Binance said on Aug. 18 that its security team helped stop a malicious governance proposal that could have exposed approximately $1.2 million in tokens from an unnamed decentralized autonomous organization’s treasury. The exchange said its monitoring systems identified the proposal with less than 48 hours remaining before execution, and it immediately contacted the project and coordinated precautionary deposit closures with other centralized exchanges.

The project rejected the proposal before it could execute, and Binance reported that no funds were lost. The exchange did not identify the project, publish the proposal identifier, or provide on-chain transaction records, leaving the $1.2 million figure as Binance’s estimate rather than an independently verified amount.

Attack exploited governance weakness

Binance said the attacker attempted to exploit a weakness in the project’s on-chain governance mechanism. The threshold for creating a proposal was reportedly low enough to bypass intended protocol requirements. The exchange did not explain what those requirements were or how the proposal would have accessed the treasury, nor did it disclose whether the attacker accumulated governance tokens, borrowed voting power, or concealed malicious instructions in executable code.

Governance systems allow token holders to vote on treasury spending, upgrades, and protocol settings. An attacker may gain control when proposal thresholds are low, voting participation is weak, or execution delays are too short for delegates to respond. In this case, the affected DAO’s voting process provided enough time for intervention, but Binance said less than two days remained. The exchange did not disclose when the proposal was submitted or the precise execution deadline.

Deposit closures limited exit routes

After identifying the proposal, Binance contacted the project and other exchanges listing its token. Those platforms closed deposits as a precaution in case the proposal passed and the attacker attempted to move treasury tokens through centralized venues. Deposit closures would not have stopped the malicious proposal itself, but they would have restricted one potential route for selling, converting, or laundering compromised tokens after execution.

The project’s community ultimately voted against the proposal. Binance did not say how many votes rejected it, whether delegates changed earlier positions, or whether project administrators used emergency authority. Binance Chief Security Officer Jimmy Su said its team identified a threat that “no external security provider had flagged,” but that statement has not received confirmation from the unnamed project or independent security firms.

Key details remain unavailable for verification

The exchange did not identify the project, affected token, governance platform, or cooperating exchanges. It also did not publish the proposal identifier, contract address, vote record, or relevant blockchain transactions. Those omissions prevent independent verification of the $1.2 million exposure and intervention timeline. There was no identifiable market reaction because the affected asset remains undisclosed.

No funds moved under the proposal, meaning the case represents an attempted attack rather than a completed treasury theft. The incident follows other attacks that used governance processes to reach protocol assets. As crypto.news previously reported, attackers drained approximately $20 million from BonkDAO through a malicious proposal in July. In another case, concerns about purchased voting power affecting DAO decisions showed how low participation and delegated votes can weaken governance protections without exploiting contract code.

Unnamed DAO still needs to close the weakness

The project would need to change the rules that allowed the proposal to reach a vote. Possible controls include higher submission thresholds, longer timelocks, quorum requirements, and independent reviews of executable proposals. Emergency cancellation authority can also stop malicious actions, although it introduces centralized control. Projects must balance rapid intervention with the governance model promised to token holders.

The exchange has not said whether the affected project completed those changes, nor has it announced plans to publish further technical details or identify the project after the immediate risk passes. A public postmortem would allow users to confirm the vote, understand the vulnerability, and assess whether the same path remains open. Until then, the successful intervention and $1.2 million exposure remain based primarily on Binance’s account.