DeFiDAOs

Governor Note: The Yam Governance Attack (Jul. 9, 2022)

Key Insights

  • Yam Finance was the target of an unsuccessful governance attack that aimed to seize approximately $3.1 million in treasury assets.
  • The attacker targeted the Compound Governor Alpha contract to propose code that, if executed, would have transferred ownership of Yam Finance.
  • The attacker prematurely withdrew their voting power allowing the proposal to be canceled. The Yam Finance Guardian multisig had also been alerted and could have vetoed the proposal.
  • Despite the attack's failure, Yam Finance's treasury remains vulnerable. The community is considering a proposal allowing YAM redemptions against the Yam treasury.

Recently, Yam Finance became one of many DAOs whose governance token's market cap has fallen below the value of their DAO treasury. This situation created a financial dynamic that introduced governance risk, as the cost-to-reward ratio increased the likelihood of an actor attacking DAO funds. That is precisely what happened with the DAO. On Jul. 9, 2022, Yam Finance experienced a governance attack that threatened the DAO treasury and the integrity of its governance module.

How Does the Yam Finance Governance System Work?

Yam uses the Compound Governor Alpha module, an on-chain governance framework that allows YAM token holders to execute code and transactions directly to the protocol. On-chain governance allows for direct control of DAO assets.

On-chain voting differs from off-chain voting, which uses tools like Snapshot and places trust on a concentrated number of individuals to execute governance proposals via a multisig. While on-chain proposals are required to enact protocol changes, Yam uses off-chain voting via Snapshot as a temperature check for achieving community consensus and as a final vote for proposals that don’t require on-chain execution.

A graphical representation of the Yam Finance governance process flows from Discord ideation for a proposal to the Proposal execution timelock.

Source: Yam Finance

Community members must stake their YAM in Sushi's YAM/ETH pool and deposit their Sushi Liquidity Pool (SLP) tokens in the Yam Incentivizer Contract to be eligible to vote. Their voting power is measured using balanceofUnderlying YAM (BoUYAM). Yam initially calculated BoUYAM to balance voting power against the YAM rebasing mechanism. Since the rebasing mechanism was disabled on Dec. 29, 2021, the equation has used fixed parameters resulting in one BoUYAM being equal to a voter’s yam holdings in the incentivizer contract divided by 2.5.

What Happened During the Jul. 9th Attack?

An attacker used 200 ETH, a smart contract, and four wallets to launch a governance attack on the Yam Finance protocol.

  • The first activity occurred on Jul. 7, 2022, when the attacker received 200 ETH to the first wallet (Wallet A) from Tornado Cash, a mixer protocol that improves the anonymity of on-chain transactions.
  • The attacker then used a series of transactions across three wallets to convert the funds into Sushiswap YAM/ETH SLP tokens.
  • The attacker used a fourth wallet to create a malicious contract. While the exact contents of the contract are not yet verified, the attacker was able to transfer the ownership of their SLP to the malicious contract, and staked the SLP in the Yam Incentivizer contract. This activated their voting power and allowed them to delegate it to the malicious contract’s address.
  • Once delegated, the attacker had amassed approximately 224,739 BoUYAM in voting power.
This image describes the steps the attacker took to launch a governance attack on the Yam Finance governance module.

Source: Yam Finance

The YAM Governor Contract includes a proposal threshold of 50,000 BoUYAM (1% of the circulating supply) and a success quorum of 200,000 BoUYAM in favor of the proposal. The attacker had enough to exceed both thresholds, and at 9:08 UTC on Jul. 9, 2022, the attacker created a malicious proposal.

The proposal included the same description as the legitimate YAM Proposal 25, which Yam successfully executed on Jun. 23, 2022. However, the executable code attached to the attacker’s proposal would instead change the admin of the YAM treasury (currently valued at ~$3.1 million) to their wallet address.

How Was the Attack Resolved?

The Yam governance module and community proved resilient to the attack. The attacker prematurely unwound their SLP token positions and sold their YAM position to ETH under an hour after they created the proposal. Proposers are required to hold their voting power throughout the entire voting process. Because the attacker withdrew their funds before the voting phase was completed, the community could cancel the proposal.

The Yam Finance Guardian, a 3-of-5 multisig that can veto proposals on behalf of the protocol before execution, was alerted of the activity by the Ethereum community and the governance proposal bot on the Yam Discord. If the attack had continued, the Guardian multisig could have canceled any non-executed proposal.

Is On-Chain Governance Safe?

Decentralized governance involves accepting inherent risks and vulnerabilities at both the contract and social layers. The permissionless access to enact change on the protocol is a double-edged sword, as an entity with the appropriate amount of tokens can propose malicious actions. To date, several governance attacks have been attempted and even executed.

The table shows recent DAO governance attacks, resolutions, and targeted funds.

Source: Messari, CoinDesk, Twitter, Medium

Ross Galloway, a Yam core team member, expressed in the Yam Discord that the susceptibility to bad actors is part of the decentralization trade-off. An open system is inherently more accessible to bad actors. Rather than introducing further restrictions to governance and thus centralizing control, the team believes the best practices employed by the community in the July 9 attack can also deter future attacks.

Treasury Redemption: An Internal Attack on the Treasury

Ironically, the more potent threat to the Yam Finance treasury may not be an external actor but its community. A less malicious but equally damaging proposal to Yam Finance is currently in play to enable YAM holders to redeem their assets against the Yam Treasury. The proposal is currently at the off-chain voting stage and aims to deploy a redemption contract recently created by Lobis Finance. If the vote is successful, YAM holders would be able to deposit their YAM into the contract. Each token deposited would be sent to a burn address, and in exchange, the underlying treasury assets would be distributed to the holder.

The treasury redemption proposal had initially succeeded in an off-chain temperature check on Jul. 7, 2022. However, the core team, which appears against the proposal, requested that the proposers follow the official governance process and submit the proposal for a revote.

The overlap of the governance attack and the community sentiment reflects a larger story of DAO longevity. While the YAM fully diluted market cap sits at $2.3 million, its treasury value is significantly higher at $3.1 million. As the bear market continues and DAOs struggle to survive, the question of what becomes of their assets becomes increasingly problematic. The lower the market cap, the more attractive attacks on the treasury appear, and the more self-sabotaging a community can become.

Let us know what you loved about the report, what may be missing, or share any other feedback by filling out this short form. All responses are subject to our Privacy Policy and Terms of Service.

All content was produced independently by the author(s) and does not necessarily reflect the opinions of Messari, Inc. Author(s) may hold cryptocurrencies named in this report. This report is meant for informational purposes only. It is not meant to serve as investment advice. You should conduct your own research and consult an independent financial, tax, or legal advisor before making any investment decisions. Nothing contained in this report is a recommendation or suggestion, directly or indirectly, to buy, sell, make, or hold any investment, loan, commodity, or security, or to undertake any investment or trading strategy with respect to any investment, loan, commodity, security, or any issuer. This report should not be construed as an offer to sell or the solicitation of an offer to buy any security or commodity. Messari does not guarantee the sequence, accuracy, completeness, or timeliness of any information provided in this report. Please see our Terms of Service for more information.


No part of this report may be (a) copied, photocopied, duplicated in any form by any means or (b) redistributed without the prior written consent of Messari®.

Traver is a Research Analyst at Messari. Previous to Messari, Traver studied Economics and Environmental Studies at Northeastern University. He is most interested in protocol governance.

Tomas Molin is the research lead of Messari Governor. Prior to joining Messari, Tomas worked at Ardian in the Growth Equity team focusing on technologies. At Messari, he began within the Intel team covering DeFi and governance related topics before taking the lead of the Governor team when the product was launched.

Mentioned Assets

Suggested Research Based on your Watchlists

Create a new watchlist
Outline
  • Key Insights
  • How Does the Yam Finance Governance System Work?
  • What Happened During the Jul. 9th Attack?
  • How Was the Attack Resolved?
  • Is On-Chain Governance Safe?
  • Treasury Redemption: An Internal Attack on the Treasury
Authors
Traver is a Research Analyst at Messari. Previous to Messari, Traver studied Economics and Environmental Studies at Northeastern University. He is most interested in protocol governance.
Tomas Molin is the research lead of Messari Governor. Prior to joining Messari, Tomas worked at Ardian in the Growth Equity team focusing on technologies. At Messari, he began within the Intel team covering DeFi and governance related topics before taking the lead of the Governor team when the product was launched.
Mentioned Assets