Yam Finance Governance Attack Puts $337k in Assets at Risk

Yam Finance faced an attempted governance takeover after an attacker self-delegated about 504,000 YAM and submitted proposal 45 to seize the Timelock, putting roughly $337,000 in assets at risk. Defimon, operated by Decurity, urged holders to vote against the proposal before block 25,897,343.

Listen to Article — 4 min
Follow Our News on Google
Be instantly informed of developments.
Add as a preferred source on Google

Yam Finance faced an attempted governance takeover after an attacker accumulated enough delegated YAM voting power to submit a proposal that could seize control of the protocol’s Timelock and put roughly $337,000 in assets at risk. Defimon, the on-chain monitoring service operated by security firm Decurity, detected the attempt and urged remaining holders to vote against the proposal before block 25,897,343. The incident highlights how dormant DeFi governance systems can become exposed when a relatively small share of voting power clears the quorum.

Attacker Used Empty Proposal to Target Timelock Admin

The attack centered on YamGovernorAlpha proposal #45, submitted with an empty “0x” description. Defimon said the proposal made a single call to the YAM Timelock contract’s setPendingAdmin function and designated an attacker-controlled address as the new pending administrator.

If executed, Defimon said the attacker would first obtain pending administrator status over the Timelock, then call acceptAdmin to complete the transfer of administrative control. That control would cover administrative functions governing YAM protocol contracts and its DAO treasury, with approximately $337,000 exposed if the proposal succeeds.

The firm said no treasury loss was reported at the time of its alert because the proposal still needed to pass governance and execute before the administrator change could proceed.

Low Participation Left Dormant Protocol Vulnerable

YAM Finance has been largely dormant, a condition Defimon cited while warning holders. Low participation can leave governance systems exposed when a relatively small concentration of delegated tokens is enough to meet voting requirements. The attacker self-delegated approximately 504,000 YAM tokens, around 3.3% of supply and enough voting power to move just above the governance quorum.

At the time of its alert, Defimon estimated holders had “around 34 hours to respond.” The service urged remaining YAM holders to vote against the proposal before block 25,897,343, placing the community under immediate pressure to organize a counter-vote.

The technical path of the attack can be summarized as follows:

  • Self-delegated YAM: approximately 504,000 tokens
  • Supply share: around 3.3% of YAM supply
  • Governance proposal: YamGovernorAlpha proposal #45
  • Proposal description: empty “0x
  • Single action: call to Timelock setPendingAdmin
  • Attacker step after execution: call acceptAdmin
  • Assets estimated at risk: approximately $337,000
  • Voting deadline: block 25,897,343
  • Estimated response window: around 34 hours

Governance Attack Pattern in DEFI

The attempted YAM takeover follows several governance attacks involving inactive or lightly monitored decentralized organizations in recent months. These incidents often exploit the same weakness: governance parameters remain live, but participation is too low for holders to notice a hostile proposal until it is close to execution.

Timelocks are meant to give users time to review and exit before governance changes take effect, but they also concentrate administrative power in the hands of whoever controls the pending admin role. If an attacker can move just above quorum, a dormant treasury can become a target even when the protocol’s user base is small.

Governance Event On-Chain Detail Reported Risk
Attacker delegation Approximately 504,000 YAM self-delegated About 3.3% of supply, just above quorum
Proposal submitted YamGovernorAlpha proposal #45 Empty “0x” description, single Timelock action
Targeted control Timelock setPendingAdmin and acceptAdmin Administrative control over protocol contracts and DAO treasury
Assets exposed Defimon estimate Roughly $337,000 at risk if executed
Community deadline Vote against before block 25,897,343 About 34 hours to respond at alert time

No funds were reported lost at the time of Defimon’s alert, and the proposal still required governance approval and execution before the attacker could complete the Timelock administrator change. The episode underscored the operational risk facing older or lightly used DeFi protocols, where governance can remain active long after daily participation fades.

What Happened with Yam Finance?

Yam Finance faced an attempted governance takeover after an attacker self-delegated about 504,000 YAM and submitted proposal #45 to change the Timelock pending administrator. The proposal could have given the attacker administrative control over protocol contracts and the DAO treasury.

How Much Was at Risk in the Yam Finance Attack?

Defimon estimated that approximately $337,000 in assets was exposed if the proposal succeeded. The reported amount was not lost at the time of the alert because the proposal still needed to pass governance and execute.

What Is a Timelock in DEFI Governance?

A Timelock is a contract mechanism that delays the execution of approved governance actions, giving users time to review changes before they take effect. Control of a Timelock’s administrator functions can affect upgrades and administrative actions across a protocol.

Why Did 3.3% of Yam Supply Matter?

The attacker’s self-delegated 504,000 YAM represented around 3.3% of supply, which was enough to move just above the governance quorum. In a dormant protocol, low participation can make a relatively small token concentration decisive.

Did Yam Finance Lose Funds from the Governance Attack?

No loss was reported at the time of Defimon’s alert. The attacker still needed proposal #45 to pass governance and execute before obtaining pending administrator status and completing the Timelock control transfer.

This article is provided for informational and educational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice. The digital asset market is highly volatile, speculative, and subject to rapid regulatory changes. While we strive to ensure the accuracy of the information presented, market conditions change quickly, and data may become outdated. You are solely responsible for your own research (DYOR) and financial decisions. ATHPost, its owners, and its authors assume no liability whatsoever for any direct or indirect financial losses, liquidations, or damages arising from the use of this content.