On August 23, 2026, fixed-rate lending protocol Term Finance lost approximately $8.5 million after an attacker executed a hostile governance takeover. Bootstrapped with just 2 ETH from Tornado Cash, the attacker acquired a supermajority of Term Finance's low-float governance token to pass malicious proposals. This allowed them to drain 2,843 ETH and 1.68 million USDC from the protocol's strategy vaults. Security firms PeckShield and CertiK confirmed the exploit targeted voting mechanics rather than smart contract code, highlighting a rising industry pattern of governance exploits.
Story comments
Loading comments…