Attacker gained control of Yam Finance governance, reduced Timelock delay, and drained ~$121K from legacy UMA farming contracts via privileged functions.
Security & Exploits ·
An attacker executed governance proposal #45 to seize control of Yam Finance's Timelock, then expedited attack execution by reducing the delay from 5 days to 12 hours. With administrative privileges, the attacker became governor of Yam's dormant UMA farming contracts and called _settleExpired() to unlock WETH collateral from expired uGAS positions. The attacker then used the masterFallback function—a governance-only mechanism permitting arbitrary contract calls—to withdraw approximately $121K in assets, including 23.50 WETH and 763 UMA from the uGAS-MAR21 contract and 24.59 WETH from the uGAS-FEB21 contract.
The attack exploited Yam Finance's inactive governance infrastructure, which lacked active monitoring or safeguards against proposal execution. The attacker converted the extracted assets—totaling 48.15 ETH—through FixedFloat, facilitating rapid liquidation. The breach underscores risks posed by abandoned governance systems where timelock protections can be dismantled by any participant able to execute proposals.
It remains unclear whether governance mechanisms have since been secured, whether Yam Finance has initiated recovery efforts, or whether law enforcement or protocol developers have intervened. The extent of monitoring or community response to the incident has not been documented.