Newsroom
10 June, 2026 / News / AI / 438 reads / Tags: weth, aragon, attacker, balancer, governance

A governance takeover in the Token of Power (TOP) DAO allowed an attacker to mint billions of tokens and extract 944.2 WETH from a Balancer liquidity pool, exposing risks in legacy DAO setups
The Token of Power protocol fell victim to a calculated governance attack that leveraged weaknesses in its Aragon DAO configuration. With the project's MiniMeToken having a total supply of only 16,384 TOP tokens, acquiring majority control required just over 8,192 tokens. The attacker secured this threshold and immediately moved to execute a malicious proposal.
Because the governance system lacked a timelock mechanism, the attacker created, voted on, and executed the proposal in a single transaction. The proposal called the TokenManager's minting function, generating 10 billion new TOP tokens sent directly to the attacker's contract.
The attacker did not target Balancer's protocol directly. Instead, the TOP/WETH Balancer V1 pool served as the exit liquidity point. By dumping the massively inflated TOP supply into the pool, the attacker swapped against the available WETH reserves, leaving liquidity providers with heavily diluted tokens.
Security researchers from Blockaid, PeckShield, Cyvers, and BlockSec tracked the activity. The attacker performed multiple swaps within one transaction to maximize the drain. On-chain data showed the wallet address 0xff8eF7bC455a57e5893232203052Ce0232b39Fa2 as the primary executor.
BlockSec analysis indicated the attacker spent roughly 662 WETH to acquire the necessary TOP tokens beforehand, resulting in an estimated net profit of around 282 WETH after the exploit.
The attacker's initial funds came through Tornado Cash. After draining the pool, the stolen WETH was quickly routed back through the mixer with multiple deposits (including 100 ETH and 10 ETH transactions) to obscure the trail. Within hours, the attacker's wallet held almost no traceable ETH.
The incident stemmed from a misconfigured Aragon DAO setup combined with a low token supply and low market valuation, making majority control inexpensive. The absence of standard safeguards—such as timelocks, adequate quorum requirements, or proposal delays—allowed the attack to succeed rapidly.
Security firms emphasized that projects using Aragon or similar frameworks should review voting power distribution, minting permissions, and execution delays. Timelocks provide communities time to respond to suspicious proposals, a critical protection missing here.
“The Aragon Voting app allowed create → vote → execute in a single tx with no timelock,” Blockaid reported in its assessment of the governance vulnerability.
This case adds to ongoing concerns about governance security in decentralized finance, particularly for smaller projects with legacy infrastructure. While smart contract bugs often grab headlines, governance takeovers represent a distinct vector that weaponizes built-in protocol mechanisms.
Low-supply tokens with significant liquidity exposure remain attractive targets. The event serves as a reminder that strong access controls, restricted minting functions, and time-delay mechanisms are essential rather than optional. No issues were found with Balancer itself, underscoring that the vulnerability resided entirely in the project's governance design.
| Aspect | Details |
|---|---|
| Token Supply (Initial) | 16,384 TOP |
| Attacker Control | ~8,192 TOP (>50%) |
| Tokens Minted | 10 billion |
| Amount Drained | 944.2 WETH (~$1.58M) |
| Primary Vector | Aragon DAO misconfiguration |
The Token of Power team has not yet issued a detailed public response or recovery plan as of the latest reports.









