Term Labs DAO AI Voting Attack: Stealing $8.5 Million with Just $951
Victims are mostly retail investors and protocol depositors holding DAO governance tokens, concentrated in the age group of 20-40, primarily on-chain wealth management and crypto asset retail investors who lack understanding of governance quorums and proposal execution mechanisms, making them easily overwhelmed by voting power bought at extremely low costs by a few anonymous wallets. Their psychological weakness lies in blindly trusting the appearance that 'on-chain voting equals decentralization', coupled with the temptation of governance token rewards and airdrops, often neglecting to scrutinize the proposal text; protocol parties also skipped multisigs and time-locks out of trust in token-weighted governance. According to on-chain media reports, the BonkDAO treasury had about $20 million in assets drained in a single instance, with the attacker spending only about $4.4 million to 'buy votes' (media estimate, independent review unverified); in a similar event, an attacker bought governance token control for about $951, causing about $8.5 million in losses (media estimate, independent review unverified).
Key Fields
FIELD STAMPSWho Gets Targeted
Victims are mostly retail investors and protocol depositors holding DAO governance tokens, concentrated in the age group of 20-40, primarily on-chain wealth management and crypto asset retail investors who lack understanding of governance quorums and proposal execution mechanisms, making them easily overwhelmed by voting power bought at extremely low costs by a few anonymous wallets. Their psychological weakness lies in blindly trusting the appearance that 'on-chain voting equals decentralization', coupled with the temptation of governance token rewards and airdrops, often neglecting to scrutinize the proposal text; protocol parties also skipped multisigs and time-locks out of trust in token-weighted governance. According to on-chain media reports, the BonkDAO treasury had about $20 million in assets drained in a single instance, with the attacker spending only about $4.4 million to 'buy votes' (media estimate, independent review unverified); in a similar event, an attacker bought governance token control for about $951, causing about $8.5 million in losses (media estimate, independent review unverified).
骗局怎么运作
- Attackers first create thousands of anonymous wallets in bulk on public chains such as Ethereum, and automatically buy the minimum threshold of governance tokens via scripts to meet DAO voting eligibility; the creation of these wallets and token transfers are all completed off-chain, hiding costs by exploiting low batch transaction fees.
- Subsequently, hackers deploy customized AI agent programs capable of reading voting rules, proposal contents, and voting deadlines of the DAO governance interface, and simultaneously initiate voting commands the moment the voting window opens, ensuring that every account completes voting in the same time slot, creating a 'ballot stuffing' effect.
- The AI agents have built-in natural language generation models that automatically generate voting reasons and chat logs supporting malicious proposals, disguised as discussions by real community members, misleading other token holders into having a positive perception of the proposal and thereby reducing dissenting voices.
- After the proposal passes, the execution contract of the malicious proposal immediately triggers a fund transfer instruction, transferring all tokens or stablecoins in the DAO treasury into a cold wallet pre-controlled by the attacker, with the transfer path adopting multi-layer bridging and mixing services to increase tracking difficulty.
- The entire process requires only a few hundred dollars in on-chain gas fees and a small amount of vote-buying costs. Attackers can complete fully automated attacks by renting cloud computing power or using open-source AI agent frameworks, requiring almost no manual intervention.
红旗信号(看到这些快跑)
- 🚩 An abnormally large number of votes appears shortly after the voting window opens, and most come from newly created accounts with low token holdings.
- 🚩 A single proposal gains more than 90% of the voting power within a few minutes, with a highly concentrated vote distribution.
- 🚩 The creation times of voting accounts are concentrated at the same block height, and most lack ENS bindings or other identities.
- 🚩 Voting descriptions or chat logs exhibit highly similar copywriting with obvious language model generation traces.
- 🚩 The proposal execution contract contains code for a one-time transfer of all treasury assets and lacks multisig or delay mechanisms.
真实案例
- 2024-08-15, Term Labs DAO was attacked. Hackers utilized 1,200 AI agent accounts, spending only $951 to purchase voting power, successfully passing a malicious proposal and transferring approximately $8.5 million (about 8.5 Million USD) from the treasury to an anonymous cold wallet. (Source: [https://www.bitbase.com/zh-CN/news/term-labs-dao-governance-heist-951-dollars-8-5-million-exploit](https://www.bitbase.com/zh-CN/news/term-labs-dao-governance-heist-951-dollars-8-5-million-exploit))
- 2026-07-08, BonkDAO suffered a 'vote-buying' attack. The attacker passed a malicious proposal using 99.9% of the voting power in a short period of time, draining approximately $20 million in treasury funds. (Source: [https://news.marsbit.co/20260708140509957125.html](https://news.marsbit.co/20260708140509957125.html))
- 2025-03-20, YAM Finance governance proposal was ballot-stuffed by AI agents, leading to about $337,000 in assets being frozen, after which the project team released an urgent security notice. (Source: [https://www.baiyi.com/news/717397.html](https://www.baiyi.com/news/717397.html))
Official Stance
- Commodity Futures Trading Commission (CFTC), 2023-01-09, published 'CFTC Charges Avraham Eisenberg with Manipulative and Deceptive Scheme to Misappropriate Over $110 million from Mango Markets, a Digital Asset Exchange' (Release Number 8647-23) (Source: [https://www.cftc.gov/PressRoom/PressReleases/8647-23](https://www.cftc.gov/PressRoom/PressReleases/8647-23))
How to Protect Yourself
- ✅ Perform on-chain behavior analysis on all voting accounts prior to voting, set a daily voting limit and token holding threshold, and automatically place abnormal accounts into a review queue.
- ✅ Introduce multisig or time-delay mechanisms, requiring key proposals to be signed by at least two governors with different permissions before execution, preventing a single voting result from directly triggering asset transfers.
- ✅ Use on-chain identity verification (such as ENS binding or decentralized KYC) to enhance the credibility of each voting account and reduce the possibility of anonymous bulk wallet creation.
- ✅ Conduct security audits on proposal execution contracts and incorporate an emergency revocation function, allowing execution to be stopped immediately after multisig approval once an abnormally large transfer is detected.
- https://www.bitbase.com/zh-CN/news/term-labs-dao-governance-heist-951-dollars-8-5-million-exploit
- https://news.marsbit.co/20260708140509957125.html
- https://www.baiyi.com/news/717397.html
- https://www.blocktempo.com/core-dao-emergency-hard-fork-excess-validator-rewards/
- https://www.chaincatcher.com/article/2275334