Ampleforth's governance system is about to be tested by a proposal that would hand nearly its entire liquid treasury to an address that did not exist a week ago. Filed as Proposal 54 under the title “Observatory for SPOT – Completed-Work Treasury Grant,” the measure asks the DAO to release 2.5 million USDC — almost all of the treasury's available cash — to a single recipient, justified as payment for a completed SPOT ecosystem analytics tool that the DAO never commissioned through its normal grant process. SPOT is Ampleforth's bond-like stablecoin product, built on top of the protocol's elastic-supply AMPL token, and the treasury being targeted is the same pool of funds the DAO relies on to pay contributors and fund further development of both products.
The proposer's wallet, a newly created externally-owned account with a transaction nonce of zero, disclosed holding 87,238 FORTH tokens split across two addresses — comfortably above Ampleforth's 75,000 FORTH proposal threshold, which is all it takes to put a measure like this up for a vote in the first place. Clearing it is a higher bar: the approval threshold sits at 600,000 FORTH. But with FORTH trading near $0.27 at the time security researchers flagged the proposal, roughly $160,000 worth of tokens would be enough to assemble a winning vote, a gap that has become a recurring soft spot across low-float governance tokens attached to concentrated treasuries.
Voting opened at 05:22 UTC on September 14 and is scheduled to close at 23:04 UTC on September 16, giving the DAO roughly 42 hours to organize opposition. As of the most recent check, no votes had been cast in either direction, and the funds remain untouched in the timelock. Ampleforth's official channels had not issued a public statement addressing the proposal in the hours after the alert first circulated, leaving token holders to rely on third-party security monitoring rather than an official warning to know the vote was even live.
The mechanics here are not new. Security researchers have increasingly flagged governance systems where the cost of assembling a winning vote is far lower than the treasury value at stake, turning the proposal-and-vote process itself into an attack surface rather than a safeguard. A dormant escrow contract at Notional Finance was drained for $1.7 million earlier this year through an overflow bug nobody had patched, and a separate exploit cost More Markets $9.3 million when an attacker found a hole tied to an Ankr liquid staking token.
Related: Term Labs Loses $8.5M as Attacker Buys Governance Vote to Drain Vaults
What distinguishes the Ampleforth case so far is that it has been caught before execution rather than after. Proposal attacks of this kind typically succeed because treasury teams and token holders are not watching governance forums closely enough to notice a suspicious filing before the voting window closes, which is exactly the gap the 42-hour runway is now testing. Ampleforth's treasury has otherwise stayed relatively quiet this year compared with protocols that have seen funds drained through smart contract bugs — an incident closer in kind to Moonwell's oracle exploit on Base — which makes a governance-layer attack a different kind of test for a protocol that has otherwise avoided the exploit headlines.
For now, the outcome depends entirely on turnout. If FORTH holders who oppose the transfer vote in sufficient numbers before Wednesday's close, the proposal fails and the treasury stays intact. If they don't, Ampleforth will have demonstrated in the most direct way possible how little capital it can take to move millions out of a DAO treasury when nobody is watching the ballot. Either way, the episode is likely to renew calls within DeFi governance circles for higher proposal thresholds, mandatory delay windows, or automated alerts that flag unusually large transfer requests before they ever reach a public vote.
