Term Labs lost an estimated $8.5 million after an attacker built up enough voting power to seize control of its governance system and drain several vaults. No code was broken — the attacker used the protocol's own approval process to move the funds out, and Term Labs says it is still investigating.
An attacker took over Term Labs' governance system and drained millions from its vaults without touching a single line of code. Blockchain security firm PeckShieldAlert reported that the wallet built up enough voting power to control four USDC strategy vaults and about 91% of the Ethereum Meta Vault, giving it the ability to pass its own proposals.
How the attacker took control
Once the proposals passed, the vaults followed the instructions and transferred their funds to the attacker's wallet. As a result, the exploit was a governance attack rather than a conventional smart-contract hack — the audited code itself never failed. The attacker reportedly funded the scheme with just two ETH routed through Tornado Cash.
The incident shows that even protocols with clean code audits can carry risk if their governance system isn't equally protected. Because the vaults simply obeyed a majority vote, no security flaw needed to exist for the funds to move.
$8.5 million drained from Term vaults
PeckShieldAlert reported that the attacker drained about 2,843 ETH, worth roughly $6.87 million, along with close to $1.6 million in DAI. Earlier in the operation, about $1.68 million in USDC was reportedly swapped for DAI. The stolen assets now sit in a wallet holding most of the reported funds.
Term Labs officially acknowledged the incident, stating: "We are aware of a governance exploit impacting Term vaults." The protocol has not yet published a recovery plan or said how much of the loss can be recouped.
This marks the second major loss for the protocol. In May 2025, Term Finance lost about $1.5 million to an oracle decimal error during an upgrade, though those funds were later recovered.
Source: Coinpedia Fintech News
Trading involves risk.