An attacker drained $8.5 million from Term Finance’s lending vaults on August 23 by taking over the DeFi protocol’s own governance vote, not by exploiting a flaw in its code.
- The attacker seized majority control of Term’s governance vote, then withdrew 2,843 ETH and 1.68 million USDC, worth about $8.5 million combined.
- The attack wallet was funded with 2 ETH routed through Tornado Cash, and the stolen USDC was swapped into a similar amount of DAI.
- It is the fourth governance takeover to hit a DeFi protocol since early June, matching a pattern the security firm Blockaid had already documented in three earlier attacks.
Why It Matters
Term’s governance token trades on thin liquidity, and the attacker used that to build a majority stake cheaply, then passed a proposal handing itself control of the protocol’s vaults. By the time Term Labs, the company behind the protocol, caught it, the attacker held all four of Term’s five USDC strategy vaults and about 91% of its Ethereum Meta Vault.
From there, the attacker withdrew the ETH and USDC. The wallet, identified by the security firm CertiK, had been funded with just 2 ETH from Tornado Cash, the mixing service commonly used to obscure where stolen funds move next.
The Same Playbook, Four Times Since June
Term Finance is not the first protocol to fall this way this summer. Blockaid tallied about $22 million in losses across seven protocols hit by governance takeovers between June 9 and August 6, and detailed three of them by name: an Aragon-based project called Token of Power lost $1.59 million on June 9, the Solana rewards platform BonkDAO lost about $20 million on July 6 after an attacker spent $4.4 million buying voting tokens, and BarnBridge lost $777,000 on July 15 to an attacker whose entire voting position cost around $600.
In each case, Blockaid found the same underlying weaknesses: voting thresholds set too low, no timelock between a proposal passing and taking effect, and governance systems wired directly into powers strong enough to move user funds. Term’s own vault-control numbers match that description closely.
What Term Labs Has Said
Term Labs acknowledged the exploit in a statement, saying only that it was
aware of a governance exploit impacting Term vaults
and would share more details once its investigation was further along. The company has not said whether it plans to compensate affected users or change how voting power translates into control of its vaults.
Until then, Term Finance sits alongside three other protocols that lost money this summer to a failure mode security researchers had already described in detail.
Disclaimer: Cryip's content is strictly for educational and informational purposes and does not constitute financial, legal, or investment advice. Cryptocurrency involves significant risk, and readers assume full responsibility for their own financial decisions. Asset references are never endorsements.
To make complex crypto topics accessible to readers at all experience levels, our team uses AI tools strictly to refine language, correct grammar, and simplify terminology. AI is never used to draft facts, source information, or form conclusions. Every article is fact-checked and approved by a human editor before publication. Read our full AI Use & Content Policy.











