StrongBlock loses $72K after attacker hijacks abandoned governance system
An attacker has drained about $72,000 worth of STRONG and STRNGR tokens after taking control of StrongBlocks abandoned on-chain governance system through a malicious proposal. According to blockchain security firm Defimon Alerts, the attacker acquired enough voting power in StrongBlock‘s governance to pass a proposal that ultimately transferred administrative control of the protocol’s Governor contract before the funds were removed. Instead of exploiting a flaw in StrongBlock‘s smart contracts, the attacker used the protocol’s own governance process to gain privileged access. After obtaining administrator rights, the attacker upgraded the Governor proxy to a new implementation that allowed arbitrary contract calls using the Governors authority. The incident adds to a series of recent crypto security events that have targeted governance systems, supporting infrastructure, and wallet software through different attack paths rather than relying solely on smart contract bugs. StrongBlock governance was used to seize protocol control Before the attack unfolded, the attacker accumulated a majority of the protocols STRONG governance token, which Defimon Alerts described as having become nearly worthless after the project was abandoned. Holding enough voting power, the attacker submitted a governance proposal instructing the Governor‘s Upgrader contract to execute setPendingAdmin(attacker), making the attacker’s address the pending administrator. Rather than bypassing governance, the proposal advanced through