Ampleforth governance under attack: suspicious proposal seeks to drain $2.5M treasury via malicious governance vote exploiting low quorum requirements.
Security & Exploits ·
Ampleforth's governance system faced an attempted exploit when a newly created account submitted proposal #54 to the protocol's Governor Bravo contract, requesting transfer of 2,500,000 USDC—nearly the entire treasury balance—to an address claiming to represent an "Observatory for SPOT completed-work grant." The proposer disclosed plans to self-vote via a delegate holding 87,238 FORTH tokens, representing 0.57% of supply and just above the 75,000-token minimum threshold to initiate a proposal.
The attack exploited structural weakness in Ampleforth's governance: the quorum requirement stands at 600,000 FORTH tokens, equivalent to roughly $132,000 at the token's price of $0.22. This creates a low barrier for a motivated attacker to accumulate voting power needed to pass a malicious measure, particularly when targeting a treasury containing $2.5 million in USDC. The proposing account showed only two prior transactions, suggesting it was created specifically for this action.
The proposal's status—whether it has advanced to voting, been rejected, or remains pending—was not disclosed in available information. It remains unclear whether the Ampleforth community has mobilized a counterresponse or whether governance safeguards outside the quorum mechanism would prevent execution if the vote passed.