How it worked. The attack began on June 30, when an anonymous actor submitted Bonk Improvement Proposal #76, titled "Sowellian BonkDAO," to BonkDAO's governance platform on Solana Realms . The proposal was dressed up in the language of a turnaround — it sought to "implement Sowellian governance, install new members and council, rebuild financial stability" — but included a hidden clause that would transfer 4.43 trillion BONK from the treasury to an attacker-controlled address
. Over the following days, the attacker spent approximately $4.4 million buying BONK through exchange wallets, accumulating enough voting power to meet quorum
. Only seven addresses voted on the proposal, and the wallets linked to the attacker controlled 99.878% of the voting weight, according to SlowMist founder Yu Xian
. Because the DAO had no timelock and proposals executed automatically, the treasury transfer went through without delay once the vote concluded
.
What was lost, and what wasn't. The stolen 4.426 trillion BONK was valued at roughly $20–$21.2 million at the time of the transfer . Most of the tokens remained in the attacker's multisig wallet, though about $148,000 was sent to an OKX address
. BonkDAO confirmed that user funds and the BONK token contract itself were not compromised — the loss was limited to the community treasury
. The DAO said it was coordinating with exchanges, the Solana Foundation, and law enforcement to recover the assets
.
Immediate price impact. BONK fell roughly 8–10% on the news, dropping from around $0.0000045 to below $0.0000040 within days . The exploit dented market confidence and raised concerns about the token-weighted governance model more broadly
.
Upbit designated BONK a "cautionary trading item" on July 7, 2026 — the day after the governance attack became public — and opened a formal review . The exchange stated that its review identified "unresolved security incidents" and the project's "failure to disclose material information" following the $20 million treasury drain
. After approximately one month of evaluation, Upbit concluded that the issues had not been resolved and moved to delist the token
. Notably, Upbit said market performance and trading volume did not factor into the decision — the delisting was based entirely on security and disclosure concerns
.
Upbit also announced that deposits to the exchange after the cutoff date would not be credited, and services such as airdrops, wallet upgrades, and hard forks for the delisted token would not be supported .
On August 7, the delisting news pushed BONK to an intraday low of approximately $0.00000249–$0.00000255, its lowest price since November 2023 . The decline was amplified by several reinforcing factors:
The delisting was a severe blow to BONK's market structure. The token's market cap fell below $250 million in the weeks following the governance attack, and the loss of Upbit's fiat on-ramp made it harder for Korean retail investors to accumulate BONK . As of August 8, the nearest support level was the recent low of $0.00000248, with an extended decline possible if BONK fails to reclaim the 7-day moving average of $0.00000281
. Roughly $19 million worth of stolen BONK remained in the attacker's wallet as of mid-July, creating an overhang that could further depress price if those tokens are liquidated
.
For meme coin investors, the BONK case underscores a critical risk: a governance attack does not require breaking code — it only requires buying enough votes. Combined with the loss of exchange listings, the damage to price and liquidity can be swift and severe.