Ethereum-based fixed-rate lending protocol Term Finance lost approximately $8.5 million on August 23, 2026, after an attacker quietly cornered a majority of its sparsely held DAO governance token and passed malicious proposals to seize control of the protocol’s strategy vaults.
The exploit was first flagged publicly by Decurity’s on-chain monitoring bot Defimon and was later independently confirmed by security firms PeckShield and CertiK. Term Labs, the team behind the protocol, acknowledged the incident on X within hours of the drain settling on-chain.
Roughly 2,843 ETH, worth about $6.87 million, and 1.68 million USDC were pulled from the vaults, with the USDC subsequently swapped into approximately 1.68 million DAI. All proceeds were funneled to a single consolidation wallet beginning with 0xD5183.
According to Defimon’s post, the attacker “cheaply acquired a majority of a sparsely held DAO governance token, then passed malicious proposals to seize control of Term’s vaults.” The two exploit transactions have been shared as 0xd354a15b1… and 0x9f273f9a5…, with attacker wallets tracked at 0xa908… and 0x6864….
How The Attack Was Executed
The economics of the exploit are what make it stand out. On-chain data cited by PeckShield indicates the attacker bootstrapped the entire operation with just 2 ETH withdrawn from Tornado Cash, the sanctioned Ethereum mixer commonly used to sever the link between an exchange withdrawal and downstream on-chain activity.
From that modest seed, the attacker began accumulating Term’s governance token on the open market. Because the token had a low float and thin holder participation, achieving a voting supermajority required only a small capital outlay relative to the value of assets sitting under governance control.
Once the attacker’s holdings crossed the proposal and quorum thresholds, they submitted proposals that redirected vault assets and voted them through on the strength of their own balance. At the point of execution, the attacker held 100% of voting power in four out of five USDC strategy vaults, and roughly 91% of voting power in the Ethereum Meta Vault. The vault contracts then executed the malicious calls as legitimate governance-authorized actions.
The first exploit transaction, shown in the Etherscan snapshot circulated by Defimon, was executed at block 25816049 at 06:25 AM UTC on August 23, 2026. It shows attacker wallet 0xa908…00612b burning 44.37 aEthWETH and withdrawing 44.37 WETH from Aave through the stataEthWETH wrapper, for a transaction fee of just 0.00018668 ETH.
Scale Of The Loss
Per DefiLlama data, Term Finance’s vault total value locked stood at $12.2 million heading into the exploit, with $8.6 million of that concentrated on Ethereum. The attacker effectively cleared out nearly the entirety of the protocol’s Ethereum-side deposits.
PeckShield valued the ETH portion of the theft at approximately $6.87 million and the stablecoin portion at $1.68 million, taking the total observed loss to roughly $8.55 million at the time of the attack.
Term Labs kept its initial response short. “We are aware of a governance exploit impacting Term vaults. We will share more details once it has been further investigated,” the team said in an X post following the incident.
Not Term Finance’s First Security Event
This is the second security incident affecting Term Finance in less than 18 months, though the two are fundamentally different in nature. In April 2025, the protocol lost around $1.5 million after a faulty oracle update to its tETH markets allowed a user to liquidate more than 586 Treehouse collateral positions for a tiny amount of ETH. That incident was contained to tETH markets; no smart contracts were compromised, and Term Labs subsequently committed to a full reimbursement plan for affected users.
The August 2026 event is materially different. There is no internal error to reverse, no misconfigured oracle to correct, and no operational counterparty to make depositors whole from protocol reserves. The counterparty here is an external actor who has already routed initial capital through Tornado Cash, meaning on-chain attribution work becomes significantly harder.
Term Finance was founded by Dion Chu and raised $2.5 million in seed funding in early 2023. Its pitch has centered on bringing traditional finance-style fixed-rate, fixed-term structures to on-chain lending through over-collateralized, fixed-income-style products auctioned on-chain.
A Familiar Governance-Attack Playbook
Governance takeovers remain rare but expensive when they land. DefiLlama has now classified five incidents in 2026 as governance attacks, with combined losses of approximately $25.1 million. The largest of those before Term was the $20 million BonkDAO drain in July 2026, where a malicious proposal cleared quorum and moved treasury funds before the community could react.
The pattern echoes older reference cases, including the February 2022 Build Finance hostile takeover, where an attacker submitted a treasury-seizure proposal and voter apathy allowed it to pass unopposed, resulting in the total collapse of the DAO. The May 2023 Tornado Cash governance seizure, where an attacker fabricated more than 1.2 million votes to briefly control the DAO, is another commonly cited reference point.
Unlike flash loan exploits or reentrancy bugs, governance attacks require no technical wizardry. They exploit the democratic machinery that decentralized protocols use to manage treasuries and upgrade parameters, and they pass through audited contracts without breaking a single line of code.
Another Bruising Month For DeFi
Before the Term Finance incident, DefiLlama had logged 17 security incidents in August 2026 worth approximately $18.8 million. The $8.5 million loss at Term pushes the running August total past $27 million. That still trails July, which recorded 38 incidents worth roughly $254 million, largely driven by the $116 million Coldcard wallet firmware flaw.
Other August victims include Harmony, where an attacker minted roughly 4 billion tokens without authorization, and payment processor Coinsbuy, which was drained of $7.9 million.
SlowMist’s mid-year report counted 182 incidents worth about $956 million in the first half of 2026, and cumulative DeFi losses have now crossed $1.1 billion for the year, according to figures previously reported by The Crypto Times.
Recovery Outlook
Recovery prospects for Term Finance depositors are, for now, unclear. Because the attack was executed through legitimately passed governance proposals rather than a code exploit, there is no vulnerability to patch that would reverse the transfers, and no bug-bounty framing that would allow the attacker to negotiate a white-hat return without admitting to a straightforward theft.
The initial funding through Tornado Cash also reduces the on-chain leverage that firms like ZachXBT, TRM Labs, or Chainalysis typically use to attribute stolen funds to a known deposit address at a centralized exchange. Term Labs has not publicly outlined a compensation plan or named the specific governance function abused as of publication.
For the wider fixed-rate lending category and for any DeFi protocol governed by a low-float, low-participation token, the takeaway is the one that has kept resurfacing since Build Finance in 2022: audited contracts are not sufficient protection when the attacker can simply vote themselves the treasury.
Timelocks, delegate-based voting, minimum quorums scaled to treasury size, and off-chain veto councils have all been discussed in prior post-mortems, but adoption across smaller protocols remains inconsistent.
Term Labs said further details will follow its investigation.
Also Read: Sandbox SAND Hacked: Attackers Mint 329 Trillion Tokens on Base in 5-Hour Rampage
