
The two events belong to a broader shift in crypto security. Through 2026, the sector has recorded roughly $972 million in total losses from security incidents, according to Immunefi’s data. The majority of stolen value no longer comes from bugs in smart contract logic. Instead, funds are exiting through stolen signing keys, weak operational processes, and governance mechanisms that can be manipulated.
Historical data from 2021 to 2025, covering hundreds of incidents, shows that operational failures – especially at centralized exchanges and in key management – account for a disproportionate share of the losses. In the 2024–2025 period alone, more than half of the value lost across nearly 200 events came from issues above the contract layer, such as custody and authorization controls.
That does not mean code-level vulnerabilities have disappeared. Long-running protocols often still harbor serious flaws. A high percentage of programs active for five years or longer eventually reveal critical issues, and continuous upgrades introduce new attack surfaces. What has improved is the effectiveness of ongoing, incentive-driven scrutiny, Immunefi said.
Live bug bounty programs, combined with monitoring and rapid response, allow independent researchers to find weaknesses before attackers can exploit them. A typical bounty payout of about $20,000 often prevents losses that would average tens of millions of dollars, returning exceptional value on security spend.
Traditional audits, while useful, capture only a snapshot of code at a single point in time. They offer no assurance about key storage, the integrity of signers, or the resilience of governance rules under real-world conditions. One protocol underwent multiple audits yet still suffered a nine-figure loss, Immunefi said.
True resilience requires treating every element – code, keys, personnel, governance structures, and monitoring systems – as an active, continuous attack surface. Security must be maintained through persistent testing by researchers whose incentives stay aligned with finding problems early. Only when that approach extends beyond smart contracts to the full operational environment will the industry cut the scale of catastrophic incidents that continue to define much of 2026’s security landscape.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.