Bonk's $20M Governance Buyout, Summer.fi's $6M Vault Drain, and Aptos's $70B Move VM Bug | Burn Notice #8
Every loss that mattered this week came through machinery each team had stopped watching.
The week's largest losses are covered below, but the entries worth pausing on sit lower in the digest, where the attacks went after the software around crypto rather than the contracts themselves. One browser extension built to steal cryptocurrency now retrieves its command server from a smart contract. The design keeps the attacker's infrastructure on-chain, out of reach of an ordinary takedown. Another, an ad blocker with more than ten million installs, was found to carry a dormant switch that could run code on any page. The contracts, as always, are audited line by line. The browser tab beside them, and the registries their code is pulled from, rarely get the same attention.
In today’s issue.
Lazy Summer’s $6M vault drain traces to an impaired market still priced into NAV three months after its offboarding began.
BonkDAO’s treasury lost $20M after an attacker bought a one-percent quorum and voted, almost alone, to move the funds.
Aptos patched a $70B Move VM type-confusion bug back in February, and Hexens has just published the $3,000 proof of concept.
Need to Know
The losses that moved real money this week all came from mechanisms a team ran itself and had stopped watching, an impaired position still allowed to set a vault's price and a governance vote cheap enough for one buyer to win alone. Both were legitimate transactions the protocol authorised, which is why none of the usual defences fired. The largest headline figure belonged instead to a bug that cost nobody anything, because a researcher reached it months before an attacker could and the fix shipped the same day. If part of your stack still carries authority you have assumed was dormant, a retired market, a thin vote, a module nobody re-audits, the question worth carrying is when anyone last checked it was safe to trust. —AH
The Big One. Lazy Summer’s Donated NAV and a $6M Redemption
The news. On 6 July an attacker inflated the share price of two Lazy Summer Protocol USDC vaults on Ethereum and redeemed roughly $6.04M of depositor value in a single atomic transaction, about $5.64M from the lower-risk vault and $0.40M from the higher-risk one, according to the [Summer.fi post-mortem] and [CoinDesk]. They funded the whole thing with a roughly $65M flash loan and none of their own money, a position that existed only inside the single transaction and was repaid the moment it closed, so nothing they held was ever actually at risk.
What broke and how. Lazy Summer runs automated ERC-4626 vaults where a FleetCommander contract derives each vault’s share price from totalAssets(), the sum of what every active strategy adapter, called an Ark, reports it holds. An Ark credits any token transferred directly into it at that Ark’s own valuation, minting no new shares, so a donation quietly raises the vault’s reported assets. The attacker donated stale-valued Silo “Varlamore USDC Growth” tokens, which had carried a value never marked down since the November 2025 Stream Finance collapse, into an Ark whose deposit cap had been set to zero for offboarding but which still counted toward NAV. That lifted reported assets by around 9.5 percent and pushed the share price from about 1.0665 to about 1.1678 USDC, and when the attacker redeemed, the payout was assembled from the vault’s genuinely liquid Morpho, Spark, and Sky positions, which is to say from other depositors’ capital, per [CertiK’s reconstruction via The Block].
Zeroing the deposit cap stopped new money going in, but it never removed the Ark from the price calculation, so an impaired market kept helping set the price throughout the offboarding window. The position was accumulated across roughly three months before the single-transaction extraction, so the [on-chain evidence traces the setup back to a dead protocol’s mispriced tokens] rather than to any opportunistic flash loan alone.
Why it kept happening. This is a share-price and donation-manipulation pattern, and it is the second ERC-4626 accounting failure Burn Notice has run in as many issues after Vault4626. The recurring shape is a vault trusting an external number it should treat as hostile, a donated balance, a wrapped token’s self-reported value, an integrated market’s totalAssets(). Offboarding is where it bites hardest, because a market that is officially being removed but is still technically live is the softest target on the board, everyone has already written it off in their heads and stopped watching the number it feeds.
What to check now.
Do any paused, capped, or deprecated strategies still contribute to your vault’s
totalAssets()or NAV.Does any adapter credit donated or directly transferred tokens at face value without minting shares against them.
Are wrapped positions from halted or collapsed markets still reporting a stale on-chain value your accounting trusts.
Do you run independent accounting rather than reading
balanceOfortotalAssetsstraight from an integrated market.Does your pause or guardian role actually hold on every chain you deploy to. The Lazy Summer pause reverted on HyperEVM because the guardian did not hold the role there.
If your vault prices itself off a market you have already decided to retire, you are trusting a number nobody on your team is being paid to watch any more. Retire the price feed the day you retire the market, not six days later through governance.
— Adrian
Chain Reaction. Bonk’s $20M Governance Buyout
The news. On 6 July an attacker passed BonkDAO proposal BIP #76 and automatically moved about $20M, some 4.4 trillion BONK, out of the DAO treasury, having spent roughly $4.4M over the preceding days buying just over one percent of BONK’s supply on Bybit and Binance, [exactly the quorum threshold]. The vote itself ran on the DAO’s ordinary Realms governance on Solana, so every step of the buying and the balloting read as normal participation right up until the treasury emptied.
What broke and how. BonkDAO used ordinary token-weighted voting on a ballot almost nobody attended. Only seven of more than 18,000 eligible wallets voted, the attacker’s purchased stake cleared quorum by the narrowest margin, and the proposal passed with 99.9 percent in favour, one voter agreeing with itself. The payload was nothing more elaborate than a transfer of treasury BONK to a wallet the attacker controlled, which the DAO’s own machinery then executed automatically the moment the vote closed. Because every step was a valid transaction, the incident has [reopened the old argument over whether this is theft or the rules working as written], with SlowMist’s founder among those noting it was not a hack in the usual sense. BonkDAO has notified law enforcement and is working with exchanges, bridges, and the Solana Foundation, and Upbit, Bithumb, and Kraken paused BONK deposits.
Why it kept happening. Governance-buy attacks recur because they need capital rather than skill, and memecoin DAOs in particular sit on outsized treasuries behind plain token-weighted voting with no timelock, low quorum, and no veto. Burn Notice covered a one-vote DAO takeover back in issue four, and the pattern has not changed. Worth noting alongside this week’s Big One, Lazy Summer’s own guardians had cancelled a malicious governance proposal in April, and the whole difference between that outcome and this one was the existence of a veto path.
What to check now.
Is there a timelock between a proposal passing and the treasury executing it, long enough for anyone to react.
Is quorum high enough that a cheap temporary majority cannot clear it, and does any time or conviction weighting blunt last-minute accumulation.
Is there an emergency multisig or guardian veto over large treasury movements.
Can a single proposal move the entire treasury in one payload, or are transfers bounded.
Are you watching for sudden pre-vote token accumulation across exchanges the way BonkDAO could only do after the fact.
A treasury guarded only by token-weighted voting is worth exactly the cost of buying a majority, and here that cost was a fifth of the prize. If your DAO holds real money, price your own governance attack before someone else does, and ask whether your quorum is a wall or a turnstile.
— Adrian
Around the Forums
EMURGO exits Cardano’s Pentad. On 8 July, [EMURGO stepped down from the Pentad governance coalition] to concentrate on the SecondFi recovery, becoming the first of the group’s five founding members to leave. Pentad, formed earlier this year, pairs EMURGO with Input Output Global, the Cardano Foundation, Intersect, and the Midnight Foundation for treasury-backed infrastructure work, so a founding entity walking out under pressure is a real test of whether that structure was built to absorb one. SecondFi itself is now [winding down to a recovery-only operation rather than resuming service], and the two-week reimbursement target set in late June has already slipped.
Lazy Summer’s DAO now has to clean up. Governance faces its own vote in the wake of the exploit, including whether to exclude the attacker’s remaining vault shares from snapshots, how to return roughly $4M of mostly illiquid depositor capital, and a roughly six-day timeline just to unpause the untouched vaults. It is a live test of whether a narrowly scoped guardian module plus DAO governance can actually make depositors whole, or whether “we will cover it” quietly becomes “governance is evaluating options.”
What Else Happened
MEV backrun and extreme slippage. A single large trade routed into an illiquid Uniswap V3 AVAIL/WETH pool on 5 July cost the user around $2M, [flagged by Protos].
Deflationary reserve-burn manipulation. BFB on BNB Chain lost about $198K on 8 July when its price-support burn logic was gamed inside a single transaction, [per the on-chain record].
Clipboard clipper via a rogue extension. A fake “Google Notes” extension called [Silent Swap] installs into Chromium browsers by editing their protected preference files, then swaps any wallet address copied to the clipboard for one the attacker controls just before it is pasted. It resolves its command server by reading an on-chain smart contract, a technique known as [EtherHiding] that leaves the attacker infrastructure somewhere ordinary takedowns cannot reach.
Browser extension supply chain. Beyond that clipper, a Chrome ad blocker with [over 10 million installs and a Featured badge] was found carrying a dormant path to run arbitrary code on any page, flippable from the server with no update and no store review, and Microsoft pulled [119 Edge extensions in the StegoAd campaign] for hiding payloads inside image files to lift credentials and session cookies. A wallet in the same browser as either is one server-side switch from a swapped address or a hijacked session.
Supply chain compromise. North Korea-linked actors published [108 malicious packages across npm, Packagist, Go, and Chrome] using obfuscated loaders aimed at developer machines.
Researcher-targeted supply chain. Fake GitHub proof-of-concept repos are seeding the [ChocoPoC RAT to vulnerability researchers] who run the “PoC” to see if it works.
Attribution. Microsoft tied last month’s Mastra AI npm compromise to [Sapphire Sleet, also tracked as BlueNoroff], the same North Korean cluster behind several developer-targeting campaigns.
Patch Notes
This week’s operational urgency sits in the developer supply chain, not in anyone’s contracts. If your team pulls from npm, Go, or Packagist, or installs browser extensions, treat the North Korea-linked package flood in What Else Happened as the prompt to pin and audit your dependencies and to re-check what your CI actually installs on a fresh runner. And if anyone on your team reviews public proof-of-concept code, assume the ChocoPoC pattern is now standard, a “PoC” can be the payload, so run untrusted repos nowhere near a machine that touches keys.
The Lazy Summer and Bonk lessons are design reviews rather than patch deadlines, so they live in each story’s What to check now rather than here.
Long Reads
[Summer.fi’s Lazy Summer post-mortem], read alongside [BA Labs’ risk-curator retrospective]. Between them they give the clearest account of how a donation into an incompletely offboarded market moves a vault’s whole share price, and why the withdrawable-balance framing several early write-ups reached for was the wrong diagnosis.
[Hexens on the Aptos Move VM type-confusion bug]. Worth it for the risk-sizing dispute alone, Hexens’ $70B systemic figure against roughly $250M of direct Aptos exposure, Aptos Labs calling real-world exploitability [“extremely low”] against a near-90 percent simulation, and Polygon’s CTO confirming the proof of concept ran as described. Essential if you build on or bridge to any L1, because VM-level bugs sit below the audits most teams rely on.
[Gnosis Pay’s post-mortem on the Zodiac module exploit]. The incident was 1 June, but the newly published write-up is a tight lesson in [ERC-1271 signature-verification logic that read a return value without confirming the call had executed], and in how a delay module built to protect users became the path in.
Closing Tab
Taken together, the week has one shape. The money moved through systems doing exactly what they were built to do, while the one component that failed, the Aptos VM, cost nobody anything because it was caught and patched first. For a security newsletter, the uncomfortable part is that most of this week's damage was authorised.
Burn Notice. Operational intelligence for Web3, every week.
Adrian Hetman

