GoPlus Security Alert regarding an active proposal attack on #Ampleforth
We want to bring a critical situation to the community's attention. On Sept 12, a newly funded EOA submitted a malicious governance proposal on @AmpleforthOrg.
While it is disguised as a completed-work grant for SPOT ecosystem analytics tools, the request actually aims to transfer 2,500,000 USDC from the treasury directly to the proposer. To put this into perspective, this amount accounts for nearly all liquid treasury funds.
You can review the proposal details here: https://tally.xyz/gov/ampleforth/proposal/54
Currently, the status remains pending. There are no votes, and the funds have not moved.
The real risk in this scenario is the pass threshold. It requires 75,000 FORTH to propose and 600,000 FORTH to pass. Given the alert-time price of $0.27, a malicious actor would only need approximately $160k in voting power to clear out $2.5M USDC. Please stay sharp.
To clarify how this event unfolded, we have outlined the involved accounts in chronological order.
The relay and funder address is 0x92fc19271fce6d48cd41a0eff6f5dd40f1090d72. This wallet began the process by sending 87,238 FORTH and 0.005 ETH for gas to a delegator account.
That delegator, located at 0x38cAaa5782BF8afF646403D567D76b016d5c24D8, ended up with the same 87,238.546 FORTH. Exactly 19 minutes before the proposal submission, this wallet delegated its voting power to the final proposer.
Lastly, the proposer and intended payout address is 0x730C97E793f6F7c476C6AeB3E1c3fDad4714dd82. Thanks to the delegation, this account now controls 87,238.546 FORTH in voting power.
We want to bring a critical situation to the community's attention. On Sept 12, a newly funded EOA submitted a malicious governance proposal on @AmpleforthOrg.
While it is disguised as a completed-work grant for SPOT ecosystem analytics tools, the request actually aims to transfer 2,500,000 USDC from the treasury directly to the proposer. To put this into perspective, this amount accounts for nearly all liquid treasury funds.
You can review the proposal details here: https://tally.xyz/gov/ampleforth/proposal/54
Currently, the status remains pending. There are no votes, and the funds have not moved.
The real risk in this scenario is the pass threshold. It requires 75,000 FORTH to propose and 600,000 FORTH to pass. Given the alert-time price of $0.27, a malicious actor would only need approximately $160k in voting power to clear out $2.5M USDC. Please stay sharp.
To clarify how this event unfolded, we have outlined the involved accounts in chronological order.
The relay and funder address is 0x92fc19271fce6d48cd41a0eff6f5dd40f1090d72. This wallet began the process by sending 87,238 FORTH and 0.005 ETH for gas to a delegator account.
That delegator, located at 0x38cAaa5782BF8afF646403D567D76b016d5c24D8, ended up with the same 87,238.546 FORTH. Exactly 19 minutes before the proposal submission, this wallet delegated its voting power to the final proposer.
Lastly, the proposer and intended payout address is 0x730C97E793f6F7c476C6AeB3E1c3fDad4714dd82. Thanks to the delegation, this account now controls 87,238.546 FORTH in voting power.
