Web3 Daily Exploits — 03 Sep 2026: Quiet window with governance alert and small drain

No major new exploits confirmed in the last 24 hours. Smaller alerts include a Yam Finance governance takeover attempt and a ~6 ETH GebProxyActions drain on Ethereum.

Web3 Daily Exploits — 03 Sep 2026: Quiet window with governance alert and small drain

No major new exploits were confirmed in the last 24 hours after checks of DefimonAlerts, CertiKAlert, Phalcon, GoPlus, SlowMist, PeckShield, BlockSec, Lookonchain, ZachXBT and related feeds. Activity centered on a dormant-protocol governance alert and one small confirmed drain.

The window remains relatively quiet following the late-August cluster of larger incidents including Tectonic, Injective and Term Finance.

Yam Finance governance takeover attempt (unconfirmed outcome)

Defimon Alerts flagged a governance proposal on the dormant Yam Finance protocol. An attacker self-delegated approximately 504k YAM (roughly 3.3% of supply, sufficient for quorum) and submitted YamGovernorAlpha proposal #45 with an empty description. The sole action sets the pending admin of the YAM Timelock to the attacker address. If the proposal passes and executes, the attacker can accept admin and control protocol contracts and the DAO treasury.

Approximately $337k remains at risk in related pools. The protocol is largely inactive. Holders of delegated YAM were urged to vote against before the relevant block. Status: proposal live at time of alerts; no confirmed execution or successful takeover reported in the window. Confirmed alert by Defimon; outcome unverified as of this brief.

Relevant: https://x.com/DefimonAlerts/status/2095019159847313766

SlowMist reported a loss of approximately 5.9436 ETH linked to the GebProxyActions contract. The root cause was missing caller access control on quitSystem. A prior user call made directly (instead of via DSProxy delegatecall) recorded the GebProxyActions contract itself as owner of certain SAFEs. The attacker then called quitSystem directly, bypassing the safeAllowed check in GebSafeManager and transferring collateral.

Attacker: 0xb929c7215c0ec8ebad5fbf73b1da63bccfff1896. Victim collateral positions on CollateralJoin1. Confirmed small loss by SlowMist monitoring. No broader protocol impact reported. Live loss remains the drained ETH (approximate USD value under $15k at prevailing prices).

Relevant: https://x.com/SlowMist_Team/status/2094986310683705835

Also noted

  • Full Sail (Sui) announced shutdown and user reimbursement following an earlier ~$91k Switchboard oracle exploit; update circulated in the window.
  • Continued discussion and technical breakdowns of the Injective binary-options settlement incident from late August (approx. $4.8–4.9M bridged), with chain-halt and patch details.
  • Coldcard-related funds movement noted in secondary reporting.

Sources & references

Editor’s note: Strict 24-hour window applied. No major new confirmed multi-million losses first reported in this period. Always verify on-chain and official channels. This is a site post only.