EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Binance says it has stopped a $1.2 million DAO attack, but refuses to disclose the target

2026-08-20 00:18:13
Bookmark

Binance security team intercepted a malicious governance proposal to avoid $1.2 million stolen

Binance said that its security team discovered and blocked an attempt to steal $1.2 million from a blockchain project's funds pool through a malicious governance vote. The exchange did not disclose which project was targeted.

The Binance security team has flagged a governance proposal aimed at stealing $1.2 million from the project's funds, with less than 48 hours left before the proposal takes effect.

After Binance issued an alert and coordinated with other exchanges to suspend deposits, the project community voted to reject the proposal. Binance said there were no financial losses.

Binance did not disclose the names of the affected projects.

"User protection is not only about the security of our own platforms, but also about strengthening the ability of the entire ecosystem to withstand attacks. Recently, our security team discovered and helped stop a $1.2 million governance attack against a project agreement. This case demonstrates what 'design security'..."

-Binance official account, August 18, 2026

Binance described the incident after

The attacker attacked using the low threshold for submitting governance proposals on an unnamed project decentralized platform. Binance said the threshold was low enough for attackers to try to circumvent the normal requirement for projects to pass a vote.

Binance's monitoring system flagged the proposal less than 48 hours before it was implemented. The exchange said it contacted the project directly and told it to vote down the proposal, while coordinating with other exchanges that listed the token to temporarily suspend deposits-a measure designed to prevent stolen funds from being sold quickly if the vote turns out to be reversed.

The project community voted against the proposal. Binance said the attack was stopped before execution and there were no financial losses.

Jimmy Su, chief security officer of Binance, said that this case shows what happens when the concept of "security by design" extends beyond the exchange's own platform.

Unfilled Blank

Binance did not disclose the name of the project, token or wallet address involved. It did not release proposal IDs, transaction hashes or any voting records to allow external parties to verify the $1.2 million amount, timeline or results it described.

The affected projects themselves remained silent. As of August 19, no security research company or blockchain analysis agency has commented on this incident.

BonkDAO's $20 million lesson (not silent)

The mechanism described by Binance-by gaining enough governance voting rights to promote a proposal aimed at emptying the capital pool-is not new. This is the same pattern that cost BonkDAO $20 million in early July: attackers spent $4.4 million to gain voting rights and promoted a proposal that included hidden instructions to move money out of the pool. The second case occurred on July 15 at BarnBridge, when approximately $777,000 was stolen and the attacker used a small governance position to hijack the upgrade path.

Blockaid estimates that governance attacks stole approximately $22 million from seven protocols in eight weeks this summer.

BonkDAO and BarnBridge were publicly named the moment the treasury was attacked, and the on-chain records of both attacks were made public within hours. However, this incident neither disclosed the project name nor any online records.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP