The threat surfaced when an address self-delegated 504,000 YAM tokens, representing 3.3% of the total supply. This maneuver allowed the attacker to meet the governance quorum and submit YamGovernorAlpha proposal #45. According to the on-chain monitoring service Defimon, the proposal contains an empty description and executes a single function call to the Timelock contract, designating the attacker’s address as the new pending administrator.
In section Cryptocurrency
Governance Takeover Attempt Targets YAM Finance Treasury
An attacker has moved to seize control of YAM Finance, accumulating enough delegated voting power to push a proposal that would grant them administrative authority over the protocol’s Timelock. The move puts approximately $337,000 in DAO assets at risk, prompting an urgent call for holders to vote down the malicious measure.

Should the proposal pass and be executed, the attacker could finalize the transfer of control, effectively gaining command over the protocol’s smart contracts and treasury. Defimon has urged the community to vote against the proposal before block 25,897,343 to prevent the administrative handover. The protocol’s current state of low participation has left it uniquely vulnerable to such concentrated voting power, a trend that mirrors a broader wave of governance-based attacks currently plaguing decentralized organizations.
Comments (0)
No comments yet. Be the first!