BarnBridge Becomes Second Dormant-DAO Takeover in a Month, BlockSec Warns

6 August 2026 - 10:00 UTC
BarnBridge Becomes Second Dormant-DAO Takeover in a Month, BlockSec Warns

On 15 Jul, an attacker took over the abandoned BarnBridge protocol's governance, upgraded its SmartYield contracts to a version of their own making, and drained roughly $776,000 in USDC. No code was broken. An attacker simply took control of a protocol nobody was watching any more, the second such takeover in under a month.

How it happened

The mechanism is easier to picture than it sounds. A DAO like BarnBridge runs on majority vote: hold enough of its governance token, and you can vote through changes to how the protocol's funds are handled. For a while, plenty of people held that token and voted. Over time, most drifted away and stopped bothering, the protocol wound down, but the voting system stayed switched on because nobody had turned it off. An attacker noticed nobody was voting any more, quietly bought up enough of the now-cheap, largely ignored governance token, and once they held enough, passed a proposal that handed themselves control. Nothing was hacked or broken into in the traditional sense; they simply won a vote nobody else showed up to.

There was a second layer of neglect sitting underneath that. Fifty user accounts had, back when the protocol was active, granted it standing approval to move their USDC, the kind of routine permission nearly every DeFi user grants and then forgets to revoke. Once the attacker controlled the protocol's rules, they used that control to upgrade BarnBridge's SmartYield contracts to a version of their own, which called a privileged function to sweep up exactly those forgotten approvals. The stolen funds were swapped for roughly 415 ETH and moved on.

Revoke.cash, a token-approval security tool with no connection to BlockSec, later described the underlying cause in blunt terms: an attacker "bought up governance tokens of the abandoned protocol and passed a malicious proposal that gave them control." Two independent security outlets landing on the same word, "abandoned," is itself part of the story.

There had also been a warning. Blockaid had named the specific mechanism the day before, and it happened anyway, publicly flagging that two old, dormant BarnBridge governance proposals carried token-authorization risk if maliciously executed.

Sandmark contacted BarnBridge for comment on 3 Aug, and had not received a response as of publication.

Not an isolated case, BlockSec says

LWu, BlockSec's CTO, told Sandmark the incident fits a pattern the firm expects to keep recurring. "BarnBridge is not an isolated case," he sajd, adding that dormant contracts "can continue to present security risks long after a protocol has ceased active operations."

BarnBridge's own SmartYield code, its governance token, and its approval permissions didn't stop existing when the team stopped actively running the project. They just stopped being watched.

A repeat of BonkDAO, at a different scale

BarnBridge is the second confirmed case of this exact mechanism in three weeks. On 9 Jul, an attacker spent roughly $4.4mn quietly accumulating just over 1% of BONK's token supply, the precise threshold needed to hit BonkDAO's voting quorum, buying through Binance, Bybit and DeFi lending markets over several days without triggering suspicion. Once the vote passed, the attacker drained $20mn from the treasury, a payout roughly 4.5 times the cost of buying the votes.

BarnBridge's numbers are far smaller, a few hundred thousand dollars against tens of millions, but the mechanics are identical: find a protocol where token holders have stopped paying attention, acquire enough governance power to look legitimate, then use the protocol's own rules against it. Industry research on DAO governance has flagged this exact failure mode for years. As a16z crypto warned in a 2024 analysis of DAO governance attacks, low voter turnout can let a hostile position accumulate "without raising suspicion." BarnBridge and BonkDAO are two live, recent instances of a risk that was already flagged in theory.

What it means for protocols winding down

Neither BarnBridge nor BonkDAO was hacked in the conventional sense. Both were governed exactly as designed, by whoever held enough tokens to win a vote. The risk isn't a bug sitting in the code; it's a live, funded, governable system that nobody is actively defending any more.

That has a specific implication for any protocol that scales back development, team involvement, or treasury oversight without a plan for winding down its governance and outstanding approvals along with it. As institutional and mid-size projects continue to consolidate or quietly sunset, BlockSec's warning suggests BarnBridge won't be the last case, only the latest.

Add as a preferred source on Google