An attacker emptied StrongBlock's treasury on August 6, making off with $72,000 worth of STRONG and STRNGR tokens by hijacking the protocol's abandoned governance system. No smart contract exploit here. The attacker simply accumulated voting power in a token the project had left to rot, passed a proposal to grab admin rights, and drained the vault.

The path in: StrongBlock's STRONG governance token had become nearly worthless after the project abandoned it. That made it cheap for the attacker to accumulate a majority stake. With enough voting power, they submitted a proposal instructing the Governor's Upgrader contract to execute setPendingAdmin, making the attacker's address the pending administrator. The proposal sailed through every required stage without resistance.

Once admin access landed in their hands, the attacker upgraded the Governor proxy to a new implementation. This gave them the ability to make arbitrary contract calls using the Governor's own authority. They pulled 32,695 STRONG and 383,447 STRNGR tokens and vanished. Defimon Alerts caught and publicized the whole thing on the morning of August 6.

The incident slots into a wider pattern of governance attacks rippling through crypto this year. Rather than hunting for bugs in smart contract code, attackers are exploiting the governance systems themselves, targeting infrastructure, and hitting wallet software through different angles entirely.

This is informational coverage, not financial advice. Do your own research before making any investment decisions.