StrongBlock Governance System Hijacked for $72K Heist
A recent attack on StrongBlock's abandoned governance system resulted in the loss of $72,000 worth of STRONG and STRNGR tokens. The attacker exploited the protocol's own governance process to gain administrative control, using a malicious proposal that passed through every required stage.
The attacker accumulated a majority of the protocol's STRONG governance token, which had become nearly worthless after the project was abandoned. They then submitted a governance proposal instructing the Governor's Upgrader contract to execute setPendingAdmin(attacker), making the attacker's address the pending administrator.
Once in control, the attacker upgraded the Governor proxy to an implementation containing a restricted forward(address, bytes) function. This gave their wallet exclusive authority to execute arbitrary calls through the Governor contract. The stolen assets were then transferred using permissions that the protocol itself granted after the governance proposal completed.