On October 6, 2026, security firm Blockaid issued a real-time alert flagging an exploit targeting the Onyx DAO treasury contract on Ethereum. An attacker used a passed governance proposal to drain approximately $2.91 million, equivalent to 620 million XCN, from the DAO treasury into wallets attributed to the attacker. The attacker bypassed all three governance checks on Onyx: the proposal threshold, quorum requirement, and the two-day timelock. This incident exposes a structural risk highlighted by research: concentrated voting power can turn governance safeguards into mere formalities. This is not Onyx’s first security incident, as the protocol had already suffered vulnerabilities in 2023 and 2024, including losses exceeding $3.8 million.
Source: Read the original article

