StrongBlock Governance Hacked: $72K in Tokens Stolen from Inactive Protocol
A recent attack on the StrongBlock protocol exploited its abandoned governance system, resulting in a loss of approximately $72,000 worth of STRONG and STRNGR tokens. The attacker accumulated enough voting power to pass a proposal that transferred administrative control of StrongBlock's Governor proxy contract. With this new authority, they replaced the existing implementation with a new, unverified one that contained a 'forward(address, bytes)' function executable exclusively from their own account.
This mechanism allowed them to carry out arbitrary transactions with the authority of the Governor contract. The attacker then transferred 32,695 STRONG and 383,447 STRNGR from a pool controlled by StrongBlock, totaling more than 416,000 tokens. Defimon Alerts valued the stolen assets at approximately $72,000 at the time of the incident.
The exploit highlights the security risks associated with inactive protocols that continue to hold significant assets or administrative permissions. Revoking upgrade permissions and maintaining active monitoring of pending proposals are necessary measures to prevent on-chain contracts from becoming attack vectors once the community and developers stop overseeing them.