There’s a bug in the Yam Finance protocol, the day-old yield farming mash-up project delivering the latest astronomical annualized returns in the booming DeFiDeFi industry.
Yam Finance tweeted the discovery earlier today, alerting users to an error leading to unintended tokentoken supply growth that would benefit the governance-controlled reserve. The extra tokens accumulated would capture an increasing amount of the overall Yam market cap, reducing the value of all other user’s tokens over time.
We have found a bug in the rebasing contract, please read below.
All funds in staking contract are safe, as this is an unrelated part of the protocol.
In response, developers are asking early adopters to put their governing power to use implementing a temporary fix, requiring at least 175,000 votes to activate the proposal. It’s another early stress test of the power of distributed governance, and an example of developers working together with a community that has taken root literally overnight.
The bug involves the issuance of Yams during “rebase” events, when the total supply of the token is changed in a mechanism designed to keep the price stable over time. Notably, Yam developers were clear up front that while Yam was constructed largely using well known, previously audited smart contractssmart contracts, the specific Yam design had not itself been put to an audit.
Yam was launched yesterday via a Medium blog post and has already attracted close to $400 million in locked value, according to analytics platform Nansen. The protocol combines elements of yEarn.finance and Synthetix smart contracts and an elastic supply inspired by Ampleforth in an experiment in cutting edge DeFi paradigms. The value of Yams is pegged to $1 USD, which means the total supply of Yam tokens will increase or decrease in response to prices higher or lower than one dollar in “rebase” events.
If Yams are trading for more than a dollar, the twice-daily rebase event will increase the supply of tokens proportionally across each user’s Yam balance; increasing the supply, in theory, lowers the value of each individual token. This is because the total value of the supply, as measured by the token’s market cap, is distributed among a greater total number of tokens.
No one knew Yam Finance before yesterday at 5pm UTC when the team tweeted its first and only Medium article explaining the “project” they launched two hours later.
The token was born with “zero value” and without an audit, as the Medium post specified. Still, yield farmers couldn’t get enough YAMs and according to Etherscan, $90M USD was deposited in the protocol within the first 90 mins, while YAM price jumped to ~50 DAI—which sounds a lot more impressive when you take into account it was suppo...
If Yams are trading for less than a dollar, rebase events will reduce the supply of Yams to increase the price. Rebase events are limited to changing the supply by 10% at a time, so extra Yam generated would automatically be contributed to the community governance pool.
In response to the bug, Yam holders are being asked to vote via the Etherscan contract interface. The fix will halt the rebase function until developers are able to construct a more permanent fix, and will burn all Yam tokens currently in the governance reserve. Two votes will be required to activate the fix. The first will require 35,000 Yams to bring the proposal for a vote, while the second will require 140,000 Yams to activate the new code after a 12.5 hour waiting period.
Hundreds of millions of dollars are at stake within Yam Finance, but more important might be the test of whether the brand new community can pull together and follow its developers lead.
Disclaimer
The views and opinions expressed by the author are for informational purposes only and do not constitute financial, investment, or other advice.
Daily Debrief Newsletter
Start every day with the top news stories right now, plus original features, a podcast, videos and more.
Raydium's native token, Ray, rose sharply on Monday, driven by the decentralized exchange's "deep liquidity," even as it faces stiff competition from the recently launched rival PumpSwap, according to one core contributor.
As the 133rd largest crypto by market capitalization, Ray is trading at about $1.95, according to crypto data provider CoinGecko.
It is up 25% over the past 14 days, recovering ground lost earlier this year as Pump.fun grew more popular.
Ray had dropped 7.6% over a five-minut...
Real-world asset have notched a combined $10.216 billion in total-value locked on decentralized platforms as digitizing traditional financial instruments becomes increasingly popular in Web3.
The total is spread across 79 DeFi platforms, with the top three RWA protocols accounting for 36% of that total-value locked, according to DeFiLlama. The top three RWA protocols—Maker RWA, BlackRock BUIDL and Ethena USDtb—hold $1.298 billion, $1.232 billion and $1.182 billion in TVL, respectively.
Analyst...
Ethereum real-world asset platform Zoth has suffered an attack that resulted in the loss of $8.85 million. Security experts believe the hack, the second suffered by the company in a month, came about as the result of a private key leak.
On Friday morning, a Zoth proxy contract was upgraded by what security firm Cyvers called a "suspicious address.” Soon thereafter, $8.85 million worth of stablecoin USD0++ was transferred out of the proxy contract into the attackers wallet before all funds were s...