According to TRM Labs, the Token of Power protocol was exploited in a governance takeover that drained approximately $1.58 million in WETH. The attacker exploited the absence of a timelock in the protocol's Aragon DAO setup, allowing a malicious governance action to be proposed, voted on, and executed within a single blockchain block.
The attacker funded the operation using ETH from Tornado Cash, acquired majority voting power in TOP tokens, minted 10 billion new TOP tokens, and exchanged them for WETH through a Balancer pool before routing the stolen funds back through Tornado Cash. TRM Labs clarified that Tornado Cash itself was not hacked, but was used as a funding and routing mechanism in the exploit.