A single wallet was able to formally request 98% of the Ampleforth treasury’s USDC balance through the protocol’s own governance process, exposing a DeFi governance gap that should concern anyone holding tokens with on-chain treasuries. The proposal drew zero votes and moved no funds, but the fact that it could be submitted at all is the real story for traders assessing governance risk.
What Happened
The proposing wallet submitted its request after receiving 87,238 FORTH of delegated voting power, enough to clear the threshold required to put a proposal on-chain. The proposal sought to move the overwhelming majority of the treasury’s USDC to an address the proposer controlled.
In the end the action failed harmlessly. It ended with zero votes in favor and no transfer executed, meaning the treasury was never actually at risk of being drained. But the episode demonstrated that the barrier to launching a hostile proposal was low enough for one delegated wallet to attempt a near-total treasury grab.
Governance-layer risk has been a recurring theme in DeFi this year, from contentious DAO votes to disputes over locked user funds, as we covered in our reporting on a lender’s bad-debt standoff.
What It Means for Traders
Governance is a real attack surface, not an afterthought. A protocol can have flawless smart-contract code and still be vulnerable if its voting mechanics let a small amount of delegated power put dangerous proposals in front of holders. Traders evaluating a governance token should look as hard at proposal thresholds and quorum rules as they do at the underlying contracts.
Delegation deserves particular scrutiny. Many holders delegate voting power and then stop paying attention, which concentrates influence in ways the token distribution alone does not reveal. When enough idle delegation pools in one place, the practical control of a treasury can diverge sharply from its nominal ownership.
The reassuring detail is that the system’s checks worked: the proposal died for lack of support. But relying on an engaged voter base as the last line of defense is fragile. Tokens whose treasuries are large relative to their active governance participation carry a quieter risk that rarely shows up in price until something breaks.
The Bigger Picture
On-chain treasuries were meant to make protocols more transparent and community-controlled, but transparency also means every weakness is visible and testable by anyone. As DeFi treasuries grow into the hundreds of millions, the incentive to probe governance mechanics grows with them, and defenders have to get every parameter right while attackers only need one gap.
The broader design conversation is shifting toward stronger safeguards: higher proposal thresholds, timelocks, guardian roles, and even private voting to reduce coordinated pressure, an idea we explored in our look at private on-chain voting research. Each adds friction, and the trade-off between security and open participation is far from settled.
Exclusion and control fights are becoming routine across DAOs, as seen in recent Arbitrum governance disputes. The Ampleforth case fits a pattern where the hardest problems in DeFi are increasingly social and procedural rather than purely technical.
Conclusion
A failed attempt to claim nearly an entire treasury is a warning shot, not a catastrophe, and it landed exactly where DeFi is most exposed. Traders should factor governance design into their risk assessment of any treasury-backed token, watch how much voting power sits idle in delegation, and treat active, well-structured governance as a feature worth paying for rather than a box already checked.
This article is informational only and does not constitute financial advice.


















