Binance security team intercepted a malicious governance proposal to avoid $1.2 million stolen
Binance said that its security team discovered and blocked an attempt to steal $1.2 million from a blockchain project's funds pool through a malicious governance vote. The exchange did not disclose which project was targeted.
The Binance security team has flagged a governance proposal aimed at stealing $1.2 million from the project's funds, with less than 48 hours left before the proposal takes effect.
After Binance issued an alert and coordinated with other exchanges to suspend deposits, the project community voted to reject the proposal. Binance said there were no financial losses.
Binance did not disclose the names of the affected projects.
"User protection is not only about the security of our own platforms, but also about strengthening the ability of the entire ecosystem to withstand attacks. Recently, our security team discovered and helped stop a $1.2 million governance attack against a project agreement. This case demonstrates what 'design security'..."
-Binance official account, August 18, 2026
Binance described the incident after
The attacker attacked using the low threshold for submitting governance proposals on an unnamed project decentralized platform. Binance said the threshold was low enough for attackers to try to circumvent the normal requirement for projects to pass a vote.
Binance's monitoring system flagged the proposal less than 48 hours before it was implemented. The exchange said it contacted the project directly and told it to vote down the proposal, while coordinating with other exchanges that listed the token to temporarily suspend deposits-a measure designed to prevent stolen funds from being sold quickly if the vote turns out to be reversed.
The project community voted against the proposal. Binance said the attack was stopped before execution and there were no financial losses.
Jimmy Su, chief security officer of Binance, said that this case shows what happens when the concept of "security by design" extends beyond the exchange's own platform.
Unfilled Blank
Binance did not disclose the name of the project, token or wallet address involved. It did not release proposal IDs, transaction hashes or any voting records to allow external parties to verify the $1.2 million amount, timeline or results it described.
The affected projects themselves remained silent. As of August 19, no security research company or blockchain analysis agency has commented on this incident.
BonkDAO's $20 million lesson (not silent)
The mechanism described by Binance-by gaining enough governance voting rights to promote a proposal aimed at emptying the capital pool-is not new. This is the same pattern that cost BonkDAO $20 million in early July: attackers spent $4.4 million to gain voting rights and promoted a proposal that included hidden instructions to move money out of the pool. The second case occurred on July 15 at BarnBridge, when approximately $777,000 was stolen and the attacker used a small governance position to hijack the upgrade path.
Blockaid estimates that governance attacks stole approximately $22 million from seven protocols in eight weeks this summer.
BonkDAO and BarnBridge were publicly named the moment the treasury was attacked, and the on-chain records of both attacks were made public within hours. However, this incident neither disclosed the project name nor any online records.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following