Particle.news
Download on the App Store

YAM Finance Governance Proposal Seeks Timelock Control and Puts $337,000 at Risk

Defimon urged token holders to block the vote because a pending-admin change would hand an attacker control of the protocol’s Timelock and treasury.

Overview

  • Defimon, which flagged the activity Wednesday, said an address self-delegated about 504,000 YAM (roughly 3.3% of supply) and used that stake to submit YamGovernorAlpha proposal #45.
  • Proposal #45 makes a single on-chain call to the YAM Timelock contract’s setPendingAdmin function and names an attacker-controlled address as the pending administrator.
  • If the proposal passes and the attacker later calls acceptAdmin, the attacker would gain Timelock administrator powers that can control protocol contracts and move the DAO treasury.
  • Defimon estimated roughly $337,000 would be exposed if the change succeeds, but no funds had been reported stolen at the time of the alert because the proposal still needed to pass and execute.
  • The incident highlights a broader pattern where low voter participation lets small concentrations of delegated tokens meet quorum, a tactic seen in recent attacks such as BonkDAO, Term Labs, and StrongBlock, and it has prompted faster on-chain monitoring and coordinated exchange responses.