YAM Finance is dealing with an apparent governance takeover attempt after an address accumulated enough delegated voting power to file a proposal that could hand control of the protocol’s Timelock to an attacker-controlled account.
The warning came from Defimon, an on-chain monitoring service run by security firm Decurity. According to its assessment, the proposal could ultimately expose roughly $337,000 tied to YAM protocol contracts and the DAO treasury if it passes and is executed.
Proposal #45 centers on Timelock administration
Defimon said the address self-delegated about 504,000 YAM, equal to roughly 3.3% of total supply. That was enough to move just above YAM’s governance quorum and submit YamGovernorAlpha proposal #45.
According to the monitoring service, the proposal carries an empty “0x” description and contains a single action. It calls the YAM Timelock contract’s setPendingAdmin function and names an address controlled by the attacker as the new pending administrator.
How the takeover could happen
If proposal #45 receives enough support and is later executed, Defimon said the attacker would first gain pending administrator status over the Timelock. The same address could then call acceptAdmin to complete the transfer of administrative control.
Control of the Timelock would give that address authority over the administrative functions tied to YAM protocol contracts and the DAO treasury. Based on Defimon’s estimate, around $337,000 would be at risk if the process succeeds.
Low participation raises the threat
Defimon urged YAM holders to vote against the proposal before block 25,897,343. At the time of the alert, it estimated there were about 34 hours left to respond.
The firm also noted that YAM Finance has been largely dormant. In that kind of environment, governance can become vulnerable because a relatively small amount of delegated voting power may be enough to satisfy quorum and push through sensitive proposals.
Part of a wider pattern in DAO governance
The attempted YAM takeover follows several recent cases in which attackers relied on governance authority rather than a flaw in smart contract code. In August, an attacker reportedly took over StrongBlock’s inactive governance system through a malicious proposal and later drained about $72,000 in STRONG and STRNGR tokens.
Another August incident hit Term Labs after an attacker spent about $951 to build a controlling token position, then used proposals to drain roughly $8.5 million from vaults. In July, BonkDAO suffered a far larger governance incident after an attacker accumulated enough BONK voting power to approve a treasury transfer of around $20 million.
What is confirmed so far
As of Defimon’s alert, the YAM incident had not resulted in a reported loss of treasury funds. The proposal still needed to complete the governance process and be executed before the attacker could move to finalize the Timelock administrator change described by the security firm.
For now, the immediate confirmed next step is the vote on proposal #45. Defimon’s warning remains focused on defeating that proposal before block 25,897,343, which it identified as the deadline for stopping the attempted administrator handover through governance.
Source: crypto.news