A wallet funded by an address Blockscout flags as a scam bought roughly 504,000 YAM this week, about 3.3% of supply, enough to clear
@YamFinance 200k-vote governance quorum by itself. It's now sitting behind proposal #45.
The setup ran in six moves:
- fund the wallet
- buy the YAM through an on-chain aggregator
- self-delegate
- submit a proposal on YamGovernorAlpha V3 with an empty description
- then vote FOR in the very next block so the snapshot locks in before anyone can react.
- the attacker then sold most of the position, keeping back roughly 80k votes worth of YAM, just above the 50k threshold that lets anyone call a public cancel().
Proposal #45 does one thing: setPendingAdmin on Timelock V3, naming the attacker's address. Pass it, and that address controls the Reserves treasury, the YAM V3 token's gov and mint functions, and the Incentivizer and Migrator contracts, all without a second vote.
The same play failed in July 2022 on the same Governor V3 because the attacker sold below threshold and anyone could cancel. This time the position was sized to stay above it, and the Guardian multisig, which can still cancel(45) with 3 of 8 signers, hasn't signed anything since November 2022. Flash loans don't help either way, since voting power is checkpointed at the proposal's start block.
If you hold delegated YAM, vote against #45 before block 25,897,343.