2 Вересня, 2026
YAM Finance governance attack puts $337K in assets at risk thumbnail
Бізнес

YAM Finance governance attack puts $337K in assets at risk

YAM Finance has faced a governance takeover attempt after an attacker accumulated enough delegated YAM voting power to submit a proposal that could hand over control of the protocol’s Timelock and put roughly $337,000 at risk. Summary An attacker self delegated approximately 504,000 YAM, representing 3.3% of the supply and enough voting power to clear”, — write on: www.crypto.news

YAM Finance has faced a governance takeover attempt after an attacker accumulated enough delegated YAM voting power to submit a proposal that could hand over control of the protocol’s Timelock and put roughly $337,000 at risk.

Summary

  • An attacker self delegated approximately 504,000 YAM, representing 3.3% of the supply and enough voting power to clear the governance quorum.
  • Proposal #45 seeks to make the attacker pending administrator of the YAM Timelock, potentially giving the address control over protocol contracts and the DAO treasury.
  • Defimon estimated roughly $337,000 is at risk and urged YAM holders to vote against the proposal before block 25,897,343.

Defimon, the on-chain monitoring service operated by security firm Decurity, said it detected the attempt after an address self-delegated approximately 504,000 YAM tokens, representing around 3.3% of the token’s supply and enough voting power to move just above the governance quorum.

Community alert: Defimon detected a governance takeover attempt of @YamFinance

Attacker self-delegated ~504K $YAM (~3.3% of supply, just over the quorum) and submitted YamGovernorAlpha proposal #45 with an empty description (“0x”). The single action calls… pic.twitter.com/r5SrltlvDa

— Defimon Alerts (@DefimonAlerts) September 2, 2026

YAM Finance takeover proposal targets Timelock control

The attacker submitted YamGovernorAlpha proposal #45 with an empty “0x” description, according to Defimon. Instead of containing several governance actions, the proposal makes a single call to the YAM Timelock contract’s setPendingAdmin function and designates an address controlled by the attacker as the new pending administrator.

If proposal #45 receives enough support and is executed, Defimon said the attacker would first obtain pending administrator status over the Timelock. The address could then call acceptAdmin to complete the transfer of administrative control.

Taking over the Timelock would give the attacker control over the administrative functions governing YAM protocol contracts and its DAO treasury, according to the security firm. Defimon estimated that approximately $337,000 is currently exposed if the proposal succeeds.

The security firm urged remaining YAM holders to vote against the proposal before block 25,897,343. At the time of its alert, Defimon estimated that holders had around 34 hours to respond.

YAM Finance has been largely dormant, a condition Defimon cited while warning holders about the proposal. Low participation can leave governance systems exposed when a relatively small concentration of delegated tokens is enough to meet voting requirements.

The attempt has not resulted in the reported loss of the treasury funds at the time of Defimon’s alert. The proposal still needs to pass the governance process and execute before the attacker could proceed with the Timelock administrator change described by the security firm.

Governance control has become a recurring attack route

The attempted YAM takeover follows several governance attacks involving inactive or lightly monitored decentralized organizations in recent months.

Earlier in August, crypto.news previously reported that an attacker took control of StrongBlock’s abandoned governance system through a malicious proposal before draining approximately $72,000 worth of STRONG and STRNGR tokens.

In the StrongBlock incident, the attacker used governance to obtain administrative control over the protocol’s Governor contract. The address subsequently upgraded the contract and withdrew 32,695 STRONG and 383,447 STRNGR, with the incident relying on governance authority instead of exploiting a vulnerability in the underlying smart contract code.

Another governance attack targeted Term Labs in August. An attacker spent approximately $951 to acquire a controlling position in the protocol’s governance token before proposals were used to drain roughly $8.5 million from strategy vaults.

Term Labs confirmed the exploit on Aug. 23, while PeckShield and CertiK traced the stolen funds to an attacker-controlled address. Defimon was the monitoring service that initially flagged unusual transactions associated with that incident.

After obtaining enough governance tokens, the Term Labs attacker submitted proposals directing assets from four USDC strategy vaults and an Ethereum Meta Vault to the attacker’s wallet. The proposals passed because the address controlled a majority of the relevant governance tokens, allowing the contracts to process the transfers through the protocol’s existing governance system.

The stolen assets included 2,843 ETH, valued at approximately $6.87 million at the time, and 1.68 million USDC. The USDC was later exchanged for close to 1.6 million DAI.

Recent DAO attacks have relied on voting power

A much larger governance incident hit BonkDAO in July when an attacker accumulated enough BONK voting power to approve a proposal that transferred around $20 million from the organization’s treasury.

The attacker spent approximately $4.4 million acquiring BONK through exchange wallets and assembled enough voting power to clear the DAO’s quorum. Only seven wallets participated in the final vote, while the attacker’s stake was enough to push the proposal through.

Once approved, the governance system executed the transfer from the treasury to an attacker-controlled address. The incident involved no reported smart contract exploit, with the BonkDAO governance attack instead relying on the attacker obtaining enough token-based voting power to control the outcome.

BonkDAO later contacted law enforcement and worked with exchanges and other parties while attempting to trace and recover the transferred tokens. At least one exchange suspended BONK transfers following the incident.

The attack prompted governance changes elsewhere in the sector. Later in July, ENS DAO activated an eight-member Security Council with authority to cancel malicious governance proposals before their execution.

ENS structured the council as a five-of-eight multisig, requiring five members to approve a veto. Its authority is limited to canceling queued transactions and does not allow members to move treasury assets or rewrite proposals.

A separate governance attempt disclosed by Binance in August placed approximately $1.2 million in assets at risk after the exchange’s security team detected a malicious proposal with less than 48 hours remaining before execution. Binance said it contacted the affected DAO and coordinated precautionary deposit closures with other centralized exchanges.

The unnamed project eventually rejected the proposal before execution, and Binance said no funds were lost. The exchange did not identify the DAO, publish the proposal number or provide on-chain transaction records for the attempted attack.

For YAM Finance, Defimon’s warning remains focused on proposal #45 and the pending vote. The security firm has asked YAM holders to vote against the proposal before block 25,897,343, the point it identified as the deadline for stopping the proposed Timelock administrator change through the governance vote.

ПОВ'ЯЗАНІ НОВИНИ

Strategy challenges MSCI proposal targeting digital asset treasury firms

cryptonews

Alle Indizien gesammelt – Was spricht für Russland

bild.de

Gabriel über Sabotage in Leipzig – Was wirklich hinter der Bomben-Drohne steckt

bild.de

Залишити коментар


Цей веб-сайт використовує файли cookie, щоб покращити ваш досвід. Ми припустимо, що ви з цим згодні, але ви можете відмовитися, якщо хочете. Прийняти Читати більше