An anonymous attacker drained approximately $1.58 million from the Token of Power ($TOP) liquidity pool on June 9 by exploiting a governance vulnerability in the project’s Aragon DAO setup.The incident was first flagged by Cyvers Alerts and has drawn widespread attention to the risks faced by low-cap DeFi projects that rely on legacy governance frameworks and extremely limited token supplies.According to multiple on-chain security firms, the attacker first acquired a controlling stake in the project by purchasing roughly 8,192 TOP tokens – more than 50% of the total supply of just 16,384 tokens – from the TOP/WETH Balancer V1 pool. The acquisition cost around 663 WETH and was funded through Tornado Cash.
🚨ALERT🚨Our system has detected a suspicious transaction involving Token of Power ($TOP), resulting in losses of approximately $1.58 million.
An address funded through @TornadoCash executed a malicious transaction that drained funds from the TOP/WETH Balancer V1 Pool.
The… pic.twitter.com/ewpQTmDA8s
— 🚨 Cyvers Alerts 🚨 (@CyversAlerts) June 9, 2026
Token of Power Contract Address: `0x0EBD…D3eDb6` Attacker’s Primary Wallet: `0xff8e…b39Fa2`
With majority voting power secured, the attacker executed a malicious governance proposal in a single transaction. The proposal passed immediately and triggered the TokenManager to mint 10 billion new TOP tokens directly to the attacker’s contract.These newly minted tokens were then swapped into the Balancer V1 pool, draining 944.2 WETH (valued at roughly $1.58 million at the time). The stolen funds were subsequently routed back through Tornado Cash. The attacker is estimated to have netted around 281 WETH after costs.The Balancer protocol itself was not compromised. The V1 pool served only as an exit liquidity source for the massively inflated token supply. Similar cross-chain exploits also continue to plague the ecosystem, including the recent $1.88 million hack on Transit Finance.
Following the exploit, the Token of Power project has been left in a severely compromised state. The total supply has ballooned to 10 billion TOP, and liquidity in the main pool has been almost completely drained.

- One single wallet now holds 100% of the total supply.
- Top 5 holders control 100% of all tokens.
- The Gini distribution score stands at 0.9954, indicating near-total centralization.
- Max Total Supply: 10,000,016,384 TOP
- Number of Holders: 218
- Total Transfers: 39 (a massive +3,900% increase in 24 hours due to the attack)
One wallet now controls virtually the entire supply, resulting in extreme concentration. Liquidity in the main pool has been almost completely drained, trading activity has collapsed, and the token’s market value has plummeted close to zero. Liquidity providers have suffered heavy losses due to both the WETH drain and severe dilution.As of June 10, 2026, the project team operating under “The Mask of Power” DAO (maskofpower.art) has not issued any official statement on recovery efforts, compensation for affected users, or future plans for the token.
PeckShield and other security researchers noted that the exploit succeeded due to several critical oversights: the project’s microscopic original token supply, the absence of a timelock on governance actions, lack of minting caps, and insufficient voting safeguards in the Aragon DAO configuration based on MiniMeToken mechanics.
This exploit adds to a worrying wave of DeFi incidents in 2026. The crypto industry already faced a record $625 million in DeFi exploits during April 2026 alone. Experts advise DeFi builders to implement stricter tokenomics, timelocks on sensitive functions, and regular governance audits. Liquidity providers are urged to carefully review project parameters before committing funds to small-cap pools.The $TOP case serves as a reminder that while decentralized finance continues to innovate, economic design and governance security remain critical foundations for long-term sustainability.

















