Malicious governance proposal submitted to drain Olas treasury of 40.196 ETH (~$100K) by transferring ownership to attacker-controlled contract.
Security & Exploits ·
A malicious governance proposal targeting Olas.network has surfaced, putting approximately $100K in treasury assets at immediate risk. The attacker, operating via a Tornado-funded address and an ENS name "autonolas-deployer.eth," submitted a proposal ostensibly titled around transferring treasury ownership to a purported Safe updater. In reality, execution would redirect control of the Olas treasury away from the legitimate Autonolas Timelock to an attacker-controlled contract, enabling subsequent extraction of all held funds.
The targeted treasury contains 40.196 ETH. Once ownership shifted to the malicious contract, the attacker could rebalance assets and initiate full withdrawal. The community has been notified of the threat within official channels.
A three-day window remains to halt the proposal before it advances to execution. The exact mechanics by which the attacker bypassed or exploited the governance process remain unclear from available details, as does confirmation of whether the proposal has yet reached a voting stage or whether additional safeguards exist to prevent passage.