Categories: Crypto/NFTs

Token Of Power Governance Exploit Drains $1.58 Million In WETH, TRM Says


Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure

TL;DR

  • TRM Labs says Token of Power was exploited for roughly $1.58 million in WETH.
  • The attacker used a governance setup with no timelock to propose, vote, and execute in one block.
  • Tornado Cash was used for funding and routing, but Tornado Cash itself was not hacked.

TRM Details A Governance Takeover

Blockchain intelligence firm TRM Labs has detailed a governance takeover exploit against the Token of Power protocol that drained approximately $1.58 million in WETH.

According to TRM’s analysis, the attacker exploited a weakness in the protocol’s Aragon DAO setup: the absence of a timelock. That allowed the attacker to propose, vote on, and execute a malicious governance action in a single block.

The attacker reportedly funded the operation with 662 ETH withdrawn from Tornado Cash, purchased enough TOP tokens to gain majority voting power, minted 10 billion new TOP, and swapped those tokens for WETH through a Balancer pool before routing funds back through Tornado Cash.

Why Timelocks Matter

The exploit is a clear example of how governance design can become a direct security risk. Token voting can look decentralized on paper, but if a malicious actor can quickly buy voting power and execute changes without delay, the governance system can become an attack surface.

Timelocks are meant to give users, developers, and security teams time to react before a proposal becomes executable. Without that delay, a hostile vote can become a drain before anyone can stop it.

Why This Matters

For DeFi users, the story is a reminder that smart-contract risk is not limited to code bugs. Governance parameters, treasury controls, and voting thresholds can be just as important.

It also highlights how mixers and liquidity pools can be used around an exploit without being the exploited protocol themselves.

What To Watch Next

The next thing to watch is whether stolen funds move again and whether the protocol, Aragon, or affected liquidity providers publish further remediation details.

The article must not say Tornado Cash itself was hacked.

Market Context

For Bitcoinist, the story sits inside a wider shift in crypto where infrastructure, security, governance, and token utility are becoming just as important as short-term price action. Traders still care about momentum, but they also need to understand the systems, risks, and product changes behind the headlines.

The useful angle is not to overstate the development, but to explain why it belongs in the daily market conversation. Strong crypto stories increasingly come from protocol updates, official notices, security reports, court records, and on-chain data rather than recycled commentary alone.

The editorial takeaway should stay grounded: the source confirms a meaningful crypto development, but the implications depend on adoption, follow-up disclosures, or further on-chain evidence. That balance keeps the piece useful without leaning on hype or unsupported claims.

From an editorial standpoint, this makes the story worth covering as part of the day’s broader crypto operating environment rather than as a standalone hype cycle. The strongest version of the piece should stay close to the verified source, explain the practical risk or opportunity, and leave room for follow-up once more official data, filings, or project statements are available.

This report is based on information from TRM Labs’ on-chain security report.

Editorial Process for bitcoinist is centered on delivering thoroughly researched, accurate, and unbiased content. We uphold strict sourcing standards, and each page undergoes diligent review by our team of top technology experts and seasoned editors. This process ensures the integrity, relevance, and value of our content for our readers.



Source link

admin2

Share
Published by
admin2

Recent Posts

JPMorgan Converts $950M to Active NY, CA Muni ETFs

This week J.P. Morgan Asset Management launched two actively managed municipal bond ETFs focused on…

2 hours ago

Vozinha’s mum celebrates hero keeper son from afar | World Cup 2026 News

NewsFeedThe mother of Cape Verde’s celebrated goalkeeper Vozinha says she watched his heroics on the…

2 hours ago

Binance Faces Reported MiCA Setback In Greece Ahead Of July Deadline

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure TL;DR …

2 hours ago

Kristi Noem hired in strategic advisory role for B.C. mining company

Former U.S. secretary of homeland security and current special envoy to the Shield of the…

3 hours ago

Dad describes hearing his daughter was injured at Cultus Lake Waterpark – BC

When Darin Nielsen answered a call from his wife on Monday afternoon telling him that…

6 hours ago

AI’s Exponential Power Demands Could Make This ETF a Winner

Participate in artificial intelligence (AI) investing long enough and you’re apt to hear plenty about…

7 hours ago