Term Labs Suffers $8.5M Governance Exploit Affecting Vaults

24-Aug-2026 mpost.io
Term Labs Suffers $8.5M Governance Exploit Affecting Vaults

Term Labs, the decentralized finance (DeFi) protocol behind fixed-rate lending platform Term Finance, suffered a severe governance exploit on August 23 that drained approximately $8.5 million from its vaults.

Blockchain security firms PeckShieldAlert and CertiK Alert confirmed the losses, noting that the attacker currently holds roughly 2,843 ETH and approximately $1.6 million in DAI at a single address. On-chain records indicate that the attacker’s wallet was initially funded with 2 ETH through the cryptocurrency mixer Tornado Cash.

The root cause of the breach was a critical vulnerability in Term Labs’ governance structure, where voting power was insufficiently protected against economic capture.

According to a technical breakdown published by Go Plus Security, the attacker acquired absolute governance control for merely 0.5 ETH. The exploit began with a swap of approximately 0.5 ETH into 0.485 tmvETH, which was subsequently deposited into the Yearn/Governance wrapper to mint an equivalent amount of gtmvETH—granting immediate and disproportionate voting rights.

The attacker then self-submitted and self-approved proposalId=5 without meaningful opposition. After a six-day waiting period, the proposal was executed, bypassing the Zodiac Delay module’s cooldown and expiration safeguards. This manipulation allowed the attacker to register a malicious strategy, alter debt parameters, and vacuum the vault’s WETH holdings into a pre-deployed contract before routing the stolen funds to their own address.

Protocol Response and Governance Accountability

In a public statement, Term Labs acknowledged the incident, stating: “We are aware of a governance exploit impacting Term vaults. We will share more details once it has further investigated.”

The team clarified that the underlying Term protocol and its direct borrowing and lending markets were not affected by the breach. As an immediate containment measure, all Term Meta Vaults were permanently shut down, DAO governance roles were revoked, and further deposits were irreversibly disabled—though withdrawals remain open for users.

The team is coordinating with external security firms on remediation and recovery, noting that “if a shortfall remains, we will explore paths to address it.”

The incident raises serious questions about Term Labs’ security posture, particularly given a prior oracle failure in April 2025 that triggered unintended liquidations totaling approximately 918 ETH.

Although the protocol recovered 556 ETH and reimbursed affected users—reducing the net loss to 362 ETH—that event prompted public pledges of third-party validation for critical updates and greater governance transparency. The latest exploit, which required minimal capital to execute, suggests those commitments failed to prevent a fundamental governance vulnerability.

The post Term Labs Suffers $8.5M Governance Exploit Affecting Vaults appeared first on Metaverse Post.

Also read: Samsung Electronics Stock Falls 9% After Shareholder Return Plan Disappoints
WHAT'S YOUR OPINION?
Related News