An attacker has exploited a governance misconfiguration in the Token of Power (TOP) Aragon DAO. They reportedly used majority voting power to mint tokens and drainAn attacker has exploited a governance misconfiguration in the Token of Power (TOP) Aragon DAO. They reportedly used majority voting power to mint tokens and drain

Attacker drains $1.58M from Token of Power pool via Aragon DAO governance exploit

2026/06/10 02:05
3분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 crypto.news@mexc.com으로 연락주시기 바랍니다

An attacker has exploited a governance misconfiguration in the Token of Power (TOP) Aragon DAO.

They reportedly used majority voting power to mint tokens and drain roughly 944 WETH, which is worth around $1.58 million, from a Balancer V1 liquidity pool on Ethereum.

Attacker drains $1.58M from Token of Power pool via Aragon DAO governance exploit

Various blockchain security firms flagged the incident, relying on the effective vector, which showed that TOP’s total token supply was just 16,384 tokens, and the attacker held slightly more than half of them.

How did the TOP token exploit work?

TOP is a MiniMeToken governed through Aragon’s voting infrastructure. According to Blockaid’s analysis, the attacker accumulated 8,192.000001 TOP, and this was more than enough to help them to clear the 50% threshold needed to pass governance proposals unilaterally. 

As a result of the Aragon Voting app on TOP’s DAO having no timelock, the attacker was able to create a proposal, vote it through, and execute it within a single transaction.

BlockSec Phalcon confirmed that the passed proposal minted a large quantity of new TOP tokens to the attacker’s address. The attacker then used those freshly minted tokens to drain the TOP/WETH Balancer V1 BPool, extracting 944.2 WETH.

It was noted that Balancer’s protocol was not itself vulnerable. The pool was simply the place where the attacker converted inflated TOP holdings into WETH.

How did the attacker move the funds?

The attacker’s wallet, 0xff8eF7bC455a57e5893232203052Ce0232b39Fa2, was funded through Tornado Cash. The exploit was executed in a single transaction through a dedicated contract, per Blockaid’s on-chain breakdown.

A textbook governance-takeover scenario

The root cause of the exploit was not a smart contract bug in the traditional sense. TOP’s token has a relatively small supply and low market capitalization, which made acquiring a controlling stake cheap.

When that was combined with Aragon’s voting configuration, which allows same-block proposal creation, voting, and execution, the attacker faced no major barrier between gaining majority power and draining funds.

Aragon’s own documentation on DAO security highlights access controls and the importance of restricting who can call sensitive functions on smart contracts.

In that same documentation, the organization stated that onchain functions are accessible by all by default and that authorized access “must be restricted to authorized addresses” when token minting or fund movements are involved.

However, TOP’s configuration did not enforce a timelock or quorum delay that could have given other token holders time to react.

What to watch

Neither the Token of Power team nor Aragon has issued any statement concerning the exploit as of publication. 

While the stolen WETH is still traceable onchain, the Tornado Cash funding of the attacker’s wallet complicates recovery prospects. The incident is a reminder that governance parameters (timelocks, quorum thresholds, proposal delays) are not optional safety features for low-supply tokens with meaningful treasury exposure.

Don’t just read crypto news. Understand it. Subscribe to our newsletter. It's free.

Predict & Trade to Win Rewards

Predict & Trade to Win RewardsPredict & Trade to Win Rewards

Guaranteed rewards with $500,000 prize pool

면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, crypto.news@mexc.com으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

RealStocks Now Live

RealStocks Now LiveRealStocks Now Live

Trade real U.S. stock via regulated brokerage