Term Finance, the Ethereum-based fixed-rate lending protocol built by Term Labs, lost approximately $8.5 million after an attacker quietly accumulated enough voting power to seize control of its strategy vaults. The exploit, confirmed by security firms CertiK and PeckShield, resulted in roughly 2,843 ETH and approximately 1.6 million DAI being drained to a single wallet address.
How the exploit worked
The attack on August 23 was a governance manipulation rather than code exploitation. The attacker managed to gain 100% voting control over four out of five USDC strategy vaults and roughly 91% control of the Ethereum Meta Vault. With that supermajority in hand, the attacker voted to drain the funds, directing them to a single address beginning with 0xD5183.
The initial funding reportedly came from just 2 ETH sourced through Tornado Cash. From that modest seed, the attacker bootstrapped enough voting power to commandeer vaults holding millions in user deposits.
Term Labs acknowledged the governance issue publicly and indicated the need for further investigation. The protocol’s team has been careful to distinguish this from a smart contract vulnerability.
Not Term Labs’ first brush with losses
In May 2025, Term Finance lost approximately $1.5 million due to an oracle decimal mismatch that occurred during a routine upgrade. That error was non-malicious and the funds were eventually returned.
The company raised $2.5 million in seed funding in early 2023 under the leadership of founder and CEO Dion Chu. The protocol’s value proposition has centered on bringing TradFi-like fixed-rate structures to on-chain lending through over-collateralized, fixed-income-style lending products.
The governance problem DeFi keeps ignoring
Unlike flash loan exploits or reentrancy bugs, governance attacks don’t require any technical wizardry. They exploit the democratic machinery that decentralized protocols use to manage treasuries and upgrade parameters. Term Finance’s vault structure apparently didn’t have sufficient guardrails to prevent a hostile takeover of voting power.
This exploit passed through audited contracts without breaking a single line of code. The vulnerability was architectural, sitting at the intersection of tokenomics, voter apathy, and insufficient access controls on vault management functions.
For depositors who lost funds in this exploit, the path to recovery is unclear. Unlike the May 2025 oracle mismatch, where the error was internal and funds were recoverable, this attack involved an external actor who routed their seed capital through Tornado Cash, a tool designed specifically to sever the on-chain link between sender and receiver.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

1 hour ago
13









English (US) ·