A single wallet attempted to drain approximately 98% of the Ampleforth (AMPL) treasury’s USDC balance by exploiting a loophole in the protocol's governance delegation system. The proposer was able to submit the request after receiving 87,238 delegated FORTH tokens, meeting the minimum threshold required to put a proposal to a vote. Fortunately for the protocol, the action failed to gain any traction, ending with zero votes in favor and no funds being transferred from the treasury.
This incident underscores a significant 'governance gap' that persists in the 2026 DeFi landscape, where the ability to propose major treasury changes does not always require a substantial financial stake or broad community consensus. In this case, the use of delegated power allowed a single actor to bypass traditional barriers, potentially putting millions of dollars in stablecoin reserves at risk. While the Ampleforth community successfully ignored the malicious proposal, the ease with which it was filed has raised alarms regarding the security of DAO-managed assets.
From a regulatory perspective, this event provides further ammunition for US authorities, including the SEC and CFTC, who have been pushing for stricter oversight of decentralized governance structures. Regulators often cite such vulnerabilities as evidence that DeFi protocols require centralized accountability or 'circuit breakers' to prevent treasury depletion. For US-focused investors, this serves as a reminder that governance participation is not just a right but a security necessity to protect protocol solvency.
Market implications for the FORTH token remained relatively neutral following the news, as the failure of the proposal prevented a liquidity crisis. However, the event may lead to a 'security discount' on protocols with similar delegation thresholds. Moving forward, readers should watch for an official governance update from the Ampleforth team to increase proposal thresholds or implement multi-signature safeguards. Additionally, watch for any legislative response regarding the legal liability of token delegates who support or facilitate malicious treasury requests.