A governance vote is supposed to be decentralization at its most civic. On Onyx, it apparently doubled as a withdrawal slip.
On October 6, 2026, security firm Blockaid issued a real-time alert flagging an exploit tied to the Onyx DAO treasury contract on Ethereum. The alert centered on a transfer of 620 million XCN, valued at approximately $2.91 million, out of the treasury and into wallets Blockaid linked to the attacker.
The exploit ran through Onyx’s own governance machinery. The attacker reportedly got a governance proposal passed, and that proposal authorized the treasury transfer.
Onyx’s governance framework includes three main checks: a proposal threshold, a quorum requirement, and a two-day timelock. The attacker is described as having worked through all three.
The timelock is a cooling-off period. Once a proposal passes, it sits for a set window before it can execute, giving the community time to spot anything suspicious and react. In this case, the transaction executed after the standard two-day timelock had elapsed.
Blockaid’s alert included the specifics of the exploit transaction along with the relevant addresses. The compromised treasury sits at 0x28CA9CaAE31602D0312Ebf6466c9dD57FCA5da93.
The receiving wallets attributed to the exploiter are 0xcBbA8B308c29c22158f5602793FE1eA361AfB9e0 and 0xb12aD23d4394A41C859d48c73CEd40Be6BF758c4. The XCN token’s ERC-20 contract on Ethereum is 0xA2cd3D43c775978A96BdBf12d733D5A1ED94fb18.
Onyx is not a single-chain project. It runs its own Layer 1 blockchain, the Goliath mainnet, which launched in March 2026, while also keeping a presence on Ethereum.
XCN does a lot of work in that ecosystem. It pays gas fees, it can be staked, with liquid staking offering an annual percentage rate of approximately 30%, and it is the governance token that decides proposals like the one at the center of this incident.
This is also not the first time Onyx has had to deal with a security problem. The ecosystem ran into protocol vulnerabilities in both 2023 and 2024, and one of those incidents involved losses exceeding $3.8 million.
That earlier episode prompted community recovery measures.
The research findings point to community actions, including exploit reporting and compensation plans for affected parties, as crucial to rebuilding trust. The research also flags concentrated voting power as a structural risk. When enough votes can be gathered in a few hands, the threshold and quorum stop functioning as checks and start functioning as checkboxes.
The findings suggest protocols may respond by tightening governance mechanics. Possible measures include multi-signature requirements on treasury movements or enhanced voting protocols that make it harder to push through a single hostile proposal.
Disclosure: This article was edited by Estefano Gomez. For more information on how we create and review content, see our Editorial Policy.

2 hours ago
7








English (US) ·