Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
Term Finance loses $8.5M after attacker buys governance votes for 2 ETH
00

Term Finance loses $8.5M after attacker buys governance votes for 2 ETH

Aug 24, 2026

On August 23, 2026, fixed-rate lending protocol Term Finance lost approximately $8.5 million after an attacker executed a hostile governance takeover. Bootstrapped with just 2 ETH from Tornado Cash, the attacker acquired a supermajority of Term Finance's low-float governance token to pass malicious proposals. This allowed them to drain 2,843 ETH and 1.68 million USDC from the protocol's strategy vaults. Security firms PeckShield and CertiK confirmed the exploit targeted voting mechanics rather than smart contract code, highlighting a rising industry pattern of governance exploits.

Term Finance governance takeover

  • ▪The attacker used the acquired voting power to pass malicious proposals that redirected and seized control of Term Finance's strategy vaults.
  • ▪On August 23, 2026, an attacker executed a governance takeover of the fixed-rate lending protocol Term Finance by acquiring a majority of its sparsely held DAO governance token.

Tornado Cash attack funding

  • ▪The attacker bootstrapped the Term Finance governance exploit with a seed funding of approximately 2 ETH withdrawn from the sanctioned Ethereum mixer Tornado Cash.
  • ▪The seed funding from Tornado Cash was used by the attacker to accumulate Term Finance's low-float governance token on the open market.

Vault drainage mechanics

  • ▪The impacted Term Finance vaults operated on Yearn V3 infrastructure with a custom governance framework built by Term Labs.
  • ▪Security firms PeckShield and CertiK confirmed the exploit targeted Term Finance's voting mechanics rather than any flaw in the underlying smart contract code.
  • ▪The attacker gained 100% voting control over four of Term Finance's five USDC strategy vaults and approximately 91% control over the Ethereum Meta Vault.

Eight million dollar loss

  • ▪The attacker drained approximately 2,843 ETH, worth about $6.87 million, and 1.68 million USDC from the Term Finance vaults, totaling roughly $8.5 million.
  • ▪All stolen proceeds from the Term Finance exploit were funneled to a single consolidation wallet beginning with the address 0xD5183.
  • ▪The attacker converted the stolen 1.68 million USDC into approximately 1.68 million DAI to make tracing and freezing the assets more difficult.

DeFi governance vulnerability pattern

  • ▪DefiLlama classified five incidents in 2026 as governance attacks, resulting in combined losses of approximately $25.1 million, including a $20 million BonkDAO drain in July 2026.
  • ▪The Term Finance exploit highlights a recurring DeFi vulnerability where low-float DAO tokens allow attackers to cheaply acquire governance influence to control high-value assets.

Term Finance security history

  • ▪Unlike the April 2025 incident where Term Labs committed to a full reimbursement plan, the August 2026 exploit has no misconfigured oracle to correct or protocol reserves to make depositors whole.
  • ▪In April 2025, Term Finance suffered a separate security incident where a faulty oracle update led to a loss of approximately $1.5 million in its tETH markets.

2 sources

Cryptobriefing
Term Finance loses $8.5M after attacker buys governance votes for just 2 ETH
View source article
Cryptotimes
Term Finance Loses $8.5M After Attacker Hijacks DAO Governance Vote
View source article

Story comments

Loading comments…

Related Projects

EthereumETH

Topics

DeFi security exploitsEthereumDeFi lendingDeFiDAOs & governance