StrongBlock governance contract exploited via abandoned Governor mechanism, allowing attacker to seize admin control and drain $72K in tokens.
Security & Exploits ·
StrongBlock's governance system was compromised when an attacker exploited an abandoned on-chain Governor contract to seize administrative control. By holding a majority of the depreciated STRONG governance token, the attacker submitted a proposal to designate themselves as the pending administrator, voted it through, and executed the transaction to gain control of the Governor proxy. The attacker then replaced the proxy implementation with a custom contract containing an arbitrary-call function restricted to their address, creating a backdoor to execute commands with the Governor's authority over StrongBlock's contracts.
Using this backdoor, the attacker drained approximately $72,000 worth of tokens from the affected pool, including 32,695 STRONG and 383,447 STRNGR tokens. The exploit was executed across multiple transactions, with the final sweep completing the token withdrawal.
The incident highlights risks posed by abandoned or insufficiently monitored governance mechanisms. It remains unclear whether protocol developers have implemented additional safeguards or plan to recover the funds, and the broader implications for other governance systems using similar proxy upgrade patterns have not been detailed.