Binance blocks $1.2M DAO governance attack in under 48 hours

Binance flagged a malicious DAO proposal with fewer than 48 hours to execution, warned the project and helped prevent access to about $1.2 million in treasury tokens.

On Aug. 18 Binance disclosed its security team detected a malicious governance proposal targeting an unnamed decentralized autonomous organization with fewer than 48 hours remaining before execution. The firm warned the project and helped block access to roughly $1.2 million in treasury tokens.

Binance coordinated with centralized exchanges that list the token to temporarily close deposits, limiting ways an attacker could move funds. The targeted project voted against the proposal before execution. Binance did not identify the DAO or the token involved.

The company said the proposal exploited a low barrier to submission in the DAO’s on-chain governance process. DAOs use token-based voting and smart contracts to approve changes and move treasury assets. Low submission thresholds and short review windows can allow malicious proposals to reach execution with limited scrutiny.

Binance’s chief security officer, Jimmy Su, described the response as cross-ecosystem protection: “This case demonstrates what security by design looks like, extending beyond our own walls. Our team and systems identified a threat that no external security provider had flagged and moved proactively to protect ecosystem users.” He added the incident “highlights the importance of protecting people, not just platforms” and noted that many threats now target access and behavior rather than code.

The disclosure referenced recent governance and bridge attacks as context. In July, a governance exploit at another DAO drained about $20 million in tokens after an attacker gained sufficient voting power to authorize a transfer. In a separate incident involving off-chain infrastructure, attackers stole roughly $292 million from a bridge; responders prevented another $95 million in losses and froze 30,766 ETH linked to the attacker.

Binance said it has expanded monitoring, compliance and recovery operations as threats cross protocols, exchanges and off-chain systems. The company reports spending about $300 million a year on compliance and employing nearly 1,500 staff in related roles. Binance’s fraud detection operations intercepted $10.53 billion in potential fraud and anomalous activity from 2025 through the first quarter of 2026.

The firm described the incident as stemming from a governance vulnerability rather than a conventional code exploit.

The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.

Articles by this author