Crypto news report · source clearly identified
YAM Finance governance attack puts $337K in assets at risk
YAM Finance has faced a governance takeover attempt after an attacker accumulated enough delegated YAM voting power to submit a proposal that could hand over control of the protocol’s Timelock and put roughly $337,000 at risk.

YAM Finance’s governance system was targeted by an attacker who self‑delegated roughly 504,000 YAM tokens, representing about 3.3% of the total supply. This amount of voting power is sufficient to meet the quorum required for proposals.
Malicious proposal details
The attacker submitted Governor Alpha proposal #45 with an empty description. The proposal contains a single call to the YAM Timelock contract’s setPendingAdmin function, designating an address controlled by the attacker as the pending administrator. If the proposal passes and is executed, the attacker could call acceptAdmin to assume full administrative control of the Timelock, and consequently the protocol contracts and DAO treasury.
Potential financial exposure
Defimon, an on‑chain monitoring service, estimated that approximately $337,000 is at risk if the proposal succeeds. The firm urged YAM holders to vote against the proposal before block 25,897,343, giving roughly 34 hours from the time of the alert.
Context of recent governance attacks
YAM Finance’s situation follows a series of governance‑based exploits in dormant or lightly monitored projects:
- StrongBlock: attacker seized control of an abandoned governance system and drained about $72,000 worth of STRONG and STRNGR tokens.
- Term Labs: attacker spent $951 to acquire a controlling stake, then used proposals to siphon roughly $8.5 million from strategy vaults, including 2,843 ETH and 1.68 million USDC.
- BonkDAO: attacker bought $4.4 million of BONK, reached quorum, and approved a proposal that transferred around $20 million from the treasury.
- Unnamed DAO (reported by Binance): a malicious proposal put $1.2 million at risk but was rejected before execution.
Security implications
These incidents illustrate how low participation and inactive governance can allow a relatively small concentration of delegated tokens to override protocol controls. Defimon’s alert highlights the need for vigilant voting and robust governance safeguards to prevent similar takeovers.
Source & attribution
News Source
- Publisher
- crypto.news
- Original date
- September 2, 2026, 7:15 AM
- Original headline
- YAM Finance governance attack puts $337K in assets at risk