Binance stops malicious DAO proposal targeting $1.2M treasury in under 48 hours

Via bitget.com

Binance stops malicious DAO proposal targeting $1.2M treasury in under 48 hours

The exchange's security team flagged the governance attack just before execution, coordinating with other platforms to freeze deposits and prevent losses

Binance’s security team caught a governance attack mid-flight, flagging a malicious proposal aimed at draining roughly $1.2 million from an unnamed DAO’s treasury with less than 48 hours on the clock before it could execute. The community ultimately voted the proposal down, and no funds were lost.

The incident, detected on August 18, 2026, marks the second major governance-targeted attack on a DAO in as many months.

How the attack was stopped

Binance’s internal monitoring systems picked up the suspicious proposal and immediately alerted the affected project’s team. From there, the exchange coordinated with other centralized platforms to freeze deposits tied to the DAO’s tokens as a precautionary measure.

That cross-platform coordination bought the DAO’s community enough time to mobilize. Token holders rallied to vote against the proposal, effectively killing it before any funds could move.

Advertisement

Governance attacks are the new smart contract exploits

Binance Chief Security Officer Jimmy Su pointed to this shift directly, noting that growing risks in the crypto space are increasingly centered on human behaviors and access rather than platform-specific code vulnerabilities.

DAO governance systems typically allow token holders to submit proposals that, if approved by a majority vote, execute automatically on-chain. But the mechanism assumes good faith participation, and bad actors have figured out how to game that assumption.

Low voter turnout is the most common enabler. If only a small fraction of token holders actively participate in governance votes, an attacker doesn’t need a massive stake to push through a malicious proposal. They just need enough tokens to outvote whoever happens to show up.

This latest incident came barely a month after BonkDAO suffered a successful governance hack in July 2026 that resulted in approximately $20 million in losses. That attack used a similar playbook: submit a proposal that looks innocuous or technical, hope most token holders don’t scrutinize it, and watch the treasury drain itself through a perfectly valid on-chain vote.

What this means for DAO security

The successful intervention highlights a somewhat ironic dynamic in the decentralized world: centralized exchanges still play a critical role as security backstops. Binance didn’t just detect the threat. It actively coordinated deposit freezes across multiple platforms, a response that would be impossible in a purely decentralized ecosystem.

For DAOs, the takeaway is structural. Governance frameworks need hardening. That could mean implementing time-lock mechanisms that give communities longer windows to review proposals, requiring higher quorum thresholds for treasury-related votes, or building automated alert systems that flag unusual proposal activity.

Some projects have already begun experimenting with “optimistic governance” models, where proposals pass by default unless challenged, combined with security councils that can veto obviously malicious actions. Others are exploring delegation systems that concentrate voting power with vetted, active participants rather than leaving it scattered across passive holders.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.
Binance stops malicious DAO proposal targeting $1.2M treasury in under 48 hours
Binance stops malicious DAO proposal targeting $1.2M treasury in under 48 hours

The exchange's security team flagged the governance attack just before execution, coordinating with other platforms to freeze deposits and prevent losses

Via bitget.com

Binance’s security team caught a governance attack mid-flight, flagging a malicious proposal aimed at draining roughly $1.2 million from an unnamed DAO’s treasury with less than 48 hours on the clock before it could execute. The community ultimately voted the proposal down, and no funds were lost.

The incident, detected on August 18, 2026, marks the second major governance-targeted attack on a DAO in as many months.

How the attack was stopped

Binance’s internal monitoring systems picked up the suspicious proposal and immediately alerted the affected project’s team. From there, the exchange coordinated with other centralized platforms to freeze deposits tied to the DAO’s tokens as a precautionary measure.

That cross-platform coordination bought the DAO’s community enough time to mobilize. Token holders rallied to vote against the proposal, effectively killing it before any funds could move.

Advertisement

Governance attacks are the new smart contract exploits

Binance Chief Security Officer Jimmy Su pointed to this shift directly, noting that growing risks in the crypto space are increasingly centered on human behaviors and access rather than platform-specific code vulnerabilities.

DAO governance systems typically allow token holders to submit proposals that, if approved by a majority vote, execute automatically on-chain. But the mechanism assumes good faith participation, and bad actors have figured out how to game that assumption.

Low voter turnout is the most common enabler. If only a small fraction of token holders actively participate in governance votes, an attacker doesn’t need a massive stake to push through a malicious proposal. They just need enough tokens to outvote whoever happens to show up.

This latest incident came barely a month after BonkDAO suffered a successful governance hack in July 2026 that resulted in approximately $20 million in losses. That attack used a similar playbook: submit a proposal that looks innocuous or technical, hope most token holders don’t scrutinize it, and watch the treasury drain itself through a perfectly valid on-chain vote.

What this means for DAO security

The successful intervention highlights a somewhat ironic dynamic in the decentralized world: centralized exchanges still play a critical role as security backstops. Binance didn’t just detect the threat. It actively coordinated deposit freezes across multiple platforms, a response that would be impossible in a purely decentralized ecosystem.

For DAOs, the takeaway is structural. Governance frameworks need hardening. That could mean implementing time-lock mechanisms that give communities longer windows to review proposals, requiring higher quorum thresholds for treasury-related votes, or building automated alert systems that flag unusual proposal activity.

Some projects have already begun experimenting with “optimistic governance” models, where proposals pass by default unless challenged, combined with security councils that can veto obviously malicious actions. Others are exploring delegation systems that concentrate voting power with vetted, active participants rather than leaving it scattered across passive holders.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.