A malicious governance proposal passed through Realms DAO infrastructure, enabling attackers to move approximately $20 million in treasury assets from BonkDAO. The incident underscores governance design vulnerabilities in decentralized autonomous organizations operating on Solana.
The attack exploited voter weight mechanics within Realms, the governance infrastructure widely used across the Solana ecosystem to manage proposals, voting, treasuries, and community decision-making. BonkDAO, a Solana-based DAO, fell victim to the scheme after the malicious proposal successfully passed through the Realms voting system.
Governance Attack, Not Blockchain Failure
The exploit did not stem from a failure of the Solana blockchain itself. Instead, the vulnerability lay in governance design and treasury control mechanisms inside the DAO. Governance attacks can be as damaging as smart contract exploits when attackers manipulate voting power, proposal rules, or treasury permissions.
Realms provides the tooling for DAOs to conduct governance across Solana. The platform’s widespread adoption means governance vulnerabilities affect a significant portion of the ecosystem’s decentralized decision-making infrastructure.
Broader DAO Governance Risk
The BonkDAO incident reflects a category of risk that extends beyond Solana. Similar governance vulnerabilities exist across other major ecosystems including Ethereum, BNB Chain, Arbitrum, and Optimism. Treasury security in decentralized governance systems remains a structural challenge when voting mechanisms, delegation, or proposal execution can be exploited by malicious actors.
The $20 million drain represents one of the clearest recent examples of DAO governance risk crystallizing into direct financial loss on Solana. The attack highlights the distinction between base-layer blockchain security and application-layer governance design, where even robust underlying infrastructure cannot prevent attacks that operate within the rules of a flawed governance system.