Attacker launched governance takeover of Yam.finance with 3.3% self-delegated YAM, submitting proposal to seize protocol admin control with ~34 hours until execution.
Security & Exploits ·
An attacker self-delegated approximately 504,000 YAM tokens—roughly 3.3% of supply and just above the quorum threshold—to launch a governance takeover of Yam.finance. The attacker then submitted YamGovernorAlpha proposal #45 with an empty description, containing a single action to call setPendingAdmin targeting the attacker's address on the YAM Timelock contract.
If the vote passes and executes, the attacker would become pendingAdmin and subsequently acceptAdmin, gaining full control of the Timelock—which administers all YAM protocol contracts and the DAO treasury. Approximately $337K is at risk from this exploit. The protocol is noted as dormant, leaving token holders a window of roughly 34 hours until block 25,897,343 to vote against the proposal.
The attack highlights a vulnerability in governance systems where low quorum requirements and minimal token concentration thresholds can enable takeover attempts. Whether the community can muster sufficient opposing votes or whether additional safeguards will be deployed before execution remains to be seen.