Governance Takeover Attempt at YAM Finance
A recent governance takeover attempt has put YAM Finance at risk, as an attacker has managed to gain enough voting power to initiate a proposal that could threaten approximately $337,000 in assets. This event was flagged by Defimon, a monitoring service provided by security company Decurity, which reported that an address self-delegated around 504,000 YAM tokens—a figure that constitutes about 3.3% of the total token supply, just surpassing the necessary voting threshold for governance decisions.
Details of the Proposal
The assailant submitted YamGovernorAlpha proposal #45, which alarmingly contained an empty description while seeking to alter control over the protocol’s Timelock. This single action seeks to appoint an address under the attacker’s control as the new pending administrator of the Timelock contract. Should the proposal succeed and gain the requisite backing, the attacker could subsequently finalize their takeover by invoking the ‘acceptAdmin’ function to fully transfer administrative authority.
Implications for YAM Holders
The implications of this takeover are concerning for YAM holders, as taking the reins of the Timelock would grant the attacker access to key administrative functions pertaining to YAM protocol contracts and its decentralized autonomous organization (DAO) treasury. As such, Defimon estimates that around $337,000 in assets are in jeopardy should the malicious proposal go through.
Call to Action
In light of this threat, Defimon has urged existing YAM holders to rally against the proposal before reaching block 25,897,343, providing a limited window of approximately 34 hours for a response when the alert was issued. The ongoing low participation in YAM governance was also highlighted as a potential vulnerability, leaving the system susceptible to manipulation from a small number of delegated tokens.
Context of Governance Vulnerabilities
At the time of the alert, it was noted that the proposal had not yet led to any reported loss of treasury assets, as it must pass through the governance process and be executed for the attacker to initiate the administrative shift.
This governance attempt is part of a worrying trend observed in the cryptocurrency space, where decentralized organizations with minimal oversight have increasingly become targets. Earlier in August, an incident involving StrongBlock saw a malicious proposal successfully seize control of its governance system, resulting in the theft of approximately $72,000 in STRONG and STRNGR tokens.
A further blow was dealt to Term Labs in the same month, where an assailant spent merely $951 to obtain a controlling stake in the governance token, ultimately facilitating the draining of around $8.5 million from strategy vaults.
In a notable instance from July, BonkDAO experienced a significant attack when an individual amassed enough BONK voting power to authorize a proposal that redirected about $20 million from its treasury without leveraging any smart contract vulnerabilities. The attacker maneuvered through the governance system, requiring no technical exploit, and following the transfer, BonkDAO sought law enforcement assistance to attempt to trace the moved assets.
Evolution of Governance Structures
In reaction to these events, governance structures across various projects are now evolving. For example, ENS DAO established an eight-member Security Council designed to nullify malicious governance proposals before execution, highlighting a much-needed shift towards addressing governance vulnerabilities in decentralized finance.
As the situation continues to unfold, the YAM community remains on high alert, with Defimon focusing efforts on rallying against proposal #45 before it becomes irreversible.