@AmpleforthOrg was the target of a governance attack attempt this past weekend.
An address submitted a proposal requesting a supposed DAO payment of $2.5M to a grantee, the project's entire USDC treasury. The project exists and is discussed on the forum, so it could slip by at first glance.
However, in the last few hours, the proposal that would have executed the attack was canceled.
The address that submitted the proposal was receiving a delegation from another wallet. That wallet held 87K
$FORTH, with 70K
$FORTH being the minimum required to submit a proposal. Today, the owner of those
$FORTH decided to sell their entire position in the governance token.
@AmpleforthOrg governance has a mechanism that allows anyone to cancel a proposal when the submitter holds less than 75K
$FORTH. Seventy blocks after the
$FORTH sale, an address canceled the proposal that would have stolen the $2.5M in USDC.
In parallel, a proposal to move treasury administration to the Ampleforth team's multisig entered voting. It was submitted one day after the attacker's proposal and will begin being voted on tomorrow.
If approved, Ampleforth would move administration of its treasury (via Timelock) to a 2-of-5 multisig, thereby preventing any
$FORTH holder from moving the funds currently held in treasury.
That would prevent further attacks, but it would also end the utility of
$FORTH - using the DAO's money.