TLDR
- Binance detected a malicious DAO proposal with less than 48 hours left before it could execute.
- The attack targeted about $1.2 million in treasury tokens from an unnamed project.
- Binance worked with other exchanges to freeze deposits, and the project voted down the proposal.
- The case follows a similar attack on BonkDAO that led to a $20 million loss in July.
- Binance says it spends about $300 million a year on compliance and fraud prevention.
Binance said on Aug. 18 that its security team stopped a malicious governance proposal aimed at a decentralized autonomous organization, known as a DAO.
The proposal could have put about $1.2 million in treasury tokens at risk.
Binance’s team found the issue before any outside security firm flagged it.
The company did not name the project or the token involved.
Less than 48 hours remained before the proposal could take effect.
Once the threat was found, Binance contacted the project’s team directly.
The exchange also asked other platforms that list the token to pause deposits.
The project’s community then voted against the proposal.
That vote stopped the attack before any funds could be moved.
How the Attack Worked
The attacker used a weak point in the project’s voting rules, called governance.
DAOs let token holders vote on choices like spending funds or approving upgrades.
If the rules allow proposals with little review time, a bad actor can push one through fast.
Binance security chief Jimmy Su said the response shows that security work now reaches past the exchange’s own systems.
He said many attacks today target people and access rather than code flaws.
Past Governance Attacks Show the Risk
In July, BonkDAO said an attacker drained about $20 million in BONK tokens from its treasury.
That attacker built up enough voting power to pass a harmful proposal on their own.
A separate case at KelpDAO involved a bridge hack rather than a vote.
Chainalysis reported that hackers took about $292 million from KelpDAO’s bridge.
Quick action after that theft blocked another $95 million and froze thousands of ETH tied to the attacker.
Su said this latest case started with a weakness in how the DAO’s voting system was built.
Early warnings have also helped outside of DAO cases.
The FBI’s Operation Level Up told more than 8,000 people they may be victims of crypto fraud by December 2025.
Most of them did not know they were being targeted.
The agency said its tips likely stopped about $511.5 million in losses.
Binance said it spends close to $300 million a year on compliance work.
Almost 1,500 staff work in related roles at the company.
The exchange said its checks caught $10.53 billion in fraud or unusual activity from 2025 into early 2026.
As of Binance’s Aug. 18 disclosure, the exchange has not released the name of the DAO or the token involved in this case.



