- The project eventually collapsed after a bug in its unaudited smart contract
- If the attack was successful, the attacker would have been made the controller (Admin) of the Yam Finance Treasury.
- The team battled a malicious governance attack aimed at controlling its treasury holdings.
- The latest governance attack, however, places the project under scrutiny over security issues.
The Yam Finance team successfully blocked a malicious attack that attempted to clean the project’s treasury. The team battled a malicious governance attack aimed at controlling its treasury holdings.
Yam Finance, a starlet of the DeFi Summer in 2022, attracted over $400 million in funds on its first day. The project was funded by yield farmers.
Understanding Yam Finance
The finance project eventually collapsed after a bug in its unaudited smart contract inflated the number of YAM tokens by 10x. Furthermore, this led to the rendering of any governance decision very impossible.
The project now rests on a newer platform yam finance after securing $115,000 in donations to execute a security audit in its systems. The latest governance attack, however, places the project under scrutiny over security issues.
The starlet through a Tweet said that there was a governance attack on the DAO on July 9. Yam Finance further insisted that the attack was thwarted by the cyber security team. According to a report issued by Yam Finance, the attackers issued a malicious governance proposal with a spam description.
The objective of the governance proposal was to gain full control of the project’s treasury. The spam description reads as follows; “Contributors comps for May, backpay for VDM, settling synths tokens and success tokens, sending settled rewards tokens to reserves, sending and withdrawing test Uma and claiming Sushi for reserves.”
Malicious proposals on governance attack
Shortly after the spam description was sent, the attackers then voted on the proposal using YAM tokens. The attackers used 224,739 YAM tokens to vote for the malicious proposal.
The specified number of tokens presents a sum sufficient enough to reach a quorum to pass the proposal.
The Yam team was able to cancel the proposal before it was executed. Yam Finance canceled the attack three hours after it was created. If the attack was successful, the attacker would have been made the controller (Admin) of the Yam Finance Treasury.
The Yam finance treasury is approximated to be worth $3.1 million. Recently, Following the token’s tremendous slide, last week the YAM community voted on another proposal dubbed Redemption Proposal. The Yam Community voted on this proposal last week.
The malicious proposal would have allowed YAM token holders to redeem their tokens for approximately $0.25 from Treasury. The Redemption proposal was passed with close to 54.14% of voters supporting the proposal on July 8.
Reports from the Yam Finance group claim that the team behind the project requested a re-vote on the proposal to allow more time to discuss.
Although the team insisted that they do not agree with the suggestion, will Yam Finance survive the attacks?




