Someone just walked into BonkDAO, spent roughly $4.4 million on tokens, and walked out with approximately $20 million from the treasury. Not by hacking smart contracts. Not by finding a zero-day exploit. By simply showing up to vote when nobody else did.

Welcome to the era of the “apathy attack,” a term coined by Dr. NickA (Nick Almond), Head of Governance at Jito Foundation, to describe a governance exploit pattern that has now hit DAOs from Compound to BonkDAO. The vulnerability isn’t in the code. It’s in the community.

How the BonkDAO attack unfolded

On July 6, 2026, an attacker acquired enough BONK tokens to surpass the DAO’s 1% quorum requirement. Only about 2.9% of total participants actively voted on the malicious proposal, spread across just 7 wallets. The proposal passed and drained roughly 4.43 trillion BONK tokens, valued at approximately $20 million, from the treasury.

Post-attack, the stolen tokens were reportedly moved into a newly established “BONK 2.0” multisig DAO controlled by the attacker and their associates.