Attackers stole approximately $72,000 in STRONG and STRNGR tokens through malicious proposals to control StrongBlock's obsolete on-chain governance system
Incident summary
An attacker took control of StrongBlock's obsolete governance system and stole approximately $72,000. A malicious proposal allowed an attacker to gain administrator rights on the protocol's Governor contract. After upgrading the Governor contract, the attacker stole 32,695 STRONG and 383,447 STRNGR tokens. The incident took advantage of governance controls rather than a smart contract vulnerability. The attack is one of recent cryptocurrency security incidents targeting governance systems, infrastructure and wallet software.
According to blockchain security firm Defimon Alerts, the attacker gained enough voting rights in StrongBlock's governance system to pass a proposal that eventually transferred management control of the agreement's Governor contract to his own name, and the funds were subsequently transferred.
The attacker did not exploit the vulnerability of the StrongBlock smart contract, but gained privileged access through the protocol's own governance process. After gaining administrator privileges, the attacker upgraded the Governor agent to a new implementation contract that allows arbitrary contract calls using the Governor's privileges. This incident is one of a series of recent cryptocurrency security incidents targeting governance systems, supporting infrastructure and wallet software. These attacks do not rely solely on smart contract vulnerabilities, but are carried out through different attack paths.
StrongBlock governance system is used to seize control of the protocol
Before the attack, the attacker accumulated a majority share of the protocol STRONG governance tokens. Defimon Alerts pointed out that after the project was scrapped, the tokens were almost worthless. With enough voting power, the attacker submitted a governance proposal instructing the Governor's Upgrader contract to execute setPendingAdmin(attacker), setting the attacker's address to a pending administrator. Rather than bypassing the governance process, the proposal went through all necessary stages in a step-by-step manner: getting enough votes, entering the queue, and executing in accordance with the protocol's normal governance process, ultimately transferring management control of the Governor agent to the attacker.
Administrative permissions then allowed an attacker to replace the Governor implementation with a minimalist and unverified contract that included a forward(address, bytes) function. According to Defimon Alerts, the function is limited to the attacker's external account and actually serves as an arbitrary call mechanism that allows the attacker to execute transactions between StrongBlock's contracts with the authority of the Governor. The token transfer occurs in a subsequent transaction.
More than 400,000 tokens were withdrawn from the pool
Using the upgraded implementation contract, the attacker performed a transaction that transferred assets from the protocol pool rather than exploiting errors in the protocol contract logic. Defimon Alerts said the attackers removed 32,695 STRONG tokens and 383,447 STRNGR tokens, with an estimated value of approximately $72,000 worth of stolen assets. The security company characterized the incident as a governance takeover because all critical operations, including administrator changes and contract upgrades, were completed through governance permissions rather than exploiting software vulnerabilities. By replacing the Governor implementation first before transferring funds, the attacker turns the governance contract itself into a mechanism for authorizing transfers.
Governance attacks differ from other recent cryptocurrency exploits
Recent security incidents suggest that attackers are increasingly targeting different parts of the cryptocurrency infrastructure. Late last month, Ostium, the decentralized perpetual contract protocol, concluded that attackers had unauthorized access to its off-chain infrastructure and stolen 23.75 million USDC, rather than exploiting its smart contract vulnerability. According to Ostium's post-mortem analysis, fraudulent BTC-USD price reports submitted through trusted infrastructure allowed attackers to generate fake trading profits and ultimately settle them out of the agreement's public OLP liquidity vault. Early analysis by blockchain security company Blockaid reached a similar conclusion: manipulation of oracle reports rather than contract code vulnerabilities led to the attack.
In addition, the Coldcard wallet incident originated from a firmware issue introduced in a software update in March 2021. Coinkite and Block's Bitcoin engineering and security team concluded that the affected firmware used a deterministic pseudo-random number generator to generate wallet seeds instead of the expected hardware random number generator, thereby reducing the entropy used to create private keys. Galaxy Research has confirmed that a total of 1596 BTC was stolen from approximately 7300 addresses associated with three waves of attacks. The research company also found a suspected fourth wave of coordinated attacks involving an additional 448.7 BTC, but has not yet included these addresses in its confirmation total because it still has to wait for more victim confirmation.
Coldcard review has been extended to full-scale Bitcoin security checks
The Coldcard incident has prompted developers to review the broader scope of the Bitcoin software ecosystem. Earlier this week, Bitcoin developer Calle said that the volunteer team "Bitcoin Red Team" had completed an AI-assisted and manual review of 390 bitcoin-related repositories and found 4,962 potential security issues, of which 720 were classified as high or severe. According to Calle, about 21.4% of reports found that they had been replicated through manual verification before being privately disclosed to affected developers. The review campaign covers Bitcoin wallets, cryptography libraries, infrastructure software and other open source projects. Calle said OpenSats provides approximately $10,000 a day in computing costs, while Kimi Moonshot provides AI accounts and access to its Kimi K3 model to support the effort.
Governance is still the attack surface
Unlike Ostium exploits or Coldcard wallet incidents, StrongBlock attacks do not rely on compromised infrastructure, oracle manipulation, or cryptographic weaknesses. Instead, the attacker first gained governance control and then modified the protocol's own administrator contract. According to Defimon Alerts, by upgrading the Governor agent to an implementation contract that includes the restricted forward(address, bytes) function, the attacker's wallet gained exclusive rights to perform arbitrary calls through the Governor contract. The stolen assets were then transferred through the agreement's permissions granted after the governance proposal was completed, demonstrating that even if development activities were largely stopped, the abandoned governance system could still exercise management control over the agreement contract.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following