00:00
Money for You
Money for You
USD/RUB
EUR/RUB
Cryptocurrency

StrongBlock Drained of $72K After Abandoned Governance Hijack

An attacker seized control of StrongBlock’s dormant governance system to siphon $72,000 in tokens, proving that abandoned protocols remain vulnerable to hostile takeovers. By accumulating a majority of the nearly worthless STRONG governance tokens, the perpetrator forced through a malicious proposal that granted them full administrative authority over the contract.

StrongBlock Drained of $72K After Abandoned Governance Hijack

The attacker bypassed traditional smart contract exploits, choosing instead to weaponize the protocol’s internal processes. After securing enough voting power, they submitted a proposal to the Governor contract that successfully designated their address as the system's new administrator. The proposal moved through every standard stage of the governance cycle, receiving sufficient votes and executing without resistance.

Once in control, the attacker upgraded the Governor proxy to a custom, unverified contract. This new implementation featured a restricted function that allowed the attacker to execute arbitrary transactions across the protocol's infrastructure. This mechanism was used to drain 32,695 STRONG and 383,447 STRNGR tokens from the liquidity pool. Security firm Defimon Alerts confirmed the breach was purely a governance takeover, as no underlying code vulnerabilities were utilized to authorize the transfers. This incident highlights a growing trend in crypto security where attackers target peripheral infrastructure and governance mechanisms rather than core smart contract logic.

Share

Comments (0)

Leave a comment

No comments yet. Be the first!