{"id":36538,"date":"2026-08-06T10:19:13","date_gmt":"2026-08-06T10:19:13","guid":{"rendered":"https:\/\/bitunikey.com\/news\/strongblock-loses-72k-after-attacker-hijacks-abandoned-governance-system\/"},"modified":"2026-08-06T10:19:40","modified_gmt":"2026-08-06T10:19:40","slug":"strongblock-loses-72k-after-attacker-hijacks-abandoned-governance-system","status":"publish","type":"post","link":"https:\/\/bitunikey.com\/news\/strongblock-loses-72k-after-attacker-hijacks-abandoned-governance-system\/","title":{"rendered":"StrongBlock loses $72K after attacker hijacks abandoned governance system"},"content":{"rendered":"<p><\/p>\n<div class=\"post-detail__content blocks\">\n<p class=\"is-style-lead\">An attacker has drained about $72,000 worth of STRONG and STRNGR tokens after taking control of StrongBlock\u2019s abandoned on-chain governance system through a malicious proposal.<\/p>\n<div id=\"cn-block-summary-block_eea5bc8045ecf6346f0c8214777c0eb2\" class=\"cn-block-summary\">\n<div class=\"cn-block-summary__nav tabs\">\n        <span class=\"tabs__item is-selected\">Summary<\/span>\n    <\/div>\n<div class=\"cn-block-summary__content\">\n<ul class=\"wp-block-list\">\n<li>An attacker drained about $72,000 after taking control of StrongBlock\u2019s abandoned governance system.<\/li>\n<li>A malicious proposal gave the attacker admin control of the protocol\u2019s Governor contract.<\/li>\n<li>The attacker upgraded the Governor contract before stealing 32,695 STRONG and 383,447 STRNGR tokens.<\/li>\n<li>The incident relied on governance control rather than a smart contract vulnerability.<\/li>\n<li>The attack follows recent crypto security breaches targeting governance, infrastructure and wallet software.<\/li>\n<\/ul><\/div>\n<\/div>\n<p><!-- .cn-block-summary --><\/p>\n<p>According to blockchain security firm Defimon Alerts, the attacker acquired enough voting power in StrongBlock\u2019s governance to pass a proposal that ultimately transferred administrative control of the protocol\u2019s Governor contract before the funds were removed.<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-x wp-block-embed-x\">\n<div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">\ud83d\udea8 Governance Takeover of <a rel=\"nofollow\" target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/x.com\/Strongblock_io?ref_src=twsrc%5Etfw\">@Strongblock_io<\/a> \u2013 Loss $72K<\/p>\n<p>Token: <a rel=\"nofollow\" target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/x.com\/search?q=%24STRONG&amp;src=ctag&amp;ref_src=twsrc%5Etfw\">$STRONG<\/a><br \/>Network: Ethereum<\/p>\n<p>The attacker exploited StrongBlock&#8217;s abandoned on-chain Governor. Holding a majority of the now near-worthless STRONG vote token, they pushed a proposal calling setPendingAdmin(attacker) on\u2026 <a rel=\"nofollow\" target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/t.co\/1FBfWYn9tC\">pic.twitter.com\/1FBfWYn9tC<\/a><\/p>\n<p>\u2014 Defimon Alerts (@DefimonAlerts) <a rel=\"nofollow\" target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/x.com\/DefimonAlerts\/status\/2085246380231004319?ref_src=twsrc%5Etfw\">August 6, 2026<\/a><\/p><\/blockquote>\n<\/div>\n<\/figure>\n<p>Instead of exploiting a flaw in StrongBlock\u2019s smart contracts, the attacker used the protocol\u2019s own governance process to gain privileged access. After obtaining administrator rights, the attacker upgraded the Governor proxy to a new implementation that allowed arbitrary contract calls using the Governor\u2019s authority.<\/p>\n<p>The incident adds to a series of recent crypto security events that have targeted governance systems, supporting infrastructure, and wallet software through different attack paths rather than relying solely on smart contract bugs.<\/p>\n<h2 class=\"wp-block-heading\">StrongBlock governance was used to seize protocol control<\/h2>\n<p>Before the attack unfolded, the attacker accumulated a majority of the protocol\u2019s STRONG governance token, which Defimon Alerts described as having become nearly worthless after the project was abandoned.<\/p>\n<p>Holding enough voting power, the attacker submitted a governance proposal instructing the Governor\u2019s Upgrader contract to execute setPendingAdmin(attacker), making the attacker\u2019s address the pending administrator.<\/p>\n<p>    <!-- .cn-block-related-link --><\/p>\n<p>Rather than bypassing governance, the proposal advanced through every required stage. It received sufficient votes, entered the queue, and was executed according to the protocol\u2019s normal governance process, eventually transferring administrative control of the Governor proxy to the attacker.<\/p>\n<p>Administrative privileges then allowed the attacker to replace the Governor implementation with a minimal, unverified contract containing a forward(address, bytes) function.<\/p>\n<p>According to Defimon Alerts, the function was restricted to the attacker\u2019s externally owned account and effectively served as an arbitrary-call mechanism, allowing the attacker to execute transactions with the Governor\u2019s authority across StrongBlock\u2019s contracts.<\/p>\n<p>The token transfers occurred in the following transaction.<\/p>\n<h2 class=\"wp-block-heading\">More than 400,000 tokens were removed from the pool<\/h2>\n<p>Using the upgraded implementation, the attacker executed transactions that transferred assets from the protocol\u2019s pool rather than exploiting an error in the protocol\u2019s contract logic.<\/p>\n<p>Defimon Alerts said the attacker removed 32,695 STRONG tokens together with 383,447 STRNGR, bringing the estimated value of the stolen assets to approximately $72,000.<\/p>\n<p>The security firm characterized the incident as a governance takeover because every critical action, including the administrator change and contract upgrade, occurred through governance permissions instead of a software vulnerability.<\/p>\n<p>By replacing the Governor implementation before moving the funds, the attacker turned the governance contract itself into the mechanism used to authorize the transfers.<\/p>\n<h2 class=\"wp-block-heading\">Governance attacks differ from recent crypto exploits<\/h2>\n<p>Recent security incidents have demonstrated that attackers are increasingly targeting different parts of crypto infrastructure.<\/p>\n<p>Late last month, decentralized perpetuals protocol Ostium concluded that attackers stole 23.75 million USDC after gaining unauthorized access to its off-chain infrastructure instead of exploiting vulnerabilities in its smart contracts.<\/p>\n<p>According to Ostium\u2019s post-mortem, fraudulent BTC-USD price reports submitted through trusted infrastructure allowed the attacker to generate artificial trading profits that were settled against the protocol\u2019s public OLP liquidity vault. Earlier analysis from blockchain security firm Blockaid similarly concluded that manipulated oracle reports, rather than flaws in contract code, enabled the exploit.<\/p>\n<p>Separately, the Coldcard wallet incident originated from a firmware issue introduced during a March 2021 software update. Coinkite and Block\u2019s Bitcoin engineering and security teams concluded that affected firmware generated wallet seeds using a deterministic pseudo-random generator instead of the intended hardware random-number generator, reducing the entropy used to create private keys.<\/p>\n<p>Galaxy Research has confirmed thefts totaling 1,596 BTC across roughly 7,300 addresses linked to three attack waves. The research firm has also identified a suspected fourth coordinated wave involving another 448.7 BTC, although it has not yet included those addresses in its confirmed total because additional victim confirmation remains pending.<\/p>\n<h2 class=\"wp-block-heading\">Coldcard review has expanded into Bitcoin-wide security checks<\/h2>\n<p>The Coldcard incident has prompted developers to review a much larger portion of Bitcoin\u2019s software ecosystem.<\/p>\n<p>Earlier this week, Bitcoin developer Calle said the volunteer Bitcoin Red Team had completed AI-assisted and manual reviews across 390 Bitcoin-related repositories, identifying 4,962 potential security issues, including 720 classified as high or critical severity.<\/p>\n<p>According to Calle, about 21.4% of the reported findings have already been reproduced through manual verification before being privately disclosed to affected developers.<\/p>\n<p>The review campaign covers Bitcoin wallets, cryptographic libraries, infrastructure software, and other open-source projects. Calle said OpenSats is funding approximately $10,000 per day in computing costs, while Kimi Moonshot has provided AI accounts and access to its Kimi K3 model to support the effort.<\/p>\n<h2 class=\"wp-block-heading\">Governance remained the attack surface<\/h2>\n<p>Unlike the Ostium exploit or the Coldcard wallet incident, the StrongBlock attack did not rely on compromised infrastructure, oracle manipulation, or cryptographic weaknesses.<\/p>\n<p>Instead, the attacker first obtained control of governance before modifying the protocol\u2019s own administrator contract.<\/p>\n<p>According to Defimon Alerts, upgrading the Governor proxy to an implementation containing the restricted forward(address, bytes) function gave the attacker\u2019s wallet exclusive authority to execute arbitrary calls through the Governor contract.<\/p>\n<p>The stolen assets were then transferred using permissions that the protocol itself granted after the governance proposal completed, illustrating how abandoned governance systems can continue exercising administrative control over protocol contracts even after development activity has largely ceased.<\/p>\n<p>    <!-- .cn-block-related-link --><\/p>\n<\/p><\/div>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"<p>An attacker has drained about $72,000 worth of STRONG and STRNGR tokens after taking control of StrongBlock\u2019s abandoned on-chain governance system through a malicious proposal. Summary An attacker drained about&hellip;<\/p>\n","protected":false},"author":1,"featured_media":13174,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-36538","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cryptocurrency"],"_links":{"self":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts\/36538","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/comments?post=36538"}],"version-history":[{"count":1,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts\/36538\/revisions"}],"predecessor-version":[{"id":36539,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts\/36538\/revisions\/36539"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/media\/13174"}],"wp:attachment":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/media?parent=36538"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/categories?post=36538"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/tags?post=36538"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}