📈 Get daily crypto insights that make you smarter about your money

YAM Finance Governance Attack Puts 337,000 USD at Risk as Attacker Targets Timelock Control

YAM Finance, the DeFi protocol best remembered from the 2020 yield-farming era, is facing a governance takeover attempt after an attacker quietly accumulated enough delegated voting power to submit a proposal that could hand them administrative control of the protocol’s Timelock — and put roughly 337,000 USD in treasury assets at risk.

The attempt was detected by Defimon, the on-chain monitoring service operated by security firm Decurity, which raised the alarm on September 2 and urged remaining YAM holders to vote the proposal down before block 25,897,343.

## How the attack works

According to Defimon, an address self-delegated approximately 504,000 YAM tokens — around 3.3 percent of the supply — which was just enough to clear the protocol’s governance quorum given the DAO’s low participation.

The attacker then submitted YamGovernorAlpha proposal 45 with an empty description, a bare “0x” string. Rather than bundling several governance actions, the proposal makes a single call: invoking the setPendingAdmin function on the YAM Timelock contract and designating an attacker-controlled address as the new pending administrator.

If the proposal passes and executes, the attacker would first become pending administrator of the Timelock. From there, a single call to acceptAdmin would complete the transfer of administrative control over YAM’s protocol contracts and the DAO treasury. Defimon estimated approximately 337,000 USD is currently exposed.

No treasury funds have been reported lost so far. The proposal still needs to clear the governance vote and be executed before the takeover can proceed, and Defimon calculated holders had roughly 34 hours to respond at the time of its alert.

## Dormancy is the vulnerability

Defimon’s warning carries an uncomfortable subtext: YAM Finance has been largely dormant. In a healthy, actively-governed DAO, a hostile proposal from a 3.3 percent position would be swatted down within hours. In a ghost-town protocol, a modest token stake is all it takes to meet quorum and quietly take the keys.

The YAM case is textbook economic-security failure. Nothing in the smart contracts is broken. No private key was compromised. The attacker is simply using the protocol’s own governance machinery, exactly as designed, against a community that stopped showing up to vote.

## A recurring 2026 pattern

Governance takeovers have become one of the defining attack vectors of 2026, and the YAM attempt slots into a well-documented pattern.

Earlier in August, an attacker hijacked StrongBlock’s abandoned governance system through a malicious proposal, upgraded the Governor contract, and drained approximately 72,000 USD worth of STRONG and STRNGR tokens — 32,695 STRONG and 383,447 STRNGR.

Also in August, Term Labs suffered a far costlier version of the same play. An attacker spent roughly 951 USD acquiring a controlling position in the governance token, then passed proposals that drained about 8.5 million USD from strategy vaults, including 2,843 ETH worth approximately 6.87 million USD and 1.68 million USDC that was later swapped for close to 1.6 million DAI. Defimon was also the service that first flagged that incident.

The largest hit came in July, when an attacker spent around 4.4 million USD accumulating BONK through exchange wallets to clear BonkDAO’s quorum, then pushed through a proposal transferring roughly 20 million USD from the treasury. Only seven wallets participated in that final vote.

## The sector is adapting, slowly

The BonkDAO attack did produce one concrete defensive innovation: ENS DAO activated an eight-member Security Council in late July, structured as a five-of-eight multisig with authority to cancel malicious governance proposals before execution. The council can veto queued transactions but cannot move treasury assets or rewrite proposals.

Binance disclosed in August that its security team detected a malicious proposal against an unnamed DAO with less than 48 hours before execution, coordinated precautionary deposit closures across exchanges, and the proposal was ultimately rejected with no funds lost.

YAM itself is no stranger to existential drama. The protocol’s original 2020 launch famously imploded within days when a bug in its rebasing mechanism made the treasury un-governable, and the project survived as a community-run experiment rather than the elastic-supply powerhouse its founders envisioned. Six years on, the protocol’s governance layer has become the target — and its faded relevance is precisely what makes it vulnerable.

For YAM Finance, the immediate fix is blunt but effective: holders need to show up and vote against proposal 45 before block 25,897,343. The longer-term lesson is the one this cycle keeps teaching — a DAO’s real security budget is measured in engaged voters, not in the sophistication of its smart contracts.

12 thoughts on “YAM Finance Governance Attack Puts 337,000 USD at Risk as Attacker Targets Timelock Control”

  1. 3.3% of supply clearing quorum because nobody votes anymore, and proposal 45 ships with ‘0x’ as the description. zero shame

      1. defimon caught this one but the real story is every dead governor with a timelock sitting on the same 3% attack. this is a genre now

        1. same playbook as every dead governor out there. self delegate, wait out the apathy, grab the timelock. the 0x description is just the attacker being lazy

    1. the 0x description is my favorite part. dude could not even be bothered to write a fake justification, at least he is honest about the robbery lol

    2. proposal 45 with 0x as the description should be auto flagged by every frontend. one empty string between holders and losing 337k

  2. 504k YAM self delegated, 3.3% of supply, and thats enough to grab the timelock. dead DAOs are the softest targets in crypto

    1. ^ low participation is basically an open invitation. anyone with dust can self delegate and just wait for nobody to show up

    1. voting costs more gas than most remaining YAM bags are worth. that is exactly why quorum sits undefended, the economics of defending it make no sense

  3. 3.3 percent of the supply clearing quorum. the attacker probably expected a fight and got an empty room instead. apathy is the real exploit here

  4. 337k for what, a day of planning and 504k tokens? honestly shocked this does not happen weekly given how many governors sit under 5% participation

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$77,087.00-1.2%ETH$2,400.99-1.7%SOL$99.05-2.8%BNB$686.70+0.0%XRP$1.34-2.6%ADA$0.1962-1.3%DOGE$0.0816-1.3%DOT$0.8511-1.4%AVAX$7.16-1.7%LINK$11.15-2.2%UNI$5.89+3.0%ATOM$1.46-1.1%LTC$49.14-0.6%ARB$0.1112+1.7%NEAR$1.86-7.5%FIL$0.7720+10.1%SUI$0.7190-1.5%BTC$77,087.00-1.2%ETH$2,400.99-1.7%SOL$99.05-2.8%BNB$686.70+0.0%XRP$1.34-2.6%ADA$0.1962-1.3%DOGE$0.0816-1.3%DOT$0.8511-1.4%AVAX$7.16-1.7%LINK$11.15-2.2%UNI$5.89+3.0%ATOM$1.46-1.1%LTC$49.14-0.6%ARB$0.1112+1.7%NEAR$1.86-7.5%FIL$0.7720+10.1%SUI$0.7190-1.5%
Scroll to Top