Recent FORTH Activity and Next Steps

On the evening of September 12th, the Fragments development team received an alert from ScopeLift about a possible attack on the DAO. This was confirmed by Decurity on X, and soon news spread within the ETHSecurity Community on telegram.

Two proposals (1, 2) were submitted onchain. The first contained a payload that transferred 2.5M USDC from the DAO treasury to an unknown EOA address. The second approved spending of 3.5M USDC and 3.5M FORTH, and also set AMPL’s monetary policy to a different unknown EOA.

Why We Consider These Proposals to Have Malicious Intent

On the face they seem innocuous. The first suggests payment for work completed. The second describes itself as a growth and liquidity initiative from the Amplifiers group.

The Forth DAO is an onchain organization with years of operating history and norms. The process of DAO governance is thoroughly documented, and includes a number of steps that DAO actions are expected to go through. None of these steps were followed before the binding onchain submission.

None of these payments were negotiated ahead of time in any community channels. There was no request for work, no indication of any work being done beforehand, and no check for community demand for the deliverables. This, along with the size of the payouts being nearly the entirety of the liquid DAO treasury, show these not being simply payments, but a full drainage of assets.

Had the second proposal passed, control over AMPL’s rebases would have been in the control of an unknown party. The AMPL token is immutable and enforces that rebases are proportional across all holders, but the monetary policy determines supply changes and scheduling. Tampering with the global supply could potentially allow an attacker to manipulate markets to extract funds from the broader ecosystem, not just FORTH holders.

The proposals were submitted on the weekends and also in such a way that voting snapshots started in the middle of the night US time (2:25am PT and again 5hrs later). It’s clear that these actions were meant to be submitted at times most inconvenient to anyone paying attention.

Additional onchain details which showed themselves over the course of events are also revealing, but these will need to wait for a proper post-mortem when everything has fully settled. This does not appear to be a typical takeover attempt by an operator looking to shepherd the ecosystem in a new direction.

To the proposers: Know that at least 3 security organizations have their eyes on you. Proceed wisely. If there is no ill intent, please follow the normal governance process for community review and you will find open ears.

Next Steps

After getting an initial assessment of the situation, the Fragments team decided to submit a counter proposal to defend sustainable operation. The time period here was important, in order to get ahead of any subsequent actions. This post is meant to provide more background information and seek community input for next steps.

We are past the two malicious proposals being able to execute. This counter-proposal is now in play, but the threat of malicious votes is still present. The first was canceled by the proposer. The second was cancelled by Fragments. It’s not clear if the second proposer meant to cancel as well or simply made a mistake.

This counter-proposal from Fragments, if passed, will transfer ownership of the DAO Timelock to the Kennel Club multisig. The Kennel Club multisig is an ancillary 2-of-n multisig address with known signers. The intent is to hold this temporarily until the full community can determine next steps safely, without the overhanging threat of DAO hijacking.

The Fragments team recommends the community rally in support of this proposal. Existing FORTH holders, please ensure you are delegated in full as soon as possible. You can do so very easily here. We do not recommend interacting with the FORTH markets, so just delegate what you currently have. The voting period starts early tomorrow morning.

Future

Given AMPL’s history and time in market, it’s possible that AMPL no longer needs direction from a surrounding DAO. One option would be to safely, and in an organized manner, wind down the FORTH DAO to the community to remove such risks as we faced last weekend. This would occur only if there is community support, and details would be determined with community involvement.

If there is not support for this, DAO operations could of course be resumed, provided proper security guarantees could be met.

However, this is a conversation for another day. In the meantime, let’s work to safeguard what we currently have.

--Fragments Dev Team

2 Likes

Another detail worth mentioning is that these proposals were submitted at a time when the indexer on the governance interface was down. Nothing was visible until we worked with the Tally/Cactus team to get the indexer back up. Had it not been for active onchain monitoring, no one would have known these were in the governance queue.

1 Like

The proposal passed, and the KC accepted the new admin role of the Timelock. Please note this means the 2-day security delay is still enforced for any transfer of treasury assets or changes to managed contracts.

We’ll follow up with a more specific proposal plan within 30-days.