Binance said on Aug. 18 that its security team helped stop a malicious governance proposal that could have exposed approximately $1.2 million in tokens from an unnamed decentralized autonomous organization’s treasury.

Summary

  • Binance says its security team detected a malicious governance proposal threatening approximately $1.2 million in tokens.
  • Less than 48 hours remained before the proposal could execute against the unnamed project’s treasury.
  • Binance contacted the project and coordinated precautionary deposit closures with other centralized cryptocurrency exchanges immediately.
  • The project rejected the proposal before execution, and Binance reported that no funds were lost.
  • Binance did not identify the project, publish the proposal identifier or provide on-chain transaction records.

The cryptocurrency exchange said its monitoring systems independently identified the proposal with less than 48 hours remaining before execution. Binance then contacted the project and coordinated with other centralized exchanges to close deposits for the affected token.

The project voted against the proposal before it could execute, according to Binance’s published account. The company said no funds were lost.

Binance detected a weakness in proposal creation

The exchange said the attacker attempted to exploit a weakness in the project’s on-chain governance mechanism. The threshold for creating a proposal was reportedly low enough to allow the attacker to bypass intended protocol requirements.

The company did not explain what those requirements were or how the proposal would have accessed the treasury. It also did not disclose whether the attacker accumulated governance tokens, borrowed voting power or concealed malicious instructions inside executable code.

See also  CFTC seeks feedback on CPO and CTA rule changes

Governance systems allow token holders to vote on treasury spending, upgrades and protocol settings. An attacker may gain control when proposal thresholds are low, voting participation is weak or execution delays are too short for delegates to respond.

The affected DAO’s voting process provided enough time for intervention, but Binance said less than two days remained. The exchange did not disclose when the proposal was submitted or the precise execution deadline.

Exchange deposit closures reduced the exit route

After identifying the proposal, Binance contacted the project and other exchanges listing its token. Those platforms closed deposits as a precaution in case the proposal passed and the attacker attempted to move treasury tokens through centralized venues.

Deposit closures would not have stopped the malicious proposal itself. They would instead have restricted one potential route for selling, converting or laundering compromised tokens after execution.

The project’s community ultimately voted against the proposal. Binance did not say how many votes rejected it, whether delegates changed earlier positions or whether project administrators used emergency authority.

Binance Chief Security Officer Jimmy Su said its team identified a threat that “no external security provider had flagged.” That statement has not received confirmation from the unnamed project or independent security firms.

Key details remain unavailable for verification

The exchange did not identify the project, affected token, governance platform or cooperating exchanges. It also did not publish the proposal identifier, contract address, vote record or relevant blockchain transactions.

See also  An insight into Bitcoin’s safety: Coldcard firmware vulnerability exposed; $112 million in Bitcoin Stolen

Those omissions prevent independent verification of the $1.2 million exposure and intervention timeline. The figure should therefore be treated as Binance’s estimate rather than an independently established loss amount.

Moreover, there was no identifiable market reaction because the affected asset remains undisclosed. No funds moved under the proposal, meaning the case represents an attempted attack rather than a completed treasury theft.

The incident follows other attacks that used governance processes to reach protocol assets. As crypto.news previously reported, attackers drained approximately $20 million from BonkDAO through a malicious proposal in July.

In another case, concerns about purchased voting power affecting DAO decisions showed how low participation and delegated votes can weaken governance protections without exploiting contract code.

The unnamed DAO still needs to close the weakness

The project would need to change the rules that allowed the proposal to reach a vote. Possible controls include higher submission thresholds, longer timelocks, quorum requirements and independent reviews of executable proposals.

Emergency cancellation authority can also stop malicious actions, although it introduces centralized control. Projects must balance rapid intervention with the governance model promised to token holders.

The exchange has not said whether the affected project completed those changes. It also has not announced plans to publish further technical details or identify the project after the immediate risk passes.

A public postmortem would allow users to confirm the vote, understand the vulnerability and assess whether the same path remains open. Until then, the successful intervention and $1.2 million exposure remain based primarily on Binance’s account.

See also  US Treasury seeks feedback on new GENIUS Act stablecoin rules




Source link