TOP Token Suffers $1.58M Loss in Governance Attack Exploiting Aragon DAO Voting System
Token of Power (TOP) lost $1.58 million in a governance attack exploiting a misconfigured Aragon DAO. An attacker gained over 50% of voting power with a small number of tokens, allowing them to mint 10 billion new TOP tokens in a single transaction. These were then swapped for 944.2 WETH in a Balancer V1 liquidity pool, highlighting a dangerous trend in DeFi governance exploits.
TOP governance attack mechanics
▪The successful proposal triggered a function that minted 10 billion new TOP tokens and sent them to the attacker's contract.
▪An attacker gained control of Token of Power (TOP) governance by acquiring over 50% of its voting power.
▪At the time of reporting on June 9, 2026, neither the Token of Power team nor Aragon had released an official statement.
▪Using the Aragon voting system, the attacker created, voted on, and executed a malicious proposal in a single transaction.
Aragon DAO misconfiguration vulnerability
▪The exploit was enabled by a misconfiguration in the Aragon DAO, where governance rights were concentrated in a small token supply of 16,384 TOP.
▪The system's design lacked safety gaps or waiting periods between the creation, voting, and execution of governance proposals.
Balancer V1 liquidity drainage
▪The Balancer protocol itself was not at fault; its liquidity pool was merely the venue for the token swap.
▪The funds were extracted by swapping the newly minted, unbacked TOP tokens for WETH in the TOP/WETH pool.
▪The attacker drained approximately 944.2 WETH, valued at about $1.58 million, from a Balancer V1 liquidity pool.
Tornado Cash attacker funding
▪The attacker's wallet was identified as 0xff8e….b39Fa2, and the exploit was carried out via a separate contract, 0x25c6….729A21.
▪Security firm BlockSec Phalcon identified that the attacker's wallet was funded through the transaction-obscuring platform Tornado Cash.
DeFi governance attack trend
▪Similar incidents involving token minting and administrative control exploits have been reported across multiple protocols in 2026.
▪The attack on Token of Power is part of a trend of governance attacks affecting smaller DeFi projects with low liquidity and concentrated governance.
Story comments
Loading comments…