Altcoin
BarnBridge Becomes Second Dormant-DAO Takeover in a Month, Security Firm Warns
14 Aug 2026, 13:51
16 views
Admin
An attacker quietly bought up governance tokens of the abandoned BarnBridge protocol, passed a malicious proposal, and drained roughly $776,000, the second dormant-DAO takeover in three weeks following a similar $20 million exploit at BonkDAO.
An attacker took over governance of the long-abandoned BarnBridge protocol on August 15, upgraded its SmartYield contracts to a version of their own making, and drained roughly $776,000 in USDC, without exploiting any bug in the underlying code. Security firm BlockSec says the incident is the second confirmed case of this exact attack pattern in under a month, following a similar takeover at BonkDAO in July, and warns it likely won't be the last.
The mechanism relies on simple neglect rather than a technical flaw. DAOs like BarnBridge govern themselves through token-weighted voting: whoever holds enough of the governance token can pass proposals that control the protocol's funds. When a project winds down and most token holders stop paying attention, the voting system itself typically stays switched on, since nobody formally shuts it off. In BarnBridge's case, an attacker noticed the token had become cheap and thinly watched, quietly accumulated enough of it, and passed a proposal handing themselves control, all without breaking any rule the protocol's own governance system was designed to enforce.
A second layer of exposure compounded the damage. Roughly 50 user accounts had, back when the protocol was active, granted BarnBridge standing approval to move their USDC, a routine permission many DeFi users grant and then forget to revoke. Once the attacker controlled the protocol's governance, they used that authority to upgrade the SmartYield contracts and call a privileged function that swept up exactly those forgotten approvals, later swapping the stolen funds for roughly 415 ETH. Notably, a security tool called Blockaid had flagged the specific mechanism just one day before the attack occurred, publicly warning that two old, dormant BarnBridge governance proposals carried token-authorization risk if maliciously executed.
BlockSec's CTO told reporters the incident fits a pattern the firm expects to recur, since dormant contracts, governance tokens and standing approvals do not stop presenting security risks simply because a project's team has stopped actively running it. The mechanics closely mirror the earlier BonkDAO case, where an attacker spent roughly $4.4 million quietly accumulating just over 1% of BONK's token supply, the exact threshold needed to meet the DAO's voting quorum, then drained $20 million from the treasury once the vote passed, a payout more than four times the cost of acquiring the votes. Industry researchers, including venture firm a16z crypto in a 2024 analysis of DAO governance attacks, had already flagged low voter turnout as a mechanism that lets a hostile position accumulate "without raising suspicion." BarnBridge and BonkDAO now stand as two live examples of a risk that had been identified in theory well before either attack occurred, underscoring a specific implication for any protocol scaling back development or treasury oversight without a formal plan for winding down its governance and outstanding token approvals alongside it.
The mechanism relies on simple neglect rather than a technical flaw. DAOs like BarnBridge govern themselves through token-weighted voting: whoever holds enough of the governance token can pass proposals that control the protocol's funds. When a project winds down and most token holders stop paying attention, the voting system itself typically stays switched on, since nobody formally shuts it off. In BarnBridge's case, an attacker noticed the token had become cheap and thinly watched, quietly accumulated enough of it, and passed a proposal handing themselves control, all without breaking any rule the protocol's own governance system was designed to enforce.
A second layer of exposure compounded the damage. Roughly 50 user accounts had, back when the protocol was active, granted BarnBridge standing approval to move their USDC, a routine permission many DeFi users grant and then forget to revoke. Once the attacker controlled the protocol's governance, they used that authority to upgrade the SmartYield contracts and call a privileged function that swept up exactly those forgotten approvals, later swapping the stolen funds for roughly 415 ETH. Notably, a security tool called Blockaid had flagged the specific mechanism just one day before the attack occurred, publicly warning that two old, dormant BarnBridge governance proposals carried token-authorization risk if maliciously executed.
BlockSec's CTO told reporters the incident fits a pattern the firm expects to recur, since dormant contracts, governance tokens and standing approvals do not stop presenting security risks simply because a project's team has stopped actively running it. The mechanics closely mirror the earlier BonkDAO case, where an attacker spent roughly $4.4 million quietly accumulating just over 1% of BONK's token supply, the exact threshold needed to meet the DAO's voting quorum, then drained $20 million from the treasury once the vote passed, a payout more than four times the cost of acquiring the votes. Industry researchers, including venture firm a16z crypto in a 2024 analysis of DAO governance attacks, had already flagged low voter turnout as a mechanism that lets a hostile position accumulate "without raising suspicion." BarnBridge and BonkDAO now stand as two live examples of a risk that had been identified in theory well before either attack occurred, underscoring a specific implication for any protocol scaling back development or treasury oversight without a formal plan for winding down its governance and outstanding token approvals alongside it.