Attacker drains $1.58M from Token of Power pool via Aragon DAO governance exploit

Source Cryptopolitan

An attacker has exploited a governance misconfiguration in the Token of Power (TOP) Aragon DAO.

They reportedly used majority voting power to mint tokens and drain roughly 944 WETH, which is worth around $1.58 million, from a Balancer V1 liquidity pool on Ethereum.

Various blockchain security firms flagged the incident, relying on the effective vector, which showed that TOP’s total token supply was just 16,384 tokens, and the attacker held slightly more than half of them.

How did the TOP token exploit work?

TOP is a MiniMeToken governed through Aragon’s voting infrastructure. According to Blockaid’s analysis, the attacker accumulated 8,192.000001 TOP, and this was more than enough to help them to clear the 50% threshold needed to pass governance proposals unilaterally. 

As a result of the Aragon Voting app on TOP’s DAO having no timelock, the attacker was able to create a proposal, vote it through, and execute it within a single transaction.

BlockSec Phalcon confirmed that the passed proposal minted a large quantity of new TOP tokens to the attacker’s address. The attacker then used those freshly minted tokens to drain the TOP/WETH Balancer V1 BPool, extracting 944.2 WETH.

It was noted that Balancer’s protocol was not itself vulnerable. The pool was simply the place where the attacker converted inflated TOP holdings into WETH.

How did the attacker move the funds?

The attacker’s wallet, 0xff8eF7bC455a57e5893232203052Ce0232b39Fa2, was funded through Tornado Cash. The exploit was executed in a single transaction through a dedicated contract, per Blockaid’s on-chain breakdown.

A textbook governance-takeover scenario

The root cause of the exploit was not a smart contract bug in the traditional sense. TOP’s token has a relatively small supply and low market capitalization, which made acquiring a controlling stake cheap.

When that was combined with Aragon’s voting configuration, which allows same-block proposal creation, voting, and execution, the attacker faced no major barrier between gaining majority power and draining funds.

Aragon’s own documentation on DAO security highlights access controls and the importance of restricting who can call sensitive functions on smart contracts.

In that same documentation, the organization stated that onchain functions are accessible by all by default and that authorized access “must be restricted to authorized addresses” when token minting or fund movements are involved.

However, TOP’s configuration did not enforce a timelock or quorum delay that could have given other token holders time to react.

What to watch

Neither the Token of Power team nor Aragon has issued any statement concerning the exploit as of publication. 

While the stolen WETH is still traceable onchain, the Tornado Cash funding of the attacker’s wallet complicates recovery prospects. The incident is a reminder that governance parameters (timelocks, quorum thresholds, proposal delays) are not optional safety features for low-supply tokens with meaningful treasury exposure.

The smartest crypto minds already read our newsletter. Want in? Join them.

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
XRP Just Printed A Rare Binance Signal As Market Volatility AcceleratesXRP is trying to reclaim the $1.15 level after a decline that carried the price to its lowest point since 2024 — a drop that has erased months of recovery progress and left holders navigating a
Author  Cryptopolitan
17 hours ago
XRP is trying to reclaim the $1.15 level after a decline that carried the price to its lowest point since 2024 — a drop that has erased months of recovery progress and left holders navigating a
placeholder
Google and Nvidia earmark Intel for backup chip supplier roleAlphabet’s Google has placed an order with Intel to produce over three million tensor processing units by year 2028, according to a report from The Information. Nvidia is also evaluating Intel’s technology for a multi-chip processor, though it has not committed to any order. If the deals are fully realized, this action would mark a...
Author  Cryptopolitan
17 hours ago
Alphabet’s Google has placed an order with Intel to produce over three million tensor processing units by year 2028, according to a report from The Information. Nvidia is also evaluating Intel’s technology for a multi-chip processor, though it has not committed to any order. If the deals are fully realized, this action would mark a...
placeholder
OpenAI files for IPO as AI arms race intensifies and Wall Street takes noticeOpenAI has confidentially filed an S-1 registration statement for an initial public offering (IPO) with the US Securities and Exchange Commission. The move comes as competition among leading AI developers accelerates sharply, with rival firms such as Anthropic also moving toward public listings and investor enthusiasm for AI technologies reaching historic highs. In a post...
Author  Cryptopolitan
17 hours ago
OpenAI has confidentially filed an S-1 registration statement for an initial public offering (IPO) with the US Securities and Exchange Commission. The move comes as competition among leading AI developers accelerates sharply, with rival firms such as Anthropic also moving toward public listings and investor enthusiasm for AI technologies reaching historic highs. In a post...
placeholder
Why are Altcoins Suddenly Exploding? Two Forces are Driving the MoveAltcoins ripped higher on Monday as AI-linked tokens led a sharp rebound across an oversold crypto market.Worldcoin (WLD), NEAR Protocol (NEAR), and Bittensor (TAO) posted double-digit weekly gains wh
Author  Beincrypto
17 hours ago
Altcoins ripped higher on Monday as AI-linked tokens led a sharp rebound across an oversold crypto market.Worldcoin (WLD), NEAR Protocol (NEAR), and Bittensor (TAO) posted double-digit weekly gains wh
placeholder
Bitcoin’s “Electrical Cost” Floor Sits at $48,694: Is That the Bottom?Bitcoin (BTC) trades near $63,000 after recovering about 4%, yet it sits roughly 50% below its record high. One on-chain marker, the Bitcoin Electrical Cost near $48,694, now frames the question of wh
Author  Beincrypto
17 hours ago
Bitcoin (BTC) trades near $63,000 after recovering about 4%, yet it sits roughly 50% below its record high. One on-chain marker, the Bitcoin Electrical Cost near $48,694, now frames the question of wh
goTop
quote