Token Of Power Governance Exploit Drains $1.58 Million In WETH, TRM Says

bitcoinist2026-06-14 tarihinde yayınlandı2026-06-14 tarihinde güncellendi

Özet

Blockchain intelligence firm TRM Labs reports a governance exploit against the Token of Power protocol, resulting in a loss of approximately $1.58 million in WETH. The attacker exploited a missing timelock in the protocol's Aragon DAO setup, allowing them to propose, vote on, and execute a malicious action within a single block. The attacker funded the operation with 662 ETH from Tornado Cash, purchased enough TOP tokens to gain majority voting power, minted 10 billion new TOP tokens, and swapped them for WETH via a Balancer pool before moving funds back through Tornado Cash. The incident underscores that governance design is a critical security risk in DeFi, where parameters like timelocks provide essential reaction time. It also highlights how mixers and liquidity pools can be utilized in exploits without being directly compromised. Observers are now watching for any movement of the stolen funds and further remediation details from involved parties. This event is part of a broader shift in crypto, emphasizing the importance of underlying infrastructure, security, and governance alongside market movements.

Blockchain intelligence firm TRM Labs has detailed a governance takeover exploit against the Token of Power protocol that drained approximately $1.58 million in WETH.

According to TRM’s analysis, the attacker exploited a weakness in the protocol’s Aragon DAO setup: the absence of a timelock. That allowed the attacker to propose, vote on, and execute a malicious governance action in a single block.

The attacker reportedly funded the operation with 662 ETH withdrawn from Tornado Cash, purchased enough TOP tokens to gain majority voting power, minted 10 billion new TOP, and swapped those tokens for WETH through a Balancer pool before routing funds back through Tornado Cash.

Why Timelocks Matter

The exploit is a clear example of how governance design can become a direct security risk. Token voting can look decentralized on paper, but if a malicious actor can quickly buy voting power and execute changes without delay, the governance system can become an attack surface.

Timelocks are meant to give users, developers, and security teams time to react before a proposal becomes executable. Without that delay, a hostile vote can become a drain before anyone can stop it.

Why This Matters

For DeFi users, the story is a reminder that smart-contract risk is not limited to code bugs. Governance parameters, treasury controls, and voting thresholds can be just as important.

It also highlights how mixers and liquidity pools can be used around an exploit without being the exploited protocol themselves.

What To Watch Next

The next thing to watch is whether stolen funds move again and whether the protocol, Aragon, or affected liquidity providers publish further remediation details.

The article must not say Tornado Cash itself was hacked.

Market Context

For Bitcoinist, the story sits inside a wider shift in crypto where infrastructure, security, governance, and token utility are becoming just as important as short-term price action. Traders still care about momentum, but they also need to understand the systems, risks, and product changes behind the headlines.

The useful angle is not to overstate the development, but to explain why it belongs in the daily market conversation. Strong crypto stories increasingly come from protocol updates, official notices, security reports, court records, and on-chain data rather than recycled commentary alone.

The editorial takeaway should stay grounded: the source confirms a meaningful crypto development, but the implications depend on adoption, follow-up disclosures, or further on-chain evidence. That balance keeps the piece useful without leaning on hype or unsupported claims.

From an editorial standpoint, this makes the story worth covering as part of the day’s broader crypto operating environment rather than as a standalone hype cycle. The strongest version of the piece should stay close to the verified source, explain the practical risk or opportunity, and leave room for follow-up once more official data, filings, or project statements are available.

This report is based on information from TRM Labs’ on-chain security report.

İlgili Sorular

QWhat vulnerability did the attacker exploit in the Token of Power protocol to drain $1.58 million?

AThe attacker exploited a weakness in the protocol's Aragon DAO setup: the absence of a timelock mechanism. This allowed them to propose, vote on, and execute a malicious governance action in a single block.

QAccording to the article, why are timelocks important in governance design?

ATimelocks are important because they give users, developers, and security teams time to review and react to a governance proposal before it becomes executable. Without this delay, a hostile actor can execute a damaging action before anyone can intervene.

QHow did the attacker fund the operation and cash out the stolen assets according to TRM's analysis?

AThe attacker funded the operation with 662 ETH withdrawn from Tornado Cash. They then purchased enough TOP tokens to gain majority voting power, minted 10 billion new TOP tokens, and swapped those tokens for WETH through a Balancer pool before routing the funds back through Tornado Cash.

QWhat key risk for DeFi users does this exploit highlight beyond smart-contract bugs?

AIt highlights that governance parameters, treasury controls, and voting thresholds can be just as critical a security risk as smart-contract code bugs. Poorly designed governance systems can themselves become an attack surface.

QWhat does the article suggest as the 'useful angle' for covering such developments in the crypto market?

AThe useful angle is to explain why the event belongs in the daily market conversation by focusing on protocol infrastructure, security, and governance, rather than overstating it or relying on hype. Coverage should stay close to verified sources, explain the practical risk or opportunity, and leave room for follow-up information.

İlgili Okumalar

US Senate Makes Important Amendments to "Conflict of Interest" Section of Cryptocurrency Bill

The U.S. Senate has taken a key step regarding the CLARITY Act, which could shape the future of the U.S. crypto market. On July 29, Senators Tom Tillis and Ruben Gallego finalized amendments to the bill's "conflict of interest" rules, one of its most contentious aspects. The bipartisan bill aims to tighten restrictions on high-level federal officials' ties to digital assets. The new text, crafted as an alternative to a White House-endorsed ethics code, is expected to impose stricter rules limiting officials' ability to issue or directly participate in digital asset projects. However, with Congress entering an August recess and the revised text not yet reviewed by much of the Senate, the bill's timeline is uncertain. Senate Majority Leader John Thune indicated a procedural vote could occur between July 29 and August 1 but expressed doubt the full bill could pass before the break. The House-approved CLARITY Act, passed in July 2025, has been under Senate negotiation for over a year. Key goals of the CLARITY Act include clarifying jurisdictional boundaries between the SEC and CFTC, setting rules for digital commodity spot markets, and addressing topics like stablecoin yields, DeFi, and illicit financing. The stablecoin yield provisions could significantly impact U.S.-based DeFi protocols, exchanges, and issuers, affecting their global competitiveness. The outcome is being closely watched by both the U.S. and global digital asset markets.

cryptonews.ru44 dk önce

US Senate Makes Important Amendments to "Conflict of Interest" Section of Cryptocurrency Bill

cryptonews.ru44 dk önce

Pavel Durov Designated as a Terrorist in Russia. What Does This Mean for Telegram Users?

Pavel Durov, the founder of Telegram, has been added to Russia's list of terrorists and extremists by Rosfinmonitoring, as published on July 30. The entry includes his name and date of birth. The designation follows an announcement by the Russian Federal Security Service (FSB) on July 29, which charged Durov with aiding terrorist activity. The FSB alleges that a Telegram dating bot named "DaiVinchik" was used to recruit 46 individuals for attacks on police and arson, orchestrated by Ukrainian special services. The FSB also accuses Telegram's administration of failing to remove channels and bots used by Ukrainian intelligence and extremist groups. Durov is reportedly subject to an international arrest warrant. Inclusion on the Rosfinmonitoring list leads to significant restrictions: the freezing of Durov's bank accounts and assets, severe limitations on financial transactions, and a ban on election participation, media interaction, and event organization. Transfers to his accounts may be considered terrorism financing. For ordinary Russian Telegram users, purchasing Telegram Premium is not classified as financing terrorism, according to an IT expert. General use of the messenger—messaging, managing channels—does not automatically make a user a participant in extremist activity. There has been no official decision to ban Telegram itself. It is noted that French authorities are also investigating Durov over allegations of inadequate measures against criminal activity on the platform and insufficient cooperation with law enforcement. Durov denies all charges.

cryptonews.ru53 dk önce

Pavel Durov Designated as a Terrorist in Russia. What Does This Mean for Telegram Users?

cryptonews.ru53 dk önce

İşlemler

Spot
活动图片