None
EN
StrongBlock Loses $72K After Attacker Hijacks Abandoned Governance
['Danielle Du Toit', 'Danielle Du Toit Is A Crypto Security', 'Investigations Journalist Covering Digital-Asset Crime', 'Protocol Exploits', 'Scams', 'Enforcement Actions', 'Consumer Protection. With An Honours Degree In Criminology', 'She Examines How Crypto Attacks Happen', 'How Stolen Funds Move', 'How Regulators']
Coinpaper
An attacker drained approximately $72,000 in STRONG and STRNGR tokens after using StrongBlock’s abandoned governance system to seize administrative control of key protocol contracts.
Instead, the attacker used StrongBlock’s governance rules exactly as they were designed, which turned the protocol’s voting system into the mechanism behind the theft.
Malicious proposal transferred administrator rightsThe attack began when the attacker acquired enough STRONG tokens to control the outcome of a governance vote.
Smart contracts, governance permissions and token balances are still operational on-chain even after developers and community members stop actively monitoring them.
Abandoned governance can become a security liabilityToken-based governance generally assumes that voters with large holdings have a financial interest in protecting the protocol.