Security

StrongBlock Loses $72K After Attacker Hijacks Abandoned Governance System

According to publisher crypto.news, an attacker drained approximately $72,000 in STRONG and STRNGR tokens after seizing control of StrongBlock's abandoned on-chain governance system. This incident, reported by blockchain security firm Defimon Alerts, is not officially confirmed by the project team.

Digital representation of blockchain governance security risks and abandoned protocol tokens
Image: crypto.news

Overview of the Reported Governance Attack

According to reporting by crypto.news, an unauthorized actor drained approximately $72,000 worth of digital assets from StrongBlock after acquiring control of the protocol's abandoned on-chain governance system. The publisher cited information from blockchain security firm Defimon Alerts, noting that the incident unfolded through a malicious governance proposal rather than a traditional software bug. The attacker managed to accumulate enough voting power within the protocol's governance mechanism to push through changes that ultimately transferred administrative privileges of the Governor contract before any assets were removed from the platform pools.

Publisher crypto.news explained that the attack mechanism relied heavily on the low liquidity and diminished activity surrounding the project's legacy governance tokens. Because development on StrongBlock had largely ceased, the voting power required to pass proposals had dropped significantly, creating an opportunity for an external actor to acquire a majority share of the tokens cheaply. Security analysts tracking the event emphasized that every critical action, including the modification of administrative roles, followed the normal operational path of the protocol's governance framework without encountering any underlying code errors.

Execution of the Malicious Governance Proposal

Publisher crypto.news noted that the attacker did not bypass any security layers or exploit smart contract logic errors. Instead, the malicious proposal advanced through every required stage of the protocol's governance process, receiving sufficient votes, entering the queue, and executing normally. The attacker utilized the protocol's Governor token, which Defimon Alerts described as having become nearly worthless following the abandonment of the project, to submit an instruction calling setPendingAdmin on the system.

Once the proposal completed its mandatory waiting periods and passed successfully, the attacker's wallet address was designated as the pending administrator. Following this official administrative transition, the attacker upgraded the Governor proxy to a new, minimal, and unverified contract containing a specialized forward function. According to security reports, this function was restricted exclusively to the attacker's externally owned account, establishing an arbitrary call mechanism that allowed the execution of transactions with the Governor's authority across all remaining protocol contracts.

Token Drain and Estimated Financial Impact

According to crypto.news, the upgraded contract implementation enabled the attacker to execute direct transfers of digital assets from the protocol's liquidity pools. Defimon Alerts reported that the unauthorized withdrawal included 32,695 STRONG tokens alongside 383,447 STRNGR tokens, pushing the total estimated value of the stolen assets to approximately $72,000. Security observers noted that because the transfer was authorized by the governance contract itself after the proxy upgrade, the event resembled an authorized administrative action from the perspective of the underlying smart contract logic.

The publisher highlighted that while the absolute financial loss of $72,000 is relatively modest compared to major decentralized finance exploits involving tens of millions of dollars, the method used underscores persistent architectural vulnerabilities in abandoned governance systems. Protocols that cease active development but leave their governance contracts active and connected to valuable token pools remain vulnerable to hostile takeovers if secondary market liquidity for governance tokens drops low enough for an attacker to acquire a controlling stake economically.

Context of Recent Crypto Security Incidents

Publisher crypto.news placed the StrongBlock event within a broader context of recent security incidents targeting various layers of the cryptocurrency ecosystem, including infrastructure, wallets, and governance mechanisms. For instance, decentralized perpetuals protocol Ostium recently suffered a significant exploit where attackers gained unauthorized access to off-chain infrastructure, submitting fraudulent price reports that generated artificial trading profits settled against public liquidity vaults, rather than exploiting smart contract bugs.

Similarly, recent disclosures regarding hardware and firmware security issues, such as the Coldcard wallet vulnerability analyzed by Galaxy Research, demonstrate that attackers continue to diversify their strategies. In the Coldcard case, historical firmware updates introduced deterministic pseudo-random number generators that compromised wallet entropy across thousands of addresses, prompting extensive ecosystem-wide code reviews supported by organizations like OpenSats and developer teams using artificial intelligence tools.

Ecosystem Wide Code Reviews and Mitigation

Following multiple high-profile security events across different sectors of the industry, independent developer groups and volunteer teams have intensified efforts to audit open-source codebases, cryptographic libraries, and infrastructure repositories. Bitcoin developer Calle recently reported that the volunteer Bitcoin Red Team completed manual and AI-assisted reviews across nearly 400 repositories, discovering thousands of potential issues, with hundreds classified as high or critical severity, highlighting ongoing systemic vulnerability concerns.

Security specialists emphasize that projects abandoning active maintenance should take proactive steps to decommission or revoke governance rights from their smart contract deployments. Leaving upgradeable proxies, Governor contracts, and token pools operational without oversight creates an attractive target for opportunistic actors who can leverage depressed governance token valuations to seize control of remaining protocol assets without triggering traditional intrusion detection systems.

Conclusion and Outlook on Unconfirmed Claims

In conclusion, the reported incident involving StrongBlock demonstrates how abandoned on-chain governance mechanisms can be manipulated by malicious actors to drain protocol funds through official proposal processes rather than software exploits. Publisher crypto.news reported that approximately $72,000 in STRONG and STRNGR tokens was stolen after an attacker gained administrative control of the Governor proxy. This material factual claim is reported by third-party media sources and remains not officially confirmed by the project team or first-party authorities.

The affected entity is StrongBlock, and the primary user group impacted includes token holders and liquidity providers interacting with legacy pools. As a result of this reported event, no score change is applied by Cexvia, and the evidence status remains classified as reported. Moving forward, participants should monitor network developments closely, acknowledge that these allegations are not officially confirmed, and exercise extreme caution when interacting with governance systems of abandoned or inactive decentralized protocols.

Cexvia conclusion

Conclusion on Reported StrongBlock Governance Incident

Publisher crypto.news reported that an attacker acquired sufficient voting power to execute a malicious proposal, gaining administrative control of StrongBlock's Governor contract. The attacker then upgraded the proxy and transferred about $72,000 in tokens. This account is not officially confirmed.

Risk meaning
This incident highlights the lingering risks associated with abandoned blockchain governance systems, where low token liquidity can allow bad actors to accumulate majority voting power and hijack administrative contracts without encountering smart contract bugs.
User action
Holders of legacy or abandoned protocol tokens should monitor governance forums and liquidity pools closely, exercising caution regarding proposals that alter administrator permissions or proxy implementations on inactive networks.
StrongBlock