An attacker drained approximately $72,000 worth of STRONG and STRNGR tokens after taking over StrongBlock’s abandoned on-chain governance system through a malicious proposal, according to blockchain security firm Defimon Alerts. The incident did not exploit a smart contract vulnerability; instead, the attacker used the protocol’s own governance process to gain privileged access.
The attacker accumulated a majority of the now near-worthless STRONG governance token, then submitted and passed a proposal that transferred administrative control of the Governor contract. Once the proposal was executed, the attacker upgraded the Governor proxy to a minimal implementation containing a restricted forward(address, bytes) function, which allowed arbitrary contract calls with the Governor’s authority. This enabled the theft of 32,695 STRONG and 383,447 STRNGR tokens directly from the protocol’s pool.
Defimon Alerts characterized the event as a governance takeover because every critical step—admin change, contract upgrade, and fund transfer—occurred through legitimate governance permissions, not a code exploit. The attack underscores the risks posed by abandoned projects with live governance contracts, where voting power can still be weaponized long after development ceases.