The decentralized finance (DeFi) protocol Ampleforth (AMPL) is currently facing a significant governance threat following a suspicious proposal aimed at the project's treasury. On September 12, 2026, a newly activated Externally Owned Account (EOA) initiated a request to transfer 2.5 million USDC—representing nearly the entirety of the treasury's liquid reserves—to a private address. While the proposal remains in a pending state, the community and security researchers have raised alarms regarding a potential "governance attack" designed to siphon protocol assets under the pretext of ecosystem development grants.
Details of the Exploitative Proposal
According to a security alert from the GoPlus Chinese Community, the attacker submitted the proposal under the guise of "applying for completed work grants for SPOT ecological analysis tools." However, the requested amount matches the total liquid funds available in the Ampleforth treasury, suggesting a malicious intent rather than a legitimate funding request. The proposal process for the Ampleforth ecosystem relies on the FORTH governance token, which dictates the voting power required to pass such measures.
Key technical aspects of the current proposal status include:
- Proposal State: The request is currently Pending, with no official votes cast at the time of the report.
- Voting Thresholds: A minimum of 75,000 FORTH is required to initiate a proposal, while 600,000 FORTH is needed to reach a quorum for passing.
- Attacker Assets: The proposer’s address and an associated delegation address each hold approximately 87,200 FORTH in voting power.
Governance Vulnerabilities and Economic Risks
Security analysts have noted that the barrier to entry for a successful attack is alarmingly low due to the current market valuation of the governance token. At a pre-warning price of approximately $3.27 per FORTH, an attacker would need to control assets worth roughly $1.96 million to unilaterally pass the proposal. This creates a situation where the cost of acquiring the necessary voting power is lower than the 2.5 million USDC target, potentially incentivizing a hostile takeover of the governance process.
A newly activated EOA address launched a proposal attack on Ampleforth, requesting the transfer of nearly all of the treasury's liquid funds to the proposer under the guise of work grants.
The incident highlights a recurring vulnerability in Decentralized Autonomous Organizations (DAOs), where the market liquidity of a governance token can be leveraged to extract value from a protocol's treasury. As of the current UTC date, the funds remain secure within the treasury, but the Ampleforth community is being urged to monitor the FORTH voting dashboard closely. If the proposal moves from pending to active status, it will require a swift counter-vote from legitimate token holders to prevent the transfer of the USDC reserves.
Frequently Asked Questions
Quick answers to the most common questions about this topic.