StrongBlock DAO Hijacked via Governance, $72K Drained

iconChainGPT
Share
AI summary iconSummary
An attacker drained around $72,000 from the abandoned StrongBlock DAO by seizing governance control. Using a majority of STRONG tokens, they proposed a blockchain upgrade to change the admin and siphon funds. The exploit bypassed smart contract bugs, focusing instead on governance weaknesses. Similar attacks have hit Ostium and Coldcard, showing risks in network upgrade processes and infrastructure.

Headline: Attacker Uses StrongBlock’s Own Governance to Drain $72K — A Cautionary Tale for Abandoned DAOs An attacker has siphoned roughly $72,000 worth of STRONG and STRNGR from StrongBlock after seizing control of the protocol’s abandoned on‑chain governance system via a malicious proposal, according to blockchain security firm Defimon Alerts. What happened - Network / token: STRONG / STRNGR on Ethereum. - Losses: 32,695 STRONG and 383,447 STRNGR — ~ $72,000 total. - Attack vector: governance takeover, not a smart‑contract bug or oracle compromise. How the exploit unfolded 1. The attacker accumulated a majority of StrongBlock’s STRONG governance tokens, which Defimon says had become largely worthless after the project was abandoned. 2. Using that voting power, they submitted a legitimate governance proposal instructing the Governor’s Upgrader contract to call setPendingAdmin(attacker). The proposal passed every required stage—voting, queuing, and execution—under the protocol’s normal governance rules. 3. Once set as the pending administrator, the attacker used their administrative privileges to upgrade the Governor proxy to a minimal, unverified implementation containing a forward(address, bytes) function. That function was restricted to the attacker’s externally owned account and acted as an arbitrary‑call mechanism under the Governor’s authority. 4. With the upgraded Governor able to execute arbitrary calls, the attacker moved assets out of the protocol’s pools and drained the reported STRONG and STRNGR balances. Why this matters - Defimon characterizes this as a governance takeover: every critical step (admin change, contract upgrade, asset transfers) was authorized through the protocol’s own governance process rather than a code vulnerability. By hijacking the governance system, the attacker turned StrongBlock’s governance contract into the tool used to steal funds. - The incident highlights a growing trend: attackers are increasingly targeting governance systems, supporting infrastructure, or wallet/firmware weaknesses rather than only exploiting smart contract bugs. Broader context — similar recent incidents - Ostium: Attackers stole 23.75M USDC after manipulating off‑chain infrastructure (fraudulent BTC‑USD feeds) rather than exploiting on‑chain code. - Coldcard: A 2021 firmware issue that reduced entropy in key generation has been linked to large Bitcoin thefts; Galaxy Research has attributed 1,596 BTC to three waves and identified a suspected fourth wave (~448.7 BTC) pending confirmation. - Post‑Coldcard, the volunteer Bitcoin Red Team ran AI‑assisted and manual reviews of 390 Bitcoin‑related repos, finding 4,962 potential issues (720 high/critical); OpenSats and Kimi Moonshot provided funding and models to support that effort. Takeaways for projects and users - Abandoned or poorly governed protocols remain dangerous: dormant governance tokens can still pass proposals if someone accumulates voting power. - Mitigations teams should consider: emergency multisigs or timelocks, burning or locking governance tokens when a project winds down, clearer administrative handover procedures, and ongoing monitoring of governance token concentrations. - For users and investors, the incident is another reminder to watch governance activity and token distribution, not just contract audits. This StrongBlock takeover underscores that governance is itself an attack surface. Protocol teams need active maintenance, careful tokenomics, and clear end‑of‑life procedures to prevent attackers from weaponizing on‑chain governance.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.