Token Of Power Governance Exploit Drains $1.58 Million In WETH, TRM Says

bitcoinistPublicado a 2026-06-14Actualizado a 2026-06-14

Resumen

Blockchain intelligence firm TRM Labs reports a governance exploit against the Token of Power protocol, resulting in a loss of approximately $1.58 million in WETH. The attacker exploited a missing timelock in the protocol's Aragon DAO setup, allowing them to propose, vote on, and execute a malicious action within a single block. The attacker funded the operation with 662 ETH from Tornado Cash, purchased enough TOP tokens to gain majority voting power, minted 10 billion new TOP tokens, and swapped them for WETH via a Balancer pool before moving funds back through Tornado Cash. The incident underscores that governance design is a critical security risk in DeFi, where parameters like timelocks provide essential reaction time. It also highlights how mixers and liquidity pools can be utilized in exploits without being directly compromised. Observers are now watching for any movement of the stolen funds and further remediation details from involved parties. This event is part of a broader shift in crypto, emphasizing the importance of underlying infrastructure, security, and governance alongside market movements.

Blockchain intelligence firm TRM Labs has detailed a governance takeover exploit against the Token of Power protocol that drained approximately $1.58 million in WETH.

According to TRM’s analysis, the attacker exploited a weakness in the protocol’s Aragon DAO setup: the absence of a timelock. That allowed the attacker to propose, vote on, and execute a malicious governance action in a single block.

The attacker reportedly funded the operation with 662 ETH withdrawn from Tornado Cash, purchased enough TOP tokens to gain majority voting power, minted 10 billion new TOP, and swapped those tokens for WETH through a Balancer pool before routing funds back through Tornado Cash.

Why Timelocks Matter

The exploit is a clear example of how governance design can become a direct security risk. Token voting can look decentralized on paper, but if a malicious actor can quickly buy voting power and execute changes without delay, the governance system can become an attack surface.

Timelocks are meant to give users, developers, and security teams time to react before a proposal becomes executable. Without that delay, a hostile vote can become a drain before anyone can stop it.

Why This Matters

For DeFi users, the story is a reminder that smart-contract risk is not limited to code bugs. Governance parameters, treasury controls, and voting thresholds can be just as important.

It also highlights how mixers and liquidity pools can be used around an exploit without being the exploited protocol themselves.

What To Watch Next

The next thing to watch is whether stolen funds move again and whether the protocol, Aragon, or affected liquidity providers publish further remediation details.

The article must not say Tornado Cash itself was hacked.

Market Context

For Bitcoinist, the story sits inside a wider shift in crypto where infrastructure, security, governance, and token utility are becoming just as important as short-term price action. Traders still care about momentum, but they also need to understand the systems, risks, and product changes behind the headlines.

The useful angle is not to overstate the development, but to explain why it belongs in the daily market conversation. Strong crypto stories increasingly come from protocol updates, official notices, security reports, court records, and on-chain data rather than recycled commentary alone.

The editorial takeaway should stay grounded: the source confirms a meaningful crypto development, but the implications depend on adoption, follow-up disclosures, or further on-chain evidence. That balance keeps the piece useful without leaning on hype or unsupported claims.

From an editorial standpoint, this makes the story worth covering as part of the day’s broader crypto operating environment rather than as a standalone hype cycle. The strongest version of the piece should stay close to the verified source, explain the practical risk or opportunity, and leave room for follow-up once more official data, filings, or project statements are available.

This report is based on information from TRM Labs’ on-chain security report.

Preguntas relacionadas

QWhat vulnerability did the attacker exploit in the Token of Power protocol to drain $1.58 million?

AThe attacker exploited a weakness in the protocol's Aragon DAO setup: the absence of a timelock mechanism. This allowed them to propose, vote on, and execute a malicious governance action in a single block.

QAccording to the article, why are timelocks important in governance design?

ATimelocks are important because they give users, developers, and security teams time to review and react to a governance proposal before it becomes executable. Without this delay, a hostile actor can execute a damaging action before anyone can intervene.

QHow did the attacker fund the operation and cash out the stolen assets according to TRM's analysis?

AThe attacker funded the operation with 662 ETH withdrawn from Tornado Cash. They then purchased enough TOP tokens to gain majority voting power, minted 10 billion new TOP tokens, and swapped those tokens for WETH through a Balancer pool before routing the funds back through Tornado Cash.

QWhat key risk for DeFi users does this exploit highlight beyond smart-contract bugs?

AIt highlights that governance parameters, treasury controls, and voting thresholds can be just as critical a security risk as smart-contract code bugs. Poorly designed governance systems can themselves become an attack surface.

QWhat does the article suggest as the 'useful angle' for covering such developments in the crypto market?

AThe useful angle is to explain why the event belongs in the daily market conversation by focusing on protocol infrastructure, security, and governance, rather than overstating it or relying on hype. Coverage should stay close to verified sources, explain the practical risk or opportunity, and leave room for follow-up information.

Lecturas Relacionadas

U.S. Tech Momentum Stocks Post Largest Single-Day Gain Ever, But Is the Plunge Over?

US tech momentum stocks staged a sharp rebound on Tuesday (July 21st). Morgan Stanley's TMT Momentum Factor surged over 12%, marking its largest single-day gain on record, exceeding even peaks from the 2000 dot-com bubble. Key momentum indices from Goldman Sachs also posted their strongest daily performances in years. The rally was led by semiconductors, with the Philadelphia Semiconductor Index jumping 4.6%. This rebound followed three consecutive down days and a cumulative 33% plunge in momentum stocks, one of the steepest drawdowns since the dot-com era. Analysts attribute the surge largely to a short squeeze. Heavy selling had pushed high-beta momentum stocks into deeply oversold territory, forcing many short sellers, particularly in Asia, to cover their positions, creating a self-reinforcing buying spiral. However, the rebound's internals appear weak. Trading volume was notably low, and advancing stocks still lagged decliners on the S&P 500, indicating a narrow, concentrated rally rather than broad market participation. Diverging views emerge on the outlook. BTIG warns the bounce has hit key resistance and recommends selling into strength, citing extreme volatility and historical parallels to past market tops. Conversely, Goldman Sachs and UBS believe the momentum unwind is nearing its end, suggesting it may be time to gradually add exposure, as positioning has been significantly reduced. They caution, however, that high volatility warrants a measured approach, potentially using defined-risk strategies. The upcoming earnings season, particularly reports from major tech firms like Alphabet, is seen as a critical test for the rally's sustainability. Simultaneously, bond markets flashed a warning, with yields rising partly due to spiking oil prices. Analysts note that if long-term Treasury yields break decisively higher, it could pose a significant headwind for equities, especially growth stocks.

marsbitHace 5 min(s)

U.S. Tech Momentum Stocks Post Largest Single-Day Gain Ever, But Is the Plunge Over?

marsbitHace 5 min(s)

U.S. Tech Momentum Stocks Record Largest Single-Day Gain Ever, but Has the Rout Ended?

U.S. tech momentum stocks staged a dramatic rebound on Tuesday, July 21st. Key momentum indices like the Morgan Stanley TMT Momentum Factor and Goldman Sachs' High Beta Momentum Long Index posted historic or near-historic single-day gains, fueled largely by semiconductor stocks. This sharp rally followed a severe three-day sell-off that saw momentum stocks plunge 33%, marking one of the steepest pullbacks since the dot-com bubble. Analysts attribute the bounce primarily to a short squeeze, as forced covering from over-leveraged traders, particularly in Asia, created a buying spiral. However, the rally's health is questioned due to weak market breadth—overall trading volume was low, and decliners outnumbered advancers in the S&P 500 despite the index's gain—suggesting a narrow, concentrated surge rather than broad recovery. Opinions on the sustainability diverge. BTIG strategists warn the rebound has hit key resistance levels, citing extreme volatility and historic stock dispersion as signs of an ongoing broader correction, and recommend selling into strength. Conversely, Goldman Sachs and UBS view the aggressive momentum unwinding as nearing its end, noting reduced positioning and a lack of new fundamental catalysts. They suggest the sell-off presents a selective opportunity to add exposure, albeit cautiously and gradually using defined-risk strategies. The immediate trajectory hinges on the ongoing earnings season, with market focus on Alphabet's capital expenditure guidance for AI investment clarity. Meanwhile, bond markets present a risk, with rising Treasury yields—potentially heading toward 5.5%—and widening credit spreads for mega-cap tech companies posing a threat to equity valuations. The combination of technical factors, earnings results, and macro conditions leaves the durability of the rebound in doubt.

链捕手Hace 8 min(s)

U.S. Tech Momentum Stocks Record Largest Single-Day Gain Ever, but Has the Rout Ended?

链捕手Hace 8 min(s)

Long-Divided Must Unite, Long-United Must Divide: When L1 Becomes Its Own Rollup, What Is Ethereum's Endgame?

"The Inevitable Cycle: When L1 Becomes Its Own Rollup – What is Ethereum's Endgame?" For years, the Ethereum community grappled with concerns that L2s were fragmenting the ecosystem and eroding L1's value. While L2s provided cheaper execution, they also splintered liquidity and the unified user experience of a single chain. This has prompted a fundamental reassessment of the relationship between L1 and L2. Ethereum's roadmap is evolving. The "Scale" initiative merges L1 and L2 expansion into a holistic framework. L1 itself is advancing with higher gas limits, statelessness, and zkEVM verification, no longer content to be just a low-throughput settlement layer. Consequently, the primary value proposition of L2s is shifting from merely providing cheap blockspace to offering L1 cannot easily provide: application-specific optimizations, privacy features, and flexible governance models. L2s are becoming a spectrum of execution environments with varying degrees of security inheritance from Ethereum. A critical challenge in this multi-chain future is interoperability. The vision is to make Ethereum "feel like one chain again." This relies on advancements in native account abstraction (like EIP-7702) and intent-based architectures (Open Intents Framework), where users declare desired outcomes, and solvers handle the complex cross-chain execution. Furthermore, shortening Ethereum's finality time from minutes to seconds is crucial, as it underpins trust between chains for bridges, stablecoins, and cross-chain applications. Perhaps the most provocative idea is that Ethereum L1 itself could become a form of "its own Rollup." As zkEVM and proof systems mature, high-performance nodes could execute transactions and generate validity proofs. Regular validators would then verify these proofs instead of re-executing all transactions. This blurs the traditional L1/L2 hierarchy, making "Rollup" more of a general execution-verification architecture. Native Rollup aims to integrate L2 validation more directly into the Ethereum protocol, allowing L2s to inherit L1's security more fully and move away from reliance on security councils. In the end, L2s are not destined to replace L1 or be made obsolete by it. The likely future is a unified system where diverse execution environments—each optimized for specific use cases like DeFi, gaming, or privacy—coexist. They will share a common foundation of security, liquidity, and verifiable state, seamlessly connected to restore a cohesive user experience. The next phase for Ethereum is not just about scaling through separation, but about intelligently reintegrating what was separated back into a coherent whole.

链捕手Hace 24 min(s)

Long-Divided Must Unite, Long-United Must Divide: When L1 Becomes Its Own Rollup, What Is Ethereum's Endgame?

链捕手Hace 24 min(s)

Agent Race Ends, Super Workbench Takes Over

The era of fragmented AI agents is ending. Over the past month, China's tech giants—Tencent, Alibaba, and ByteDance—have simultaneously shifted strategy: instead of launching new, standalone AI agents, they are consolidating their various agent projects into unified "super workbenches." Tencent integrated its QClaw teams into WorkBuddy, a strategic product hailed as a potential third flagship after QQ and WeChat. Alibaba is merging its QoderWork, Wukong, and MuleRun agents into a new "Qianwen Office" platform under DingTalk's leadership. ByteDance rebranded its TRAE SOLO coding agent to TRAE Work, signaling a broader focus on workflow collaboration. This convergence marks a pivotal industry consensus. The initial exploration phase, where companies rapidly built numerous overlapping agents for different scenarios, proved costly and inefficient. With open-source tools eroding technical barriers, competition has shifted from agent creation to resource consolidation and cost control. Historically, platform wars are won not by creating more products, but by simplifying them—as seen with browsers unifying web access and super-apps consolidating services. Now, the "super workbench" aims to become the unified AI entry point for work. This reflects a deeper market realization: the primary audience for AI is no longer just programmers (a market in the tens of millions) but all knowledge workers (a market of billions). The real opportunity lies in augmenting everyday tasks—managing emails, documents, data, and meetings—across the entire workday. The core battleground is becoming control over the primary AI entry point that employees use daily. Tencent's WorkBuddy leverages WeChat and Tencent Docs; Alibaba's Qianwen Office taps into DingTalk's organizational data; ByteDance's TRAE Work integrates with Feishu's workflows. Whoever owns this "super workbench" gains strategic control over orchestrating enterprise data and APIs. This shift is redefining enterprise software. Traditional SaaS applications, valued for their user interfaces, will recede into the background. Their core functionalities will be exposed as standardized "Skills" or APIs for the super workbench's agents to invoke. Software value will shift from selling user seats to charging based on API calls and outcomes delivered. The evolution of agents is moving through clear stages: first as novel standalone products, then as consolidated primary work entry points, and finally as pervasive, invisible capabilities embedded into the digital fabric. The recent moves by major tech firms signal the transition from the first stage into the second, accelerating toward the third. In the end, the most successful agent technology may become invisible—like electricity or the HTTP protocol—a fundamental, unnamed infrastructure powering work itself.

marsbitHace 51 min(s)

Agent Race Ends, Super Workbench Takes Over

marsbitHace 51 min(s)

Trading

Spot
活动图片