Token Of Power Governance Exploit Drains $1.58 Million In WETH, TRM Says

bitcoinistPublished on 2026-06-14Last updated on 2026-06-14

Abstract

Blockchain intelligence firm TRM Labs reports a governance exploit against the Token of Power protocol, resulting in a loss of approximately $1.58 million in WETH. The attacker exploited a missing timelock in the protocol's Aragon DAO setup, allowing them to propose, vote on, and execute a malicious action within a single block. The attacker funded the operation with 662 ETH from Tornado Cash, purchased enough TOP tokens to gain majority voting power, minted 10 billion new TOP tokens, and swapped them for WETH via a Balancer pool before moving funds back through Tornado Cash. The incident underscores that governance design is a critical security risk in DeFi, where parameters like timelocks provide essential reaction time. It also highlights how mixers and liquidity pools can be utilized in exploits without being directly compromised. Observers are now watching for any movement of the stolen funds and further remediation details from involved parties. This event is part of a broader shift in crypto, emphasizing the importance of underlying infrastructure, security, and governance alongside market movements.

Blockchain intelligence firm TRM Labs has detailed a governance takeover exploit against the Token of Power protocol that drained approximately $1.58 million in WETH.

According to TRM’s analysis, the attacker exploited a weakness in the protocol’s Aragon DAO setup: the absence of a timelock. That allowed the attacker to propose, vote on, and execute a malicious governance action in a single block.

The attacker reportedly funded the operation with 662 ETH withdrawn from Tornado Cash, purchased enough TOP tokens to gain majority voting power, minted 10 billion new TOP, and swapped those tokens for WETH through a Balancer pool before routing funds back through Tornado Cash.

Why Timelocks Matter

The exploit is a clear example of how governance design can become a direct security risk. Token voting can look decentralized on paper, but if a malicious actor can quickly buy voting power and execute changes without delay, the governance system can become an attack surface.

Timelocks are meant to give users, developers, and security teams time to react before a proposal becomes executable. Without that delay, a hostile vote can become a drain before anyone can stop it.

Why This Matters

For DeFi users, the story is a reminder that smart-contract risk is not limited to code bugs. Governance parameters, treasury controls, and voting thresholds can be just as important.

It also highlights how mixers and liquidity pools can be used around an exploit without being the exploited protocol themselves.

What To Watch Next

The next thing to watch is whether stolen funds move again and whether the protocol, Aragon, or affected liquidity providers publish further remediation details.

The article must not say Tornado Cash itself was hacked.

Market Context

For Bitcoinist, the story sits inside a wider shift in crypto where infrastructure, security, governance, and token utility are becoming just as important as short-term price action. Traders still care about momentum, but they also need to understand the systems, risks, and product changes behind the headlines.

The useful angle is not to overstate the development, but to explain why it belongs in the daily market conversation. Strong crypto stories increasingly come from protocol updates, official notices, security reports, court records, and on-chain data rather than recycled commentary alone.

The editorial takeaway should stay grounded: the source confirms a meaningful crypto development, but the implications depend on adoption, follow-up disclosures, or further on-chain evidence. That balance keeps the piece useful without leaning on hype or unsupported claims.

From an editorial standpoint, this makes the story worth covering as part of the day’s broader crypto operating environment rather than as a standalone hype cycle. The strongest version of the piece should stay close to the verified source, explain the practical risk or opportunity, and leave room for follow-up once more official data, filings, or project statements are available.

This report is based on information from TRM Labs’ on-chain security report.

Related Questions

QWhat vulnerability did the attacker exploit in the Token of Power protocol to drain $1.58 million?

AThe attacker exploited a weakness in the protocol's Aragon DAO setup: the absence of a timelock mechanism. This allowed them to propose, vote on, and execute a malicious governance action in a single block.

QAccording to the article, why are timelocks important in governance design?

ATimelocks are important because they give users, developers, and security teams time to review and react to a governance proposal before it becomes executable. Without this delay, a hostile actor can execute a damaging action before anyone can intervene.

QHow did the attacker fund the operation and cash out the stolen assets according to TRM's analysis?

AThe attacker funded the operation with 662 ETH withdrawn from Tornado Cash. They then purchased enough TOP tokens to gain majority voting power, minted 10 billion new TOP tokens, and swapped those tokens for WETH through a Balancer pool before routing the funds back through Tornado Cash.

QWhat key risk for DeFi users does this exploit highlight beyond smart-contract bugs?

AIt highlights that governance parameters, treasury controls, and voting thresholds can be just as critical a security risk as smart-contract code bugs. Poorly designed governance systems can themselves become an attack surface.

QWhat does the article suggest as the 'useful angle' for covering such developments in the crypto market?

AThe useful angle is to explain why the event belongs in the daily market conversation by focusing on protocol infrastructure, security, and governance, rather than overstating it or relying on hype. Coverage should stay close to verified sources, explain the practical risk or opportunity, and leave room for follow-up information.

Related Reads

The Foundation of SpaceX's Trillion-Dollar Valuation: Who is Dividing Up Musk's Annual Tens of Billions in Capital Expenditure?

SpaceX's trillion-dollar valuation is built on its three core businesses: Starlink (profitable, 60% of revenue), rockets (driving down launch costs), and AI (a major investment area). This creates a financial cycle: Starlink funds rocket development, which enables low-cost launches for AI hardware, generating future revenue. This cycle fuels annual capital expenditures of tens of billions, flowing to a vast supply chain. Suppliers are categorized by their replaceability. The first group includes irreplaceable players like NVIDIA (GPU/CUDA ecosystem), Eutelsat (critical radio spectrum), Filtronic (specialized amplifiers), Materion (strategic beryllium), and STMicroelectronics (antenna chips). The second group consists of hard-to-replace suppliers due to high switching costs, such as Honeywell (flight control), Carpenter Technology (specialty alloys), Hexcel (carbon fiber), Broadcom (data exchange), and Linde (industrial gases). The third group comprises high-volume, cost-critical suppliers for mass-produced items like Starlink terminals. Key names include Wistron NeWeb (primary manufacturer) and several A-share companies like Shenzhen Sunway (connectors), Pies New Materials (forgings), Western Superconducting (alloys), and Yingliu (castings). Other niche players include Trimble (timing), Astronics (power distribution), and CTS (thermal management). The article argues that investing in these suppliers, rather than SpaceX stock directly, offers an alternative opportunity. The rationale is threefold: procurement is just beginning to scale, SpaceX's IPO brings new transparency to its supply chain, and the situation mirrors early stages of past "super terminal" ecosystems like Apple or Tesla. While risks exist (commodity cycles, geopolitical factors, technology shifts), the core thesis is that SpaceX's massive, ongoing procurement will translate into reliable revenue for its key suppliers, regardless of its own stock price volatility.

marsbit7m ago

The Foundation of SpaceX's Trillion-Dollar Valuation: Who is Dividing Up Musk's Annual Tens of Billions in Capital Expenditure?

marsbit7m ago

SpaceX's Trillion-Dollar Valuation Base: Who's Sharing in Musk's Annual Tens of Billions in Capital Expenditure?

**Title: The Foundation of SpaceX's Trillion-Dollar Valuation: Who Benefits from Musk's Annual $100 Billion Capital Expenditure?** This article argues that investors seeking to benefit from SpaceX's growth might find greater opportunities in its supply chain rather than directly investing in the company itself, drawing parallels to historical successes with Apple, Tesla, and NVIDIA suppliers. **SpaceX's Business Model & Cash Flow:** SpaceX generates revenue from three main areas: 1. **Starlink:** Its profitable core, earning $11.3B in 2023 (60% of revenue), funding other ventures. 2. **Rockets (Falcon/Starship):** Requires $3B+ in annual R&D but achieves the world's lowest launch costs. 3. **AI:** Currently unprofitable (-$6B+ in 2023), investing heavily in ground-based supercomputers (220,000 GPUs) and future orbital data centers. The cycle is: Starlink profits → fund cheaper rockets → low-cost launches deploy AI hardware → AI compute rentals generate future revenue. This cycle drives annual procurement spending of tens of billions of dollars. **The Supply Chain Beneficiaries:** Suppliers are categorized by their replaceability: **1. Nearly Irreplaceable (High Barriers to Entry):** * **NVIDIA:** Powers the Colossus supercomputer; its CUDA ecosystem creates immense switching costs. * **Eutelsat (SATS):** Controls critical radio spectrum for satellite communications; holds a ~3% stake in SpaceX. * **Filtronic (FTC):** Supplies millimeter-wave signal amplifiers for Starlink satellites; SpaceX constitutes 83% of its revenue. * **Materion (MTRN):** Global leader in beryllium production, a strategic material used in Starship structures. * **STMicroelectronics (STM):** Supplies phased-array antenna chips for Starlink satellites. **2. Replaceable, but Switching Cost is Prohibitively High:** * **Honeywell (HON):** Provides flight control and inertial navigation systems with decades of certification. * **Carpenter Technology (CRS):** Manufactures ultra-pure specialty steel alloys for Raptor engines. * **Hexcel (HXL):** Supplies custom carbon fiber composites developed over a decade with SpaceX. * **Broadcom (AVGO):** Manages high-speed data switching. * **Linde Group:** Supplies industrial gases (liquid oxygen/nitrogen) from facilities built near SpaceX launch sites. **3. High-Volume, Cost-Critical Manufacturing:** Focuses on mass-producing components like Starlink user terminals (target: 30 million units). * **Key Players:** Wistron NeWeb (6285, primary terminal manufacturer), several Chinese A-share companies (e.g., Sunway Communication, PAX New Materials, Western Metal Materials, Yingliu Co.), and smaller US firms like Trimble (TRMB, timing systems). **Why Now?** Three factors make the supply chain opportunity timely: 1. **Volume Ramp-Up:** SpaceX plans 100 launches in 2026, aims for 30 million Starlink terminals, and will deploy AI data centers, meaning procurement will accelerate. 2. **Increased Transparency:** The IPO provides public financial data, allowing investors to track supplier order growth. 3. **Historical Precedent:** The current phase is likened to Tesla's early mass-production stage (circa 2018), suggesting a long growth runway for suppliers. **Conclusion:** The article posits that while investing in SpaceX stock is betting on Elon Musk's ambitious vision at a high valuation, investing in its established suppliers is a bet on the tangible, recurring revenue from its massive procurement budget, which is largely decoupled from day-to-day stock price volatility.

链捕手11m ago

SpaceX's Trillion-Dollar Valuation Base: Who's Sharing in Musk's Annual Tens of Billions in Capital Expenditure?

链捕手11m ago

The U.S. Government Blocked the Anthropic Model. It Wasn't About 'Jailbreaking' at All.

Last Friday, the U.S. Commerce Department issued an enforcement letter that forced Anthropic to take its two most advanced AI models, Fable 5 and Mythos 5, offline. The stated reason was unspecified national security concerns, initially linked to potential "jailbreaks" of the models' safeguards. However, new details suggest the action stemmed more from a deteriorating relationship between the Trump administration and Anthropic, rather than a genuine technical threat. According to reports, the government cited a little-known export control regulation, compelling Anthropic to block access for all non-U.S. persons, including its own international employees. The company complied, shutting down the models without a court order or specific technical details from the government. Cybersecurity expert Katie Moussouris revealed she was privately shown a research paper detailing a potential safeguard bypass in Fable 5. She argued the described method was minor and did not warrant an export ban, stating that attempts to "fix" it would only weaken the model's defensive capabilities. Moussouris and other experts have since called for the order to be revoked, warning it dangerously removes advanced cybersecurity tools from U.S. defenders. Analysts like Justin Hendrix suggest the move appears retaliatory and sets a dangerous precedent, signaling that the U.S. government can unilaterally shut down a tech company's products. The incident has raised concerns about the reliability of American AI and the potential for political interference in the tech industry, serving as a warning to the broader sector.

marsbit14m ago

The U.S. Government Blocked the Anthropic Model. It Wasn't About 'Jailbreaking' at All.

marsbit14m ago

Ray Dalio: AI Bull Market Continues to Soar, Should Investors Go All In or Cash Out and Leave the Field?

In his latest notes, Ray Dalio addresses a critical question for investors amid the AI-driven stock market surge: how should one allocate assets during a transformative technological revolution? Dalio emphasizes that technological advancement does not automatically make related stocks attractive. Historical tech cycles—marked by excitement, crowding, volatility, and eventual shakeouts—show that even long-term winners like Microsoft and Apple experienced severe drawdowns. Today's AI sector faces similar uncertainties: overinvestment, intensifying competition, geopolitical tensions (e.g., Taiwan's chip supply), tax policy shifts, anti-AI sentiment, and potential disruption from future technologies like quantum computing. Dalio's core argument focuses on the highly concentrated market structure, where a few tech giants dominate major indices. He warns investors against unknowingly holding concentrated, correlated exposures. Instead of chasing a handful of AI leaders, he advocates for a robust, diversified portfolio of 15 or more high-quality, uncorrelated investments, risk-balanced to match an investor's volatility tolerance. Mathematically, such diversification significantly improves the risk-return ratio—for example, holding 15 uncorrelated assets can boost the ratio by over four times compared to a single concentrated bet. Dalio cautions that future equity returns appear low, with his bubble indicator suggesting real returns could be negative over the next 5-10 years. He stresses that knowing what you don't know is as important as knowing what you do. In an environment of high uncertainty and concentration, avoiding large, concentrated bets on AI stocks is prudent. The optimal strategy is disciplined diversification—the "holy grail" of investing—to navigate this technologically driven cycle with lower risk and comparable or better returns.

marsbit18m ago

Ray Dalio: AI Bull Market Continues to Soar, Should Investors Go All In or Cash Out and Leave the Field?

marsbit18m ago

Trading

Spot
Futures
活动图片