NewsCryptoTerm Labs Suffers $8.5M Governance Exploit Affecting Vaults

Term Labs Suffers $8.5M Governance Exploit Affecting Vaults

Author: Metaverse Post·

Key Takeaways

  • The exploit targeted Term Labs’ governance system rather than the underlying borrowing and lending protocol.
  • Security firms said the attacker was holding about 2,843 ETH and $1.6 million in DAI at a single address after the attack.
  • Go Plus Security reported that the attacker obtained full governance control with about 0.5 ETH and used it to execute a malicious proposal.
  • Term Labs permanently shut down all Term Meta Vaults, revoked DAO governance roles, and disabled new deposits while keeping withdrawals open.
  • The incident came after a 2025 oracle failure at Term Labs that caused unintended liquidations and prompted commitments to stronger governance and review processes.
Term Labs Suffers $8.5M Governance Exploit Affecting Vaults

Term Labs, the decentralized finance (DeFi) protocol behind the fixed-rate lending platform Term Finance, suffered a major governance exploit on August 23 that drained about $8.5 million from its vaults.

Governance exploits are a distinct class of DeFi attack: instead of breaking a protocol’s code, they capture the voting power that controls its treasury and parameters. Some of the industry’s largest thefts have come through that route, including the April 2022 Beanstalk attack, in which an attacker used a flash loan to accumulate voting power and drained roughly $182 million. Fixed-rate lending itself remains a niche corner of DeFi, where the largest money markets, such as Aave and Compound, operate on floating rates.

Blockchain security firms PeckShieldAlert and CertiK Alert confirmed the losses. They said the attacker is currently holding roughly 2,843 ETH and about $1.6 million in DAI at a single address. On-chain records show the attacker’s wallet was initially funded with 2 ETH through the cryptocurrency mixer Tornado Cash, a service that has repeatedly appeared as the seed-funding source in past crypto exploits and typically makes attribution harder for investigators.

#CertiKInsight @term_labs was targeted in a governance attack resulting in the loss of ~$8.5M. 2,843 ETH and ~$1.6M DAI are currently at address 0xD5183d8BfC65a50863C62aF2538198A8288FFc13 Stay vigilant! — CertiK Alert (@CertiKAlert) August 23, 2026

#CertiKInsight @term_labs was targeted in a governance attack resulting in the loss of ~$8.5M. 2,843 ETH and ~$1.6M DAI are currently at address 0xD5183d8BfC65a50863C62aF2538198A8288FFc13 Stay vigilant!

According to the report, the breach stemmed from a critical weakness in Term Labs’ governance design, where voting power was not sufficiently protected against economic capture.

A technical breakdown published by Go Plus Security said the attacker gained full governance control for just 0.5 ETH. The exploit began with a swap of about 0.5 ETH into 0.485 tmvETH, which was then deposited into the Yearn/Governance wrapper to mint an equivalent amount of gtmvETH. That step granted immediate and disproportionate voting rights.

The attacker then self-submitted and self-approved proposalId=5 without meaningful opposition. After a six-day waiting period, the proposal was executed, bypassing the Zodiac Delay module’s cooldown and expiration safeguards. According to the breakdown, this allowed the attacker to register a malicious strategy, change debt parameters, and drain the vault’s WETH holdings into a pre-deployed contract before routing the stolen funds to their own address.

The Zodiac Delay module is an open-source governance component developed by Gnosis Guild that sits between a DAO’s approval and execution of proposals, creating a buffer window in which defenders can spot and block malicious actions — the safeguard this attack reportedly circumvented.

In a public statement, Term Labs acknowledged the incident, saying: “We are aware of a governance exploit impacting Term vaults. We will share more details once it has further investigated.”

The team said the underlying Term protocol and its direct borrowing and lending markets were not affected. As an immediate containment measure, all Term Meta Vaults were permanently shut down, DAO governance roles were revoked, and new deposits were irreversibly disabled. Withdrawals remain open for users.

The company also said it is working with external security firms on remediation and recovery, adding that “if a shortfall remains, we will explore paths to address it.”

Update: All Term Meta Vaults were shut down and dao governance roles have been revoked. This shutdown is irreversible and permanently prevents further deposits. Withdrawals remain open. Today's incident involved Term Vault governance. Based on our investigation so far, the… — Term Labs (@term_labs) August 23, 2026

Update: All Term Meta Vaults were shut down and dao governance roles have been revoked. This shutdown is irreversible and permanently prevents further deposits. Withdrawals remain open. Today's incident involved Term Vault governance. Based on our investigation so far, the…

The incident also renewed scrutiny of Term Labs’ security record. In April 2025, the protocol experienced an oracle failure that triggered unintended liquidations totaling about 918 ETH. The project later recovered 556 ETH and reimbursed affected users, reducing the net loss to 362 ETH. That event led to public commitments for third-party validation of critical updates and greater governance transparency.

The open questions now are concrete ones: how withdrawals continue to function as the vaults wind down, what the remediation work with outside security firms produces, whether the funds sitting at the attacker’s now-public address can be traced or frozen, and how any residual shortfall for vault users is covered. The latest exploit, which reportedly required only a small amount of capital to execute, has raised new questions about whether those commitments were enough to prevent a fundamental governance failure.