StrongBlock Loses $72K After Governance Takeover Hands Attacker Admin Control
Cryptocurrency trading is speculative and your capital is at risk when you trade. We may earn affiliate commissions from some of the products on this page - at no extra cost to you.

Highlights:
- StrongBlock governance allowed an attacker to gain admin control before stealing about $72,000 in STRONG and STRNGR tokens.
- The attacker passed every required vote instead of exploiting a smart contract vulnerability.
- Recent crypto attacks increasingly target governance systems, infrastructure, and wallet software instead of contract bugs.
An attacker drained about $72,000 worth of STRONG and STRNGR tokens after gaining administrative control of StrongBlock’s abandoned governance system through a malicious proposal. Blockchain security firm Defimon Alerts said the proposal passed through the protocol’s normal voting process instead of exploiting a smart contract flaw.
🚨 Governance Takeover of @Strongblock_io – Loss $72K
Token: $STRONG
Network: EthereumThe attacker exploited StrongBlock's abandoned on-chain Governor. Holding a majority of the now near-worthless STRONG vote token, they pushed a proposal calling setPendingAdmin(attacker) on… pic.twitter.com/1FBfWYn9tC
— Defimon Alerts (@DefimonAlerts) August 6, 2026
Defimon Alerts said StrongBlock’s governance tokens had become nearly worthless after the project was abandoned. However, the attacker accumulated enough STRONG tokens at a low cost to secure majority voting power over the protocol.
The attacker submitted a malicious proposal after securing that voting power. The proposal instructed the protocol’s Upgrader contract to execute an action that named the attacker’s wallet as the pending administrator.
The proposal received enough votes, entered the governance queue, and completed every required approval stage. The protocol then executed the proposal through its standard voting process. The approved proposal transferred administrative control of the Governor proxy to the attacker’s wallet.
Defimon Alerts said the administrator change happened through StrongBlock’s governance permissions. The attacker never bypassed the protocol’s voting process. Instead, the attacker relied on majority voting power to gain privileged administrator access. Every critical action followed the protocol’s existing approval framework.
StrongBlock Governor Upgrade Enabled Arbitrary Contract Calls
After obtaining administrator rights, the attacker upgraded the protocol’s Governor proxy. The attacker replaced the existing implementation with a minimal unverified contract. The replacement contract introduced a function that allowed arbitrary contract calls.
Defimon Alerts said only the attacker’s externally owned account could use that function. The governance contract’s authority allowed the attacker to execute transactions across StrongBlock’s contracts after the upgrade.
The attacker first secured administrator rights through voting. Next, the attacker upgraded the governance contract. After that, the attacker transferred assets directly from the protocol’s pool. Defimon Alerts said the attacker removed 32,695 STRONG tokens and 383,447 STRNGR tokens, assets that carried a combined estimated value of about $72,000.
Defimon Alerts classified the incident as a governance takeover because governance permissions enabled every critical action. The governance proposal authorized the administrator change through the protocol’s existing approval process. The attacker also completed the contract upgrade by using the authority obtained after the proposal passed.
The attacker upgraded the governance contract before transferring the funds so the new implementation could authorize arbitrary transactions. The incident relied entirely on governance approvals instead of vulnerable smart contract code.
Recent Crypto Incidents Show Changing Attack Methods
The StrongBlock incident follows several recent attacks that targeted governance systems, supporting infrastructure, and wallet software instead of smart contract vulnerabilities.
Late last month, attackers stole 23.75 million USDC from decentralized perpetuals protocol Ostium. The attackers gained unauthorized access to the platform’s off-chain infrastructure. They submitted fraudulent BTC-USD price reports through trusted systems to create artificial trading profits. The manipulated reports settled against Ostium’s public OLP liquidity vault.
#PeckShieldAlert The @Ostium public OLP vault has been drained of ~$24M $USDC.
The exploiter swapped it for 12.08K $ETH and has deposited 10,540 $ETH to #TornadoCash so far.
The exploiter originally funded Wallet 0x321D…8bfD9 with 1 ETH from #ChangeNow and 1 ETH from… pic.twitter.com/8KDnKHAPIf
— PeckShieldAlert (@PeckShieldAlert) July 16, 2026
Like the StrongBlock incident, the attackers targeted trusted infrastructure instead of exploiting contract code. Blockchain security firm Blockaid also concluded that manipulated oracle reports enabled the theft.
Another recent incident involved Coldcard wallet firmware rather than protocol governance. A software update released in March 2021 introduced the issue. The firmware generated wallet seeds with a deterministic pseudo-random generator instead of the intended hardware random-number generator. The deterministic generator reduced the entropy used to create private keys.
Best Crypto Exchange
- Over 90 top cryptos to trade
- Regulated by top-tier entities
- User-friendly trading app
- 30+ million users
eToro is a multi-asset investment platform. The value of your investments may go up or down. Your capital is at risk. Don’t invest unless you’re prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong.







