Key Takeaways
- Binance detected the proposal with less than 48 hours remaining.
- The unnamed project rejected the measure before it could execute.
- Comparable attacks show governance flaws can threaten DAO treasuries.
Binance Flags Proposal Before Vote
Crypto exchange Binance shared on Aug. 18 that its security team detected a malicious governance proposal targeting an unnamed decentralized autonomous organization, or DAO, as investors increasingly scrutinize risks beyond smart contract code. The security disclosure said the proposal could have placed approximately $1.2 million in treasury tokens at risk.
Binance Chief Security Officer Jimmy Su described the response as an example of security extending across the cryptocurrency ecosystem:
“This case demonstrates what security by design looks like, extending beyond our own walls. Our team and systems identified a threat that no external security provider had flagged and moved proactively to protect ecosystem users.”
With less than 48 hours remaining before execution, Binance contacted the project and coordinated with centralized exchanges listing the token to close deposits. The project then voted against the proposal, stopping it before execution. Binance did not identify the project or affected token.
How Governance Rules Created the Risk
According to the crypto firm, the proposal exploited a low submission barrier within the project’s on-chain governance mechanism. A DAO uses smart contracts and token-based voting to manage proposals, upgrades, protocol settings and shared assets. The governance process often gives token holders voting rights, placing treasury management under transparent rules. Concentrated voting power or limited review periods can leave those systems exposed to manipulation.
A completed governance attack shows what can happen when a malicious proposal reaches execution. BonkDAO confirmed in July that a malicious proposal drained approximately $20 million in BONK tokens from its treasury. The BonkDAO governance attack succeeded after the attacker accumulated sufficient voting power to authorize the transfer.
Rapid Coordination Limits Further Losses
Although it involved a bridge rather than a governance vote, the KelpDAO incident demonstrates how rapid coordination can limit further losses after detection. Chainalysis reported that attackers stole roughly $292 million from KelpDAO’s bridge after compromising off-chain infrastructure. The response blocked another $95 million theft and froze 30,766 ETH associated with the attacker.
Su said the incident demonstrated how governance weaknesses can expose users without relying on a conventional code exploit: “This malicious proposal also highlights the importance of protecting people, not just platforms.” He added:
“The biggest risks in crypto today increasingly target people, access, and behaviors rather than code vulnerabilities. In this case, the attack stemmed from an underlying governance vulnerability.”
Early Warnings Extend Across Crypto
Early warnings have also limited losses in consumer-focused cryptocurrency schemes, although those scams differ from protocol governance attacks. The FBI’s Operation Level Up had notified 8,103 potential cryptocurrency investment fraud victims by December 2025. The agency said 77% were unaware of the scams and estimated that its intervention prevented approximately $511.5 million in losses.
As attacks increasingly cross protocols, exchanges and off-chain systems, Binance has expanded its monitoring, compliance and recovery operations. The exchange reportedly spends approximately $300 million annually on compliance, while nearly 1,500 employees work in related roles. Binance’s fraud detection operations reportedly intercepted $10.53 billion in potential fraud and anomalous activity from 2025 through the first quarter of 2026.
