Binance Blog published a new article, revealing how its security team detected and helped prevent a potential governance attack that could have put approximately $1.2 million in a project’s decentralized autonomous organization treasury tokens at risk. The incident involved a malicious governance proposal targeting the project’s on-chain decision-making process, where token holders can submit and vote on proposals that may affect treasury funds, protocol parameters, upgrades, or other important actions. Binance said its monitoring systems identified the threat independently and flagged it before the proposal could be executed. With less than 48 hours to respond, the security team contacted the project directly and coordinated with other centralized exchanges that listed the affected token to close deposits as a precaution. This step was intended to reduce the risk that any potentially compromised funds could move through exchanges if the proposal succeeded. The project ultimately voted against the malicious proposal, and the attack was stopped before execution with no funds lost.

The article explains that governance attacks target weaknesses in blockchain protocols’ decision-making systems rather than smart contract code. Binance said such attacks can become possible when the barrier to submitting or passing a proposal is too low, or when governance rules are not designed to prevent abuse. In this case, the malicious proposal attempted to exploit a vulnerability in the project’s on-chain governance mechanism. Binance Chief Security Officer Jimmy Su said the case shows what security by design looks like beyond Binance’s own platform, adding that the team and its systems identified a threat that no external security provider had flagged. He also said the incident highlights the importance of protecting people, not just platforms, because the biggest risks in crypto increasingly target people, access, and behaviors rather than code vulnerabilities. Su added that governance attacks are an emerging attack vector as the industry matures and that crypto security is increasingly converging with enterprise security, requiring security practices to evolve accordingly.

Binance said the intervention reflects its broader commitment to prevention, real-time detection, and coordinated response across the crypto ecosystem. The company stated that in 2025, its systems helped prevent more than $3.9 billion in potential scam losses and blocked $6.69 billion in fraud and scams affecting 5.4 million users. Binance also said it helped recover over $12.8 million for users and supported more than 48,000 recovery cases through internal efforts and industry coordination. The article concludes that protecting users requires cooperation with projects, exchanges, and partners across the ecosystem to reduce risk before it reaches users, while strengthening trust, resilience, and confidence in the crypto sector as a whole.