Web3 Daily Exploits — 2 Sep 2026: Yam governor grab, Geb 5.94 ETH drain

Yam Finance faces an active Timelock takeover vote with about $337K still at risk. SlowMist confirmed a GebProxyActions drain of ~5.94 ETH; no new eight-figure protocol hacks landed in-window.

Web3 Daily Exploits — 2 Sep 2026: Yam governor grab, Geb 5.94 ETH drain

Yam Finance faces an active Timelock takeover vote with about $337K still at risk. SlowMist confirmed a GebProxyActions drain of ~5.94 ETH; no new eight-figure protocol hacks landed in-window.

This 2 September 2026 brief covers incidents first reported, confirmed, or materially updated in the prior 24 hours (from about 11:30 UTC on 1 September). Yesterday’s edition already treated the Injective binary-options drain, the Aquifer vault emptying on Solana, and the Cronos halt-and-rollback after Tectonic. Those events are not recycled here except where a tracker posted a narrow follow-up. @CertiKAlert published no in-window exploit alert. @Phalcon_xyz did not add a new incident after its Aquifer write-up. @DefimonAlerts and @SlowMist_Team supplied the two confirmed items below.

1. Yam Finance — governance takeover attempt (confirmed attempt; funds not yet moved)

What happened. On 1 September 2026 at 21:02:35 UTC, address 0x26881EacC00Bcccd7c4ebE14BD7840dD989Bf982 submitted YamGovernorAlpha proposal #45. Defimon Alerts flagged the proposal as a governance takeover attempt against the long-dormant Yam Finance stack. The description field is empty in the alert. Etherscan decodes the propose call description as setPendingAdmin(address). The single queued action targets the YAM Timelock and calls setPendingAdmin with the proposer as the new pending admin.

Protocol / chain / asset. Yam Finance, Ethereum mainnet. Assets at risk sit in remaining protocol and treasury-linked contracts, including the Yam WETH pool Defimon later singled out. Defimon estimated about $337,000 exposed if the vote succeeds and the Timelock admin change is accepted. That figure is an at-risk estimate, not a realized loss.

Loss (USD). Live loss from this incident is currently $0. No treasury drain transaction has been confirmed as of this brief. If proposal #45 passes, is queued, and is executed, and if the attacker then calls acceptAdmin, the Timelock would become an admin surface over Yam protocol contracts and the DAO treasury.

Attack type. Hostile governance / low-quorum takeover of an abandoned GovernorAlpha, not a smart-contract math bug. The proposer first acquired voting power on the open market, self-delegated, then submitted a one-action proposal that would re-point Timelock administration.

Technical details (confirmed on-chain). Hours before the propose call, the same address swapped about 4.1 ETH for roughly 504,427 YAM via SushiSwap’s RedSnwapper path, matching Defimon’s note of about 504K YAM, or 3.3 percent of supply, just over the quorum. The propose transaction hit YamGovernorAlpha at 0x2DA253835967D6E721C6c077157F9c9742934aeA. Decoded parameters: target 0x8b4f1616751117C38a0f84F9A146cca191ea3EC5 (Timelock), value 0, signature setPendingAdmin(address), calldata pointing at the proposer, proposal id 45, start block 25884998, end block 25897343. Defimon said holders who still control YAM votes needed to vote against before that end block, about 34 hours from the 05:21 UTC alert.

At 07:51 UTC on 2 September, Defimon added that anyone still in the Yam WETH pool should withdraw. Etherscan at the time of that reply showed the pool contract with a multi-hundred-thousand-dollar balance, consistent with the $337K at-risk band.

Yam has a documented history of governance-path attacks. The 2022 treasury incident was stopped before execution. The current event is a new proposal on the same GovernorAlpha pattern: quorum is small relative to liquid supply, the protocol is inactive, and a single Timelock admin change is enough to inherit contract control. This desk is not publishing vote-casting walkthroughs beyond the public facts Defimon already posted.

Status. Confirmed attempt. Vote window still open at the time of the original alert. No official Yam team statement located in the window. Outcome — pass, fail, cancel, or later execution — is not yet final and should be re-checked on the governor before treating the $337K as lost.

Sources. https://x.com/DefimonAlerts/status/2095019159847313766, https://x.com/DefimonAlerts/status/2095056926715372025, plus the Etherscan records above. Independent recaps at crypto.news, Odaily, Foresight, and PANews repeated Defimon’s figures without adding a second on-chain source.

2. GebProxyActions — missing caller check on quitSystem (confirmed)

What happened. SlowMist TI Alert on 2 September 2026 at 03:10 UTC reported that GebProxyActions.quitSystem has no caller access control. Users who previously called quitSystem directly — instead of through the intended DSProxy delegatecall path — left ownsSAFE[safe] pointing at the GebProxyActions contract itself. An attacker then called GebProxyActions.quitSystem(manager, safe, dst) directly, skipped GebSafeManager’s safeAllowed check, and pulled collateral.

Protocol / chain / asset. Geb / Reflexer-style SAFE stack on Ethereum. SlowMist named CollateralJoin1 and SAFEs #3, #5, #8, and #18. The lost asset in the alert is ETH collateral, not a protocol token print.

Loss. SlowMist: about 5.9436 ETH. No official USD print accompanied the alert. Spot ETH around the alert window was near $2,400, which implies a rough $14,000 live loss. That conversion is desk arithmetic, not a SlowMist figure. No rollback or reimbursement has been announced.

Attack type. Access-control / calling-context assumption. The actions contract treated msg.sender as a user proxy. When users invoked it as a normal external call, ownership of the SAFE attached to the actions contract, and a later unprivileged caller could exit collateral to an address they chose.

Technical details. SlowMist listed:

An associated exploit transaction that emits multiple QuitSystem events with sender set to GebProxyActions and destination 0xB0F1eA5fCE6EC33967C1C43A09bf73C8D7b20996 is 0xfbce28e35c26358110dd9ed91f9ceef588acb264c3cf6c573df65ca21335058f. Event data on that transaction includes SAFE ids 3 and 5 and non-zero deltaCollateral values moving toward the destination contract. SlowMist’s public post truncated the Tx line; this hash is the matching on-chain quit bundle from the named attacker context and should be treated as the primary explorer reference unless SlowMist later publishes a different canonical hash.

Status. Confirmed by SlowMist; loss realized on-chain. No protocol pause or user-repay statement found in the window. PANews, Phemex News, and KuCoin flash desks repeated the SlowMist text.

Sources. https://x.com/SlowMist_Team/status/2094986310683705835 and the Etherscan links above.

UPDATE — Tectonic / Cronos escaped funds (narrow follow-up, not a new drain)

PeckShieldAlert’s 1 September monthly wrap restated August totals: 50 major hacks, $136.3M lost, with Tectonic.cro about $74M listed as the month’s largest and the year’s fourth-largest at the time of that post. The material line for this brief is the movement note: the exploiter bridged only about $6M to Ethereum before Cronos paused, and PeckShield said the exploiter had started laundering those escaped funds toward Bitcoin (about 200K so far in that post). Cronos validators had already restored pre-exploit state on-chain; funds that left Cronos before the halt remain the live loss from that incident. This is not a second Tectonic drain. Full incident mechanics stay in the 31 August and 1 September briefs.

Source: https://x.com/PeckShieldAlert/status/2094631045845164273. Official Cronos resume-from-rollback post remains https://x.com/CronosNetwork/status/2094417832394301499 (31 August, outside this window, cited only as the halt/restore record).

Also noted

  • Required-account sweep. Last-24-hour checks on @DefimonAlerts, @CertiKAlert, @Phalcon_xyz, @GoPlusSecurity, and @SlowMist_Team found no additional confirmed protocol exploit beyond Yam and Geb. @CertiKAlert was silent in the window (last public stats post was 31 August). @Phalcon_xyz did not publish a new incident after Aquifer. @GoPlusSecurity’s 12:00 UTC 1 September Aquifer recap restated the 31 August Solana drain already covered yesterday; its later posts were token-screening and a community audit promo. @immunefi posted researcher-program notes, not incident response. @zachxbt posted no exploit thread in the window.
  • Unverified / reject. @LumidaNews posted that Arbitrum protocol AFX Trade was hit by a $24M bridge exploit at 11:00 UTC on 2 September (21 views, no engagement from security desks). AFX Trade’s about $24.15M USDC bridge-key incident is a 22 July 2026 event documented by Blockaid, The Block, The Defiant, and others. No evidence it recurred in the last 24 hours. Treated as noise.
  • Out of window (not counted). GoPlus stale-Permit drains and a $47K Homebrew / Nova Stealer Mac setup theft posted before 11:30 UTC on 1 September. They are phishing and malware, not new protocol bugs, and fall outside the cutoff used for this edition.

Sources and references

Editor’s note

Today is a quiet large-ticket day after a heavy 31 August–1 September stretch. The Yam proposal is the item that can still change the live-loss column: $337K is exposed, not gone. Geb is a small, clean access-control loss on a helper contract that assumed DSProxy context. Do not treat July’s AFX Trade figure as a 2 September event. This brief does not include exploit reproduction steps. Figures that are only at-risk are labeled as such.