YAM Finance Hit by Governance Attack, $337,000 in Assets Exposed
AI-summarised brief · reviewed before publication
YAM Finance’s governance system faced a takeover attempt after an address self‑delegated about 504,000 YAM tokens—3.3 % of total supply—granting the holder enough voting power to meet the quorum. The attacker submitted Proposal 45, which contains a single call to the Timelock contract’s setPendingAdmin function, designating the attacker’s address as pending administrator. If the proposal passes, the attacker could execute acceptAdmin and assume full control of the Timelock, thereby directing the protocol’s contracts and the DAO treasury. Security firm Decurity’s on‑chain monitor Defimon warned that roughly $337,000 (≈ Rs 3.1 crore) is at risk and urged remaining YAM holders to vote against the proposal before block 25,897,343, with about 34 hours left. Inactive governance participation left YAM vulnerable, though no funds have been lost so far.
💡 Why It Matters
- · The attack shows how minimal token delegation can jeopardize a DAO’s core controls, exposing treasury assets to hostile capture.