Newsroom
23 August, 2026 / News / AI / Tags: vaults, attacker, governance, labs, protocol

DeFi protocol confirms governance exploit drained vaults holding ETH and stablecoins; security firms detail attacker control and fund movements
Term Labs, operator of the Term Finance decentralized lending protocol, confirmed on August 23 that a governance exploit had impacted its strategy vaults. Blockchain security researchers estimated the resulting loss at approximately $8.5 million in cryptocurrency assets.
The protocol specializes in fixed-rate borrowing and lending, primarily involving ETH. Its strategy vaults allocate deposited funds through programmed contracts. Term Labs stated it was investigating the incident and would provide further details after completing its review. The team has not yet confirmed the precise loss amount, identified every affected vault, or outlined any recovery steps.
Security analysis indicates the incident was not a traditional smart-contract code vulnerability. Instead, the attacker obtained sufficient voting power to pass proposals that redirected vault funds. Term Finance vaults allowed users to deposit assets for passive returns, with an optional step to wrap share tokens into governance tokens through the Aragon platform.
Most regular depositors did not perform this wrapping step. The attacker completed it and thereby secured outsized influence. On-chain data shows the attacker controlled four of the five drained vaults with 100 percent of the relevant governance tokens and roughly 91 percent of the Ethereum Meta Vault. Governance tokens held by the attacker were valued at only a few dollars, yet this was enough to dominate decisions amid limited participation.
The attacker submitted a proposal on August 17 containing actions that were not immediately visible to other participants. After a six-day waiting period, the proposal passed and enabled changes to vault parameters. Those changes permitted the transfer of reserves from several USDC lending vaults to addresses controlled by the attacker.
Researchers reported that the exploiter drained approximately 2,843 ETH, valued at about $6.87 million at the time of the transactions, along with 1.68 million USDC. The USDC was subsequently swapped for roughly 1.68 million DAI. The primary address associated with the attack held approximately 2,843 ETH and 1.6 million DAI after the transfers.
Initial funding for the attacker’s wallets consisted of 2 ETH received from Tornado Cash. The stolen assets remained in the identified wallet at the time of reporting and had not yet been further mixed or dispersed.
At the time of the incident, Term Labs reported more than $25 million in total value locked, with $3.92 million in active loans and $12.25 million held across its vaults. The drain significantly reduced the protocol’s available lending capacity.
Term Labs has not announced any pause of deposits, withdrawals, or governance functions. No reimbursement terms, recovery timeline, or technical postmortem have been released. The team has also not disclosed whether it has contacted the attacker, law-enforcement agencies, stablecoin issuers, or exchanges.
This marks the second notable loss for the protocol. In May 2025, Term Finance lost about $1.5 million due to an oracle decimal error during an upgrade; those funds were later recovered.
Security firms noted that governance mechanisms relying on optional token wrapping and low voter engagement can allow a single actor with modest capital to gain decisive control. Full details of the control path and any remaining safeguards will depend on the protocol’s forthcoming investigation findings.









