Term Labs Confirms $8.5M Governance Exploit Targeting Term Finance Vaults
Key Takeaways
- •Security firms CertiK and PeckShield estimate that a governance exploit drained approximately $8.5 million from Term Finance vaults on Aug. 23.
- •The attacker-controlled wallet held about 2,843 ETH along with stablecoins, including DAI converted from 1.68 million stolen USDC, and the attack was initially funded with 2 ETH from Tornado Cash.
- •Early reports identify governance controls rather than a smart-contract flaw as the apparent route to the funds, and no vulnerability has been established in Yearn V3 or Ethereum itself.
- •Term Labs had not released a postmortem, confirmed total user losses, announced a recovery plan, or disclosed whether deposits, withdrawals, or governance functions were paused.
- •Term's documented safeguards include a Gnosis Safe multisig, a Zodiac Delay Module, a seven-day timelock, and liquidity-provider veto rights, but it remains unclear which control failed or whether it operated as designed.

Term Labs is investigating a governance exploit that security firms estimate drained about $8.5 million from Term Finance vaults on Aug. 23. The incident has shifted attention away from smart-contract code and toward the governance controls protecting the protocol's vaults and the assets they hold.
Security Firms Trace Attacker Funds
CertiK identified an attacker-controlled address holding about 2,843 ETH and roughly $1.6 million in DAI after the exploit. PeckShield estimated that the attacker removed 2,843 ETH — worth approximately $6.87 million — alongside 1.68 million USDC from the affected system.
The stolen USDC was later exchanged for roughly 1.68 million DAI, while the attack was initially funded with 2 ETH sourced from Tornado Cash, a mixing service built to obscure the on-chain trail of funds.
Term Labs Suffers $8.5M Governance Exploit Affecting Vaults
DeFi lending protocol @term_labs suffered a governance exploit affecting its vaults. According to PeckShieldAlert and CertiK Alert, the attack resulted in losses of about $8.5 million, with the exploiter holding… pic.twitter.com/yhAHbCN95d
— Wu Blockchain (@WuBlockchain), August 23, 2026 (X)
Term Labs confirmed that a governance exploit affected its vaults, but the protocol had not released a complete postmortem by Aug. 23. Consequently, the attack sequence, the specific vaults affected, and the method used to defeat governance protections all remained unconfirmed.
Governance Controls Face Scrutiny
The incident differs from a conventional smart-contract failure because early security reports identify governance — not a code flaw — as the apparent route to vault assets. That distinction places Term Finance's control structure under examination as investigators work to determine how the attacker reached protected funds. Losses traced to compromised keys or governance privileges, rather than flaws in on-chain code, have been a recurring category in DeFi security incidents; the October 2024 Radiant Capital breach, in which attackers drained roughly $53 million after compromising multisig signing keys, is one widely reported example.
Term's documentation assigns separate manager and governor roles, with governance actions passing through a Gnosis Safe — a multisig wallet widely used across DeFi — and a Zodiac Delay Module. Those actions are additionally subject to a seven-day timelock before execution, creating a review window for proposed changes. Vault liquidity providers are described as DAO participants with the authority to veto proposals during that delay; according to the documentation, a successful veto can invalidate a queued transaction before it executes, adding a further layer of protection.
Term Labs had not, however, confirmed whether voting influence, a permissions issue, a configuration failure, or another governance path caused the breach. Absent a postmortem, the available evidence does not establish which safeguard failed or whether the documented controls operated as designed.
Vault Design, TVL and Recovery Questions Remain Open
Term Finance provides non-custodial, fixed-rate, overcollateralized lending modeled on traditional repurchase agreements, matching borrowers with lenders through sealed-bid auctions. Lenders receive repo tokens representing principal and interest claims at maturity, while Strategy Vaults automate participation and liquidity management.
The vaults are built on Yearn V3's implementation of ERC-4626, the Ethereum standard for tokenized single-asset vaults, alongside custom logic covering auctions, portfolio limits, reserves, and maturity controls. On the evidence to date, no vulnerability has been established in Yearn V3 or in Ethereum itself; scrutiny remains focused on the permissions and governance layer surrounding Term's vault implementation.
Before the exploit, DeFiLlama, a public tracker of deposits across DeFi protocols, listed TermFinance Vaults with about $10.87 million in total value locked, including approximately $7.23 million on Ethereum. That figure excludes capital deployed into Term repo tokens in order to prevent double-counting, which makes a direct comparison with the $8.5 million loss estimate unreliable.
At the time of writing, Term Labs had not announced a recovery plan or reimbursement framework, nor had it confirmed total user losses. The protocol also had not disclosed whether deposits, withdrawals, governance functions, or specific vaults had been paused following the incident.
The attacker-controlled wallet remains the focus of tracing efforts, although Tornado Cash funding alone does not identify the attacker. For depositors, the next disclosures will need to clarify the malicious governance transactions, the affected contracts, proposal timing, and timelock activity. Those details will determine whether the incident involved governance capture, faulty permissions, or another implementation failure within Term Finance's vault controls.