Ethereum DeFi Protocol Term Finance Hit by $8.5M Governance Attack

iconAMBCrypto
Share
AI summary iconSummary
On August 23, 2026, Ethereum-based DeFi protocol Term Finance suffered a $8.5M governance attack. The attacker bought a majority of governance tokens at a low cost, submitted and approved malicious proposals, and drained 2,843 ETH and 1.68 million USDC. The stolen assets were later swapped for 1.68 million DAI. The incident highlights the risks of DeFi exploit vulnerabilities and the need for a swift protocol update to prevent similar attacks.

Another day and yet another blow to crypto security. On the 23rd of August, Term Finance, a DeFi lending & borrowing protocol on Ethereum [ETH], was attacked.

Rather than directly breaking into the protocol through a smart contract bug, the illicit actor took advantage of the weakness in Term Finance’s DAO governance system.

Term Finance
Source: Term Finance/X

How did the hacker drain millions in ETH?

A relatively small amount of Term’s governance token was actively available in the market. Using this as an opportunity, the wrongdoer bought a large enough portion of the governance tokens at a low cost to gain majority voting power.

AD

Soon after the attacker got enough votes for approval, they simply went ahead and submitted and approved malicious governance proposals. This, in turn, gave the attacker control over Term Finance’s vaults, which hold users’ assets.

But before that, the attacker reportedly funded the operation with 2 ETH sourced through Tornado Cash. This caused a drain of approximately $8.5 million from Ethereum. 2,843 ETH, worth $6.87 million, alongside 1.68 million USDC were compromised. The attacker swapped those tokens for roughly 1.68 million DAI.

2026 becomes the worst year for Ethereum

A recent security report from Blockaid uncovered that in H1 2026, crypto theft and fraud losses exceeded $1 billion. Wherein, Ethereum accounted for the largest share of losses, worth approximately $332 million.

Losses by chain
Source: Blockaid

Ethereum’s losses were largely driven by smart contract and application-layer exploits, including vulnerabilities in bridges, privileged accounts, and protocol logic.

ETH was not spared

This was in line with AMBCrypto’s recent report on the Verus-Ethereum Bridge hack, which was attacked for the second time in July, with attackers draining approximately $7.54 million.

Back in May, nearly $11.58 million was compromised in a similar attack. This repeated attack has further raised questions about whether the earlier vulnerability was fully fixed.

All this happened as the price of Ethereum, which was trading around $4k in the middle of January, was down to $2412 at press time.

In a year, ETH has declined by 48.9% as per CoinGecko’s yearly data, thanks to attacks, regulatory uncertainty, geopolitical tensions, Fed rate cuts, and a lot more.


Final Summary

  • The offender bought a large enough portion of the governance tokens at a low cost and got access to majority voting power.
  • In H1 2026, Ethereum accounted for the largest share of funds lost in crypto frauds, with $332 million.
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.