Overview
- Defimon, which flagged the activity Wednesday, said an address self-delegated about 504,000 YAM (roughly 3.3% of supply) and used that stake to submit YamGovernorAlpha proposal #45.
- Proposal #45 makes a single on-chain call to the YAM Timelock contract’s setPendingAdmin function and names an attacker-controlled address as the pending administrator.
- If the proposal passes and the attacker later calls acceptAdmin, the attacker would gain Timelock administrator powers that can control protocol contracts and move the DAO treasury.
- Defimon estimated roughly $337,000 would be exposed if the change succeeds, but no funds had been reported stolen at the time of the alert because the proposal still needed to pass and execute.
- The incident highlights a broader pattern where low voter participation lets small concentrations of delegated tokens meet quorum, a tactic seen in recent attacks such as BonkDAO, Term Labs, and StrongBlock, and it has prompted faster on-chain monitoring and coordinated exchange responses.