Token of Power Governance Exploit Drains $1.58 Million in WETH, TRM Labs Reports

POWER-6.42%
ETH2.42%
BAL0.09%

According to TRM Labs, the Token of Power protocol was exploited in a governance takeover that drained approximately $1.58 million in WETH. The attacker exploited the absence of a timelock in the protocol's Aragon DAO setup, allowing a malicious governance action to be proposed, voted on, and executed within a single blockchain block.

The attacker funded the operation using ETH from Tornado Cash, acquired majority voting power in TOP tokens, minted 10 billion new TOP tokens, and exchanged them for WETH through a Balancer pool before routing the stolen funds back through Tornado Cash. TRM Labs clarified that Tornado Cash itself was not hacked, but was used as a funding and routing mechanism in the exploit.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments