Term Labs Loses $8.5M in Governance Exploit as Attacker Seizes Strategy Vaults

iconCryptoBriefing
Share
AI summary iconSummary
Ethereum news broke on August 23 as Term Labs, developer of Term Finance, reported an $8.5 million governance exploit. An attacker gained enough voting power to seize control of four USDC strategy vaults and nearly 91% of the Ethereum Meta Vault. Around 2,843 ETH and 1.6 million DAI were drained to a single wallet. The attacker used just 2 ETH from Tornado Cash to start. Term Labs confirmed the exploit did not target code but governance mechanics. This is the second loss for the protocol, following a $1.5 million incident in May 2025. Altcoins to watch may include those linked to governance attacks.

Term Finance, the Ethereum-based fixed-rate lending protocol built by Term Labs, lost approximately $8.5 million after an attacker quietly accumulated enough voting power to seize control of its strategy vaults. The exploit, confirmed by security firms CertiK and PeckShield, resulted in roughly 2,843 ETH and approximately 1.6 million DAI being drained to a single wallet address.

How the exploit worked

The attack on August 23 was a governance manipulation rather than code exploitation. The attacker managed to gain 100% voting control over four out of five USDC strategy vaults and roughly 91% control of the Ethereum Meta Vault. With that supermajority in hand, the attacker voted to drain the funds, directing them to a single address beginning with 0xD5183.

The initial funding reportedly came from just 2 ETH sourced through Tornado Cash. From that modest seed, the attacker bootstrapped enough voting power to commandeer vaults holding millions in user deposits.

Advertisement

Term Labs acknowledged the governance issue publicly and indicated the need for further investigation. The protocol’s team has been careful to distinguish this from a smart contract vulnerability.

Not Term Labs’ first brush with losses

In May 2025, Term Finance lost approximately $1.5 million due to an oracle decimal mismatch that occurred during a routine upgrade. That error was non-malicious and the funds were eventually returned.

The company raised $2.5 million in seed funding in early 2023 under the leadership of founder and CEO Dion Chu. The protocol’s value proposition has centered on bringing TradFi-like fixed-rate structures to on-chain lending through over-collateralized, fixed-income-style lending products.

The governance problem DeFi keeps ignoring

Unlike flash loan exploits or reentrancy bugs, governance attacks don’t require any technical wizardry. They exploit the democratic machinery that decentralized protocols use to manage treasuries and upgrade parameters. Term Finance’s vault structure apparently didn’t have sufficient guardrails to prevent a hostile takeover of voting power.

This exploit passed through audited contracts without breaking a single line of code. The vulnerability was architectural, sitting at the intersection of tokenomics, voter apathy, and insufficient access controls on vault management functions.

For depositors who lost funds in this exploit, the path to recovery is unclear. Unlike the May 2025 oracle mismatch, where the error was internal and funds were recoverable, this attack involved an external actor who routed their seed capital through Tornado Cash, a tool designed specifically to sever the on-chain link between sender and receiver.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.