Skip to content
Est. MMXXVIVol. VI · № 284RSS
Blockchain Breaches

An archive of cryptocurrency security incidents — hacks, exploits, bridge failures and rug pulls, documented with on-chain evidence.

Dossier № 284Governance Attack

Token of Power Governance Takeover

An attacker acquired a majority of TOP supply, then created, voted and executed an Aragon governance proposal in one transaction to mint ~10 billion tokens and drain 944 WETH from a Balancer V1 pool.

Date
Chain(s)
Status
Funds Stolen

On June 9, 2026, Token of Power (TOP), an Ethereum token governed through an Aragon DAO, was drained of approximately 944.2 WETH (~$1.58 million) in a governance-takeover attack. The Balancer protocol itself was unaffected — the loss fell on the TOP/WETH liquidity pool deployed on Balancer V1.

What happened

The attacker first acquired more than 50% of TOP's circulating supply, enough to single-handedly control voting. TOP's governance relied on a misconfigured Aragon setup built around the MiniMeToken standard with no timelock separating proposal creation from execution. That let the attacker create a proposal, vote on it, and execute it within a single transaction — minting roughly 10 billion new TOP tokens directly to an attacker-controlled contract. The freshly minted supply was then swapped against the TOP/WETH pool, draining about 944 WETH while leaving liquidity providers holding a now-worthless token. Security firms Blockaid, Cyvers and PeckShield flagged the activity on-chain, with Blockaid characterising it as a governance-takeover attack.

Aftermath

The stolen ETH was routed into Tornado Cash, complicating tracing. The starting wallet had itself been funded through Tornado Cash, consistent with a premeditated operation. As of reporting, none of the funds had been recovered.

Why it matters

TOP is a textbook single-transaction governance capture: when a token's own supply is the voting weight and there is no timelock, anyone who can buy or borrow a majority can rewrite the rules in one block. It echoes the Beanstalk flash-loan governance drain and the Tornado Cash governance takeover, and — like Audius — turns on a contract-configuration flaw rather than a market manipulation. The episode is a reminder that timelocks and execution delays are not optional ornaments but the core defence that gives a community time to react before a malicious proposal settles.

Sources & on-chain evidence

  1. [01]crypto.newshttps://crypto.news/token-of-power-exploit-drains-1-58m-from-balancer-pool/
  2. [02]ambcrypto.comhttps://ambcrypto.com/governance-takeover-lets-attacker-mint-10b-top-tokens-in-1-5m-exploit/
  3. [03]crypto-economy.comhttps://crypto-economy.com/attacker-steals-1-6-million-worth-of-top-tokens-in-aragon-dao-breach/
  4. [04]cryptotimes.iohttps://www.cryptotimes.io/2026/06/10/one-vote-1-58m-gone-top-token-hit-by-alleged-governance-attack/

Related filings