EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

YAM Finance governance attack puts $337,000 in assets at risk

2026-09-02 20:31:46
Bookmark

YAM Finance encounters governance takeover attempt

YAM Finance faces a governance takeover attempt. By accumulating enough YAM delegated voting rights, the attackers submitted a proposal in an attempt to seize control of the agreement's time-lock and put approximately $337,000 in funds at risk.

Summary of the incident

An attacker self-commissioned approximately 504,000 YAM tokens, accounting for 3.3% of the supply, and gained enough voting rights to reach a governing quorum. Proposition 45 aims to make attackers a pending administrator of YAM timelocks, potentially giving them control of protocol contracts and the DAO treasury. Security monitoring service Defimon estimates that approximately $337,000 is at risk and urges YAM holders to vote against the proposal ahead of block 25,897,343.

YAM Finance takeover proposal targets time-lock control

According to Defimon monitoring, the attacker submitted YamGovernor Alpha Proposal No. 45, which was described as null ("0x"). The proposal does not include multiple governance actions, but only calls the setPendingAdmin function of the YAM timelock contract to designate the address controlled by the attacker as the new pending administrator. Defimon pointed out that if the proposal receives sufficient support and is implemented, the attacker will first obtain the pending administrator identity of the timelock, and then can be used by calling acceptAdminComplete the transfer of management rights. Security companies said seizing the time lock would allow attackers to control administrative functions that manage YAM protocol contracts and the DAO treasury. Defimon estimates that if the proposal is successful, approximately $337,000 in current funding will be at risk.

Security companies are calling on remaining YAM holders to vote against the proposal before block 25,897,343. When the alert was issued, Defimon estimated that the holder had approximately 34 hours to respond.

YAM Finance had previously been largely dormant, a situation Defimon cited when warning holders. Low participation exposes the governance system to risk because a relatively concentrated small number of delegated tokens is sufficient to meet voting requirements.

Governance control has become a recurring attack path

This YAM takeover attempt is one of several recent governance attacks targeting inactive or under-monitored decentralized organizations. In early August, it was reported that an attacker had taken control of StrongBlock's legacy governance system through malicious proposals and subsequently stole approximately $72,000 in STRONG and STRNGR tokens. In this incident, the attacker used governance privileges to gain management control of the protocol's Governor contract, then upgraded the contract and extracted the corresponding assets. The entire process relied on governance authorization rather than exploiting the underlying smart contract code vulnerability.

Another governance attack occurred in August and targeted Term Labs. An attacker spent approximately $951 to gain control of the protocol governance token and then stole approximately $8.5 million from the strategy vault through a proposal. Term Labs confirmed the attack on August 23, and security companies PeckShield and CertiK traced the stolen funds to addresses controlled by the attackers. Defimon was the monitoring service that originally flagged abnormal transactions in this event. After obtaining enough governance tokens, the attacker submitted a proposal to transfer assets from four USDC policy vaults and one Ethereum meta vault to its wallet. Because the attacker's address controlled the majority of the voting rights of the relevant governance token, the proposal was passed and the contract processed the transfer through the existing governance system. The stolen assets included 2,843 ETH (valued at approximately $6.87 million at the time) and 1.68 million USDC, which were subsequently exchanged for nearly 1.6 million DAIs.

Recent DAO attacks rely heavily on voting power

In July, BonkDAO encountered a larger governance incident. The attackers amassed enough BONK voting power to approve a proposal to divert approximately $20 million from the organization's treasury. The attackers spent approximately $4.4 million to purchase BONK through exchange wallets and gathered enough voting rights to reach the DAO quorum. In the end, only seven wallets participated in the vote, and the attacker had enough voting power to push the proposal through. After the proposal was approved, the governance system executed transfers from the treasury to addresses controlled by the attacker. The incident did not involve a smart contract vulnerability, but relied on the attacker to obtain enough token voting rights to control the outcome. BonkDAO then contacted law enforcement and worked with exchanges and other parties to try to trace and recover the transferred tokens. At least one exchange suspended BONK transfers after the incident.

The attack prompted governance reforms in other projects in the industry. In late July, ENS DAO activated an eight-member security committee with the power to cancel malicious governance proposals before implementation. ENS designed the committee to have a 5/8 multi-vote structure that requires the consent of five members to veto the proposal. Its authority is limited to canceling queued transactions and does not allow members to transfer treasury assets or rewrite proposals.

In August, Binance disclosed another governance attempt when its security team discovered a malicious proposal less than 48 hours before its implementation, putting approximately $1.2 million in assets at risk. Binance said it had contacted the affected DAOs and coordinated with other centralized exchanges to take precautionary deposit closures. The anonymous project was ultimately rejected before the proposal was implemented, and Binance said there were no financial losses. Binance did not disclose the name of the DAO, nor did it announce the proposal number or provide relevant on-chain transaction records.

Regarding YAM Finance, Defimon's warning remains focused on Proposition 45 and the upcoming vote. Security companies have asked YAM holders to vote against the proposal before block 25,897,343, which was set as the deadline for blocking changes to timelock administrators through governance votes.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP