• bitcoinBitcoin (BTC) $ 65,913.00
  • ethereumEthereum (ETH) $ 1,721.53
  • tetherTether (USDT) $ 0.999384
  • bnbBNB (BNB) $ 617.82
  • usd-coinUSDC (USDC) $ 0.999759
  • xrpXRP (XRP) $ 1.18
  • solanaSolana (SOL) $ 71.27
  • tronTRON (TRX) $ 0.320429
  • staked-etherLido Staked Ether (STETH) $ 2,265.05
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.02
  • hyperliquidHyperliquid (HYPE) $ 64.77
  • dogecoinDogecoin (DOGE) $ 0.088843
  • usdsUSDS (USDS) $ 0.999677
  • leo-tokenLEO Token (LEO) $ 9.78
  • rainRain (RAIN) $ 0.013545
  • wrapped-stethWrapped stETH (WSTETH) $ 2,779.67
  • zcashZcash (ZEC) $ 497.25
  • cardanoCardano (ADA) $ 0.181425
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 76,243.00
  • stellarStellar (XLM) $ 0.190634
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.998762
  • canton-networkCanton (CC) $ 0.165222
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 2,466.93
  • whitebitWhiteBIT Coin (WBT) $ 53.48
  • moneroMonero (XMR) $ 334.09
  • chainlinkChainlink (LINK) $ 8.21
  • wrapped-eethWrapped eETH (WEETH) $ 2,465.31
  • the-open-networkToncoin (TON) $ 1.79
  • ethena-usdeEthena USDe (USDE) $ 0.999407
  • susdssUSDS (SUSDS) $ 1.08
  • usd1-wlfiUSD1 (USD1) $ 0.999868
  • bitcoin-cashBitcoin Cash (BCH) $ 212.43
  • daiDai (DAI) $ 0.999740
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 76,366.00
  • memecoreMemeCore (M) $ 2.96
  • hedera-hashgraphHedera (HBAR) $ 0.081917
  • litecoinLitecoin (LTC) $ 45.42
  • wethWETH (WETH) $ 2,268.37
  • labLAB (LAB) $ 10.82
  • suiSui (SUI) $ 0.801643
  • nearNEAR Protocol (NEAR) $ 2.39
  • usdt0USDT0 (USDT0) $ 0.998824
  • hashnote-usycCircle USYC (USYC) $ 1.13
  • shiba-inuShiba Inu (SHIB) $ 0.000005
  • avalanche-2Avalanche (AVAX) $ 6.78
  • paypal-usdPayPal USD (PYUSD) $ 0.999749
  • crypto-com-chainCronos (CRO) $ 0.062031
  • bittensorBittensor (TAO) $ 281.65
  • global-dollarGlobal Dollar (USDG) $ 0.999995
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.22
  • tether-goldTether Gold (XAUT) $ 4,289.45
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.14
  • worldcoin-wldWorldcoin (WLD) $ 0.587745
  • pax-goldPAX Gold (PAXG) $ 4,298.11
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.061329
  • mantleMantle (MNT) $ 0.572806
  • ondo-financeOndo (ONDO) $ 0.383532
  • aster-2Aster (ASTER) $ 0.634138
  • polkadotPolkadot (DOT) $ 1.01
  • little-pepe-5Little Pepe (LILPEPE) $ 2.16
  • ripple-usdRipple USD (RLUSD) $ 1.00
  • uniswapUniswap (UNI) $ 2.60
  • syrupusdcsyrupUSDC (SYRUPUSDC) $ 1.15
  • audieraAudiera (BEAT) $ 5.51
  • okbOKB (OKB) $ 75.20
  • htx-daoHTX DAO (HTX) $ 0.000002
  • falcon-financeFalcon USD (USDF) $ 0.995877
  • pi-networkPi Network (PI) $ 0.134535
  • internet-computerInternet Computer (ICP) $ 2.57
  • usddUSDD (USDD) $ 0.999596
  • skySky (SKY) $ 0.056883
  • bfusdBFUSD (BFUSD) $ 0.998701
  • morphoMorpho (MORPHO) $ 2.00
  • bitget-tokenBitget Token (BGB) $ 1.81
  • pepePepe (PEPE) $ 0.000003
  • ethereum-classicEthereum Classic (ETC) $ 7.29
  • aaveAave (AAVE) $ 69.45
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 4.00
  • cosmosCosmos Hub (ATOM) $ 1.98
  • quant-networkQuant (QNT) $ 69.52
  • united-stablesUnited Stables (U) $ 0.999800
  • eutblSpiko EU T-Bills Money Market Fund (EUTBL) $ 1.22
  • blockchain-capitalBlockchain Capital (BCAP) $ 106.96
  • jito-staked-solJito Staked SOL (JITOSOL) $ 124.46
  • superstate-short-duration-us-government-securities-fund-ustbInvesco Short Duration US Government Securities Fund (USTB) $ 11.11
  • render-tokenRender (RENDER) $ 1.83
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 2,404.69
  • kucoin-sharesKuCoin (KCS) $ 7.02
  • usdtbUSDtb (USDTB) $ 0.999741
  • binance-peg-wethBinance-Peg WETH (WETH) $ 2,262.26
  • kaspaKaspa (KAS) $ 0.032542
  • rocket-pool-ethRocket Pool ETH (RETH) $ 2,631.35
  • janus-henderson-anemoy-treasury-fundJanus Henderson Anemoy Treasury Fund (JTRSY) $ 1.11
  • algorandAlgorand (ALGO) $ 0.093468
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999945
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.077863
  • dexeDeXe (DEXE) $ 17.65
  • wbnbWrapped BNB (WBNB) $ 759.61
  • stable-2​​Stable (STABLE) $ 0.034746
  • ignition-fbtcFunction FBTC (FBTC) $ 76,389.00
  • nexoNEXO (NEXO) $ 0.813429
  • ethenaEthena (ENA) $ 0.085812
  • venice-tokenVenice Token (VVV) $ 16.24
  • gatechain-tokenGate (GT) $ 6.84
  • flare-networksFlare (FLR) $ 0.008016
  • syrupusdtsyrupUSDT (SYRUPUSDT) $ 1.11
  • janus-henderson-anemoy-aaa-clo-fundJanus Henderson Anemoy AAA CLO Fund (JAAA) $ 1.04
  • bianrensheng币安人生 (BinanceLife) (币安人生) $ 0.671142
  • justJUST (JST) $ 0.077001
  • binance-staked-solBinance Staked SOL (BNSOL) $ 108.24
  • filecoinFilecoin (FIL) $ 0.806104
  • jupiter-exchange-solanaJupiter (JUP) $ 0.189980
  • beldexBeldex (BDX) $ 0.079550
  • xdce-crowd-saleXDC Network (XDC) $ 0.030625
  • ghoGHO (GHO) $ 0.998932
  • humanityHumanity (H) $ 0.324353
  • new-x-ceo-is-backNEW X CEO IS BACK (XFLOKI) $ 0.506041
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999720
  • aptosAptos (APT) $ 0.686810
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 76,461.00
  • yldsYLDS (YLDS) $ 0.999809
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 76,491.00
  • pump-funPump.fun (PUMP) $ 0.001606
  • usual-usdUsual USD (USD0) $ 0.998633
  • midnight-3Midnight (NIGHT) $ 0.033115
  • clbtcclBTC (CLBTC) $ 76,920.00
  • arbitrumArbitrum (ARB) $ 0.086584
  • hash-2Provenance Blockchain (HASH) $ 0.009693
  • injective-protocolInjective (INJ) $ 5.24
  • spiko-amundi-overnight-swap-fund-eurSpiko Amundi Overnight Swap Fund (EUR) (EURSAFO) $ 1.17
  • a7a5A7A5 (A7A5) $ 0.013194
  • usxUSX (USX) $ 0.999374
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 2,419.84
  • dashDash (DASH) $ 38.98
  • true-usdTrueUSD (TUSD) $ 0.998537
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 33.97
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.217872
  • tbtctBTC (TBTC) $ 70,942.00
  • pancakeswap-tokenPancakeSwap (CAKE) $ 1.39
  • wrappedm-by-m0WrappedM by M0 (WM) $ 1.00
  • ousgOndo Short-Term U.S. Government Bond Fund (OUSG) $ 115.55
  • official-trumpOfficial Trump (TRUMP) $ 2.01
  • adi-tokenADI (ADI) $ 3.73
  • kite-2Kite (KITE) $ 0.199376
  • euro-coinEURC (EURC) $ 1.16
  • vechainVeChain (VET) $ 0.005111
  • c8ntinuumc8ntinuum (CTM) $ 0.087592
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.006968
  • mantle-staked-etherMantle Staked Ether (METH) $ 2,455.82
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.655964
  • lighterLighter (LIT) $ 1.70
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999983
  • bonkBonk (BONK) $ 0.000005
  • hastra-primePRIME (PRIME) $ 1.04
  • resolv-wstusrResolv wstUSR (WSTUSR) $ 1.13
  • cocaCOCA (COCA) $ 1.30
  • apxusdapxUSD (APXUSD) $ 0.961700
  • terra-lunaTerra Luna Classic (LUNC) $ 0.000073
  • aerodrome-financeAerodrome Finance (AERO) $ 0.394416
  • doge-strategyDoge Strategy (DOGESTR) $ 0.288297
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 2,406.26
  • skyaiSkyAI (SKYAI) $ 0.373962
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 76,200.00
  • sei-networkSei (SEI) $ 0.054640
  • curve-dao-tokenCurve DAO (CRV) $ 0.238975
  • blockstackStacks (STX) $ 0.196807
  • the9bitThe9bit (9BIT) $ 0.043760
  • wrapped-flareWrapped Flare (WFLR) $ 0.009961
  • ethgas-2ETHGas (GWEI) $ 0.170094
  • celestiaCelestia (TIA) $ 0.365791
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 2,266.86
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.997574
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.12
  • kinesis-goldKinesis Gold (KAU) $ 139.89
  • sun-tokenSun Token (SUN) $ 0.017012
  • spx6900SPX6900 (SPX) $ 0.339582
  • unibaseUnibase (UB) $ 0.123556
  • pyth-networkPyth Network (PYTH) $ 0.038926
  • binance-peg-xrpBinance-Peg XRP (XRP) $ 1.59
  • ether-fiEther.fi (ETHFI) $ 0.337349
  • ether-fi-liquid-ethEther.Fi Liquid ETH (LIQUIDETH) $ 2,443.47
  • usdgoUSDGO (USDGO) $ 0.999782
  • jito-governance-tokenJito (JTO) $ 0.610164
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 2,421.84
  • gnosisGnosis (GNO) $ 108.79
  • grassGrass (GRASS) $ 0.460701
  • noonNoon (NOON) $ 0.751949
  • sbtc-2sBTC (SBTC) $ 77,039.00
  • layerzeroLayerZero (ZRO) $ 1.07
  • zebec-networkZebec Network (ZBCN) $ 0.002748
  • kinesis-silverKinesis Silver (KAG) $ 70.54
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 115.56
  • chilizChiliz (CHZ) $ 0.025501
  • savings-usddSavings USDD (SUSDD) $ 1.03
  • apenftAINFT (NFT) $ 0.00000027
  • monadMonad (MON) $ 0.022315
  • bittorrentBitTorrent (BTT) $ 0.00000027
  • msolMarinade Staked SOL (MSOL) $ 133.18
  • tezosTezos (XTZ) $ 0.240223

Governance takeover lets attacker mint 10B TOP tokens in $1.5m exploit

0 0


A governance takeover attack allowed an exploiter to mint 10 billion TOP tokens and drain roughly $1.5m in WETH from a Balancer liquidity pool on Ethereum, according to security researchers.

Blockchain security firm Blockaid said the attacker drained 944.2 WETH, worth approximately $1.58m, from the TOP/WETH Balancer V1 pool after exploiting a governance configuration tied to the Token of Power [TOP] ecosystem.

Researchers stressed that Balancer itself was not vulnerable. Instead, the exploit targeted the protocol’s governance architecture.

Attack weaponized DAO governance

According to Blockaid and CertiK, the attacker acquired more than 50% of TOP’s token supply before executing a governance proposal that minted billions of new TOP tokens directly to the attacker-controlled contract.

The exploit reportedly relied on a misconfiguration in the Aragon DAO involving TOP’s MiniMeToken structure.

Blockaid said the governance system allowed proposal creation, voting, and execution within a single transaction because no timelock protections were in place.

That allowed the attacker to:

  • gain majority voting control,
  • execute a mint proposal instantly,
  • create 10 billion TOP tokens,
  • and dump the newly minted supply into the liquidity pool for WETH.

“The Aragon Voting app allowed create → vote → execute in a single tx with no timelock,” Blockaid said in its analysis.

CertiK separately reported that the attacker initially withdrew 662 ETH from Tornado Cash before accumulating enough TOP tokens to gain majority governance control.

Governance became the exploit vector

The incident highlights how governance systems themselves can become attack surfaces in DeFi protocols.

Unlike traditional smart contract exploits involving coding flaws or reentrancy attacks, governance takeovers weaponize administrative permissions and voting systems already embedded inside protocols.

Timelocks are commonly used in DAO systems to slow governance execution and give communities time to react to malicious proposals.

In this case, researchers say the absence of execution delays allowed the exploit to unfold instantly.

Legacy DAO infrastructure still carries risks

The exploit also highlights risks associated with older DAO governance frameworks and legacy DeFi infrastructure still operating on Ethereum.

Aragon and MiniMeToken-based governance systems were widely adopted during earlier phases of Ethereum’s DAO ecosystem. Still, some deployments may no longer reflect modern governance security standards.

The incident adds to growing scrutiny of governance security as attackers increasingly target protocol control mechanisms rather than seeking only direct smart contract vulnerabilities.


Final Summary

  • An attacker exploited a governance misconfiguration to mint 10 billion TOP tokens and drain roughly $1.5m in WETH from a Balancer liquidity pool.
  • Researchers said the exploit relied on an Aragon DAO setup that allowed proposal creation, voting, and execution in a single transaction without a timelock.



Source link

Leave A Reply

Your email address will not be published.