Web3 Daily Exploits — 14 Sep 2026: Yam $121k Gov Drain + Spiral 10.7 ETH

Yam proposal #45 finished as a realized ~$121k UMA-farm pull. SlowMist printed a same-block ~10.7 ETH (~$26.8k) spot-price borrow on SpiralHookV2. Ampleforth Governor Bravo #54 was cancelled on-chain.

Web3 Daily Exploits — 14 Sep 2026: Yam $121k Gov Drain + Spiral 10.7 ETH

Required monitors were checked through the 14 Sep 2026 America/Panama cutoff: DefimonAlerts, CertiKAlert, Phalcon, GoPlusSecurity, SlowMist_Team, PeckShieldAlert, BlockSecTeam, Lookonchain, ZachXBT, CyversAlerts, Immunefi, and rekt.news. Two confirmed protocol-side money movements landed in this slice. Combined live loss scored on this card is approximately $148k: Defimon’s ~$121k Yam print (48.15 ETH cashed out via FixedFloat after the executed GovernorAlpha takeover) plus SlowMist’s ~10.7 ETH / $26,800 SpiralHookV2 print. Ampleforth Governor Bravo proposal #54, flagged yesterday as a $2.5M USDC at-risk item, was cancelled on-chain in this window and is not live loss. Orb3’s node-716 assertion remains unwithdrawn.

Yesterday’s Ampleforth-pending and Orb3-pending items stay on the 13 Sep brief except where this cutoff adds a hash or a status change. Zentra’s first-report ctUSD drain stays on 12 Sep; the 14 Sep 12:00 UTC bounty reply deadline passed with no new official Zentra post located in the required-monitor set. Symbiosis’s 20% white-hat window was written through 13 Sep; no new return hash was published. Edgeless node 228 and Liquid’s unpaid ~598.5 BTC are unchanged. CertiKAlert, Phalcon, PeckShieldAlert, BlockSecTeam, and CyversAlerts published no new first-report smart-contract drain with a fresh loss figure after the 13 Sep brief cutoff. All dollar figures below are amounts still outside the affected party’s control unless a return transaction is cited.

Yam Finance / GovernorAlpha proposal #45 — Ethereum — Confirmed drain (UPDATE)

What happened: At 04:33 UTC on 14 Sep 2026, Defimon published the first required-monitor confirmation that Yam GovernorAlpha proposal #45 had been executed and that Timelock admin had moved. The same actor then cut the Timelock delay from five days to twelve hours, took the gov role on Yam’s old UMA farming contracts, called _settleExpired() on expired uGAS positions, and pulled the released collateral through the gov-only masterFallback path. First public attempt was 2 Sep (Defimon + this desk). Funds had not moved in that earlier window. They moved in this one.

Protocol / chain / asset: Yam Finance on Ethereum. Realized assets named by Defimon: 23.50 WETH + 763 UMA from UMAFarmingMar (uGAS-MAR21) and 24.59 WETH from UMAFarmingFeb (uGAS-FEB21). Combined proceeds cited as 48.15 ETH, sent out through FixedFloat. The 2 Sep at-risk print was ~$337k across remaining protocol and treasury-linked contracts, including the Yam WETH pool. This card scores only the extracted stack Defimon published today, not the leftover at-risk remainder.

Loss: ~$121k per Defimon. 48.15 ETH cashed out. No return transaction identified. Do not add the original $337k at-risk figure on top of the $121k; the $121k is the realized subset.

Attack type: Hostile governance / low-quorum takeover of a dormant GovernorAlpha, then privileged settlement of leftover UMA farm collateral. Not a new math bug in the farming contracts.

Technical details: The 2 Sep record still holds for the setup: address 0x26881EacC00Bcccd7c4ebE14BD7840dD989Bf982 bought ~504k YAM, self-delegated just over quorum, and submitted proposal #45 with an empty description. The single action called setPendingAdmin on Timelock 0x8b4f1616751117C38a0f84F9A146cca191ea3EC5. After execution and acceptAdmin, the same path shortened the delay and re-pointed gov on the expired UMA farms. Defimon: masterFallback lets gov make an arbitrary call from those contracts. Farming contracts resolved from Defimon’s shortlinks: UMAFarmingMar 0xffb607418dBEaB7A888e079A34Be28A30d8E1DE2; UMAFarmingFeb 0xc0AE1e1e172ECD4C56fD8043FD5Afe5a473E9835. No official @YamFinance statement was located in this cutoff. Independent replies on the Defimon thread noted the farms were expired leftover surface; those comments are not a second loss print.

Explorer links:

Status: Confirmed realized drain by Defimon. Admin change complete on the named Timelock path. Extracted stack not reported returned. Residual Yam treasury or pool balances are not re-scored here without a new desk print.

Sources: https://x.com/DefimonAlerts/status/2099355802909691999, original attempt https://x.com/DefimonAlerts/status/2095019159847313766

Spiral / SpiralHookV2 — Ethereum — Confirmed

What happened: At 08:11 UTC on 14 Sep 2026, SlowMist published a TI alert for a ~10.7 ETH loss against @spir8l_com. SlowMist Hacked later listed the same event dated 2026-09-14 with a $26,800 dollar print and the attack method “Price Manipulation.” A third-party reply on the SlowMist thread placed the bundle in block 25,974,146 and described six follow-up transactions as EIP-7702 Type-4 calls used to produce distinct tx.origin values. That reply is not a required monitor; the loss figure and root-cause sentence used on this card are SlowMist’s.

Protocol / chain / asset: SpiralHookV2 on Ethereum, Uniswap V4 pool-manager pricing. Official docs for the canonical Ethereum deployment name SpiralHookV2 at 0x1725577dC9B1ee2D95dB49c2193226471594aacc, matching SlowMist’s vulnerable-contract line. Asset taken: ~10.7 ETH. @spir8l_com posted product notes through the same morning and did not publish an incident statement in the required-monitor set before cutoff.

Loss: ~10.7 ETH. SlowMist Hacked dollar print: $26,800. Card uses both as the same incident. No return transaction identified.

Attack type: Spot-price collateral valuation without TWAP or deviation limits, plus a same-block swap guard keyed by tx.origin rather than a shared attack context. Not an access-control print in SlowMist’s write-up.

Technical details: SlowMist: SpiralHookV2.borrow() reads Uniswap V4 pool spot via poolManager.getSlot0() to value collateral. The protocol’s noSameBlockSwap guard is keyed by tx.origin, so six different EOAs were used to keep the pumped price in-block and borrow against the inflated collateral. Addresses named by SlowMist: attacker EOA 0x859E69A29244A10800A34eE66919426C02aFa2f0; attack contract 0x0c23c8bc3b7c565f3f9f4ac691a4dc4275086f86; vulnerable hook 0x1725577dC9B1ee2D95dB49c2193226471594aacc. A representative transaction in block 25,974,146 (14 Sep 2026 07:17:59 UTC) shows the attack contract receiving ETH from the Uniswap V4 Pool Manager and pushing SPIRAL into the hook: 0x3172b1d4baf8d29cb2ecd74e3eb89c34d786290ce9f607a3c4edc136281d6fb2. That hash is an explorer match to the named contracts and block, not a substitute for SlowMist’s full seven-link set (those t.co targets were not expanded in this cutoff). A same-thread comment that the first EOA pushed 54 ETH into the pool is flagged unverified against SlowMist’s own text.

Explorer links:

Status: Confirmed by SlowMist. No official project containment note located on @spir8l_com at cutoff. Funds not reported returned.

Sources: https://x.com/SlowMist_Team/status/2099410818244968850, https://hacked.slowmist.io/

Ampleforth / Governor Bravo proposal #54 — Ethereum — Cancelled (UPDATE)

What happened: First report remains on the 13 Sep brief: a fresh proposer submitted Governor Bravo proposal #54 to send 2,500,000 USDC from the treasury as an “Observatory for SPOT completed-work grant.” In this cutoff two required monitors moved the status. At 04:35 UTC on 14 Sep, GoPlus independently reprinted the pending proposal, named the 87,238.546 FORTH voting-power stack, and said funds had not moved. At 04:43:35 UTC the on-chain cancel landed. At 07:29 UTC Defimon replied on the original Ampleforth thread: “Malicious proposal has been cancelled,” with the cancel hash.

Protocol / chain / asset: Ampleforth DAO on Ethereum. Target asset was 2,500,000 USDC behind Governor Bravo / timelock. FORTH cited by both desks: 0x77fba179c79de5b7653f68b5039af940ada60ce0.

Loss: $0 live. The $2.5M USDC at-risk figure is retired from the live column because the proposal was cancelled before an executable transfer.

Attack type: Malicious governance proposal against a low-threshold Governor Bravo. Not a smart-contract drain.

Technical details: Cancel transaction 0x0cd6b540d8027ec1e74b698b5bb0a06d1c02dc019e9e50b3154b5df05115c636 succeeded in block 25,973,374 at 04:43:35 UTC on 14 Sep. Method: cancel(uint256 proposalId) with proposalId = 54. From: 0x38cAaa5782BF8afF646403D567D76b016d5c24D8. To: Governor Bravo 0x8a994C6F55Be1fD2B4d0dc3B8f8F7D4E3a2dA8F1. GoPlus identified that from-address as the delegator that pointed 87,238.546 FORTH at proposer 0x730C97E793f6F7c476C6AeB3E1c3fDad4714dd82 nineteen minutes before submission, funded by relay 0x92fc19271fce6d48cd41a0eff6f5dd40f1090d72. The cancel therefore came from the same voting-power stack that cleared the propose threshold, not from a separately confirmed official Ampleforth ops key. No @AmpleforthOrg statement was located in this cutoff. GoPlus priced 600,000 FORTH quorum at ~$160k at $0.27, versus Defimon’s ~$132k at $0.22 yesterday; both are desk marks on an unexecuted proposal.

Explorer links:

Status: Cancel confirmed on-chain and by Defimon. Treasury transfer not reported. Official team statement still absent at cutoff.

Sources: https://x.com/DefimonAlerts/status/2099400145313935690, https://x.com/GoPlusSecurity/status/2099356365613593053, https://x.com/DefimonAlerts/status/2098990897924821329

Also noted

  • Orb3 / chainId 788988 L1 bridge (UPDATE, not re-scored): First-report forged assertion (node 716) remains on the 13 Sep brief. Confirmation still gated on L1 block 26,005,988 (~18 Sep). No Outbox withdrawal hash in this cutoff. Source: https://x.com/DefimonAlerts/status/2098986314670502077.
  • Edgeless Network L1 bridge (UPDATE, not re-scored): Fake assertion node 228, first reported 12 Sep, still cannot confirm before L1 block 25,999,225 (~17–18 Sep). No Outbox withdrawal in this cutoff.
  • Zentra Finance (UPDATE, not re-scored): First-report ctUSD reserve drain remains on the 12 Sep brief. The 14 Sep 12:00 UTC bounty reply deadline named in that post-mortem elapsed in this window. No new @ZentraFinance post was located after the 12 Sep rate-zero / re-pause note.
  • Symbiosis Bitcoin Bridge (UPDATE, not re-scored): First-report mint-and-dump remains on the 11 Sep brief. The 20% white-hat window cited through 13 Sep 2026 had no new return hash in this cutoff.
  • Liquid Network (UPDATE, not re-scored): ~598.5 BTC remains with the 6 Sep actor. No new return hash in this cutoff.
  • Lookonchain: Cumberland $PONS accumulation, a $MEME whale add, loracle $PONS/$CASHCAT short profit-taking, and a $STONK buy. Market-flow notes, not exploit first-reports.
  • ZachXBT: in-window posts were a medical-fund verification and a thread reply, not a protocol-drain first-report.
  • Immunefi: ENS audit-competition submissions closed and moved to evaluation. Not an incident.
  • CertiKAlert, PeckShieldAlert, Phalcon, BlockSecTeam, CyversAlerts, rekt.news: no new first-report smart-contract drain with a fresh loss figure after the 13 Sep brief cutoff.

Sources & references

Editor’s note: Card live-loss is this window’s confirmed realized protocol drains only (~$121k Yam + ~$26.8k Spiral). Ampleforth #54 is scored as a cancelled pending item with $0 live loss. Orb3 and Edgeless remain unwithdrawn assertions. Yam’s original $337k at-risk print is not added on top of the $121k extracted subset. White-hat and bounty claims are recorded as claims. No how-to or exploit reproduction steps. Verify explorers and official channels before acting on any alert.

Read more