
An attacker appears to have used majority control of TOP’s Aragon DAO to mint new tokens and pull about 944 WETH from the TOP/WETH pool in a same-transaction governance exploit.
Token of Power suffered a roughly $1.58 million exploit after an attacker used a governance misconfiguration in its Aragon DAO to seize effective control, mint new TOP tokens and drain about 944.2 WETH from the TOP/WETH Balancer V1 liquidity pool on Ethereum. Security firms said the attacker accumulated 8,192.000001 TOP, just over half of the token’s 16,384 total supply, enough to unilaterally clear the 50% voting threshold. Because the DAO’s Aragon Voting app had no timelock, the attacker was able to create, pass and execute a proposal in a single transaction, then use the newly minted tokens to extract WETH from the pool. Balancer itself was not described as vulnerable; the pool was used to convert inflated TOP holdings into WETH. The attacker’s wallet was funded through Tornado Cash, and neither the Token of Power team nor Aragon had issued a statement as of publication.