NewsCryptoTerm Labs Loses $8.5M as Governance Exploit Drains Ethereum Vaults

Term Labs Loses $8.5M as Governance Exploit Drains Ethereum Vaults

Author: Crypto Adventure·

Key Takeaways

  • The attacker used governance control, not an Ethereum protocol flaw, to authorize transfers from Term vaults.
  • The identified attacker address currently holds about 2,843 ETH and 1.6 million DAI.
  • Roughly 1.68 million USDC was moved during the attack and later converted into DAI.
  • Term has confirmed the exploit and says the affected vaults are under active investigation.
  • The article links the attack to a broader pattern of governance takeovers affecting DeFi protocols.
Term Labs Loses $8.5M as Governance Exploit Drains Ethereum Vaults

Term Labs, the team behind the Ethereum-based fixed-rate lending protocol, has lost an estimated $8.5 million after an attacker accumulated enough governance power to execute malicious proposals against protocol-operated vaults.

The company confirmed the governance exploit on Sunday and opened an investigation into the affected vaults. The attacker-controlled address currently holds approximately 2,843 ETH and 1.6 million DAI, placing the observed proceeds near $8.5 million at current prices.

Wallets connected to the operation were funded through Tornado Cash, the Ethereum privacy mixer that has appeared as a funding source in earlier crypto exploits, before the attacker began building governance voting power. The exploit then relied on Term's own voting process to authorize transactions against protocol vaults, converting control of governance into control over deposited assets rather than exploiting Ethereum itself.

Governance Route to Term's Vaults

TERM is the governance token for Term Finance, with holders able to participate in decisions affecting the protocol. Term operates fixed-rate lending markets and vault products that deploy capital across onchain lending strategies.

The attack targeted the governance path controlling Term's vaults. The attacker accumulated voting power, submitted proposals capable of moving vault assets, and secured enough support for the transactions to execute.

The stolen assets included roughly 2,843 ETH alongside stablecoins. About 1.68 million USDC was moved during the attack and subsequently converted into DAI, leaving the identified address with approximately 1.6 million DAI in addition to the ETH.

The use of acquired voting power separates the Term drain from contract-level attacks such as Sunday's KiiChain exploit, in which an EVM-module vulnerability allowed funds to leave the chain through Hyperlane before validators halted the network. Because governance-driven transfers execute through a protocol's own approval process, the defenses that matter are the ones that slow or block hostile proposals — voting power thresholds and delays between approval and execution.

BONK Lost $20M Through Another Governance Capture

BonkDAO lost roughly $20 million in BONK on July 6 after an attacker accumulated enough voting power to pass a malicious proposal through Solana's Realms governance system. The attacker spent about $4 million building the required BONK position before the proposal transferred 4.426 trillion BONK from the DAO treasury. BONK subsequently fell nearly 40% as the stolen tokens moved through the market. The spread between the cost of the votes and the size of the treasury transfer illustrates why assets controlled by token voting are recurring targets: the voting power needed to move them can be far cheaper than the assets themselves.

A similar takeover hit the small Ethereum-based TOP protocol in June. An attacker withdrew about 664 ETH from Tornado Cash, bought more than half of TOP's 16,384-token supply, and used that majority to approve a mint of 10 billion new tokens. Roughly $1.6 million was extracted from a Balancer pool after the newly created supply was sold. The governance majority could execute immediately because TOP lacked a timelock between approval and execution. Timelocks are a widely used DAO safeguard for this reason, creating a window in which malicious proposals can be detected and countered before funds move.

Term Investigates as DeFi Exploits Accelerate

The $8.5 million Term drain comes days after Maya Protocol lost roughly $1.7 million when faulty accounting allowed an attacker to manipulate liquidity positions and extract assets. Maya responded with a network halt while developers isolated the affected path.

Term has not published a final transaction-by-transaction postmortem, a recovery plan, or a confirmed reimbursement process. Its latest update places the affected Term vaults under active investigation, while the identified attacker address continues to hold approximately 2,843 ETH and 1.6 million DAI.