Term Labs confirmed that a governance attack drained approximately $8.5 million from several lending vaults operated through Term Finance.
The attacker secured decisive governance influence with tokens worth only a few dollars. Vault users had not converted their shares.
Term Finance provides decentralized, fixed-rate loans backed by ETH. Its developer cited predictable lending costs and experience from former Citibank and Morgan Stanley quantitative professionals.
The company said that several vaults were affected, although the total impact remained under assessment. Early evidence indicated the attacker followed governance rules rather than exploiting malicious code.
Governance structure enabled control
Term Finance offered lending vaults resembling Morpho’s. Depositors could supply funds, earn passive income, and receive share tokens representing their positions.
The protocol used Aragon governance and let depositors wrap vault shares into separate governance tokens. Users had to complete this conversion manually, and many never did.
The attacker completed the conversion and obtained 100 percent of governance power across four of the five affected vaults. Despite holding governance tokens valued at only several dollars, the individual gained authority over reserves worth millions.
A proposal submitted on August 17 contained actions that voters could not immediately see. Following a six-day waiting period, the attacker changed vault parameters and drained five USDC lending vaults.
Stolen ETH and DAI remain visible
Blockchain data showed that the attacking wallets initially received 2 ETH through Tornado Cash. Similar funding methods have previously appeared in exploits attributed to DPRK-linked hackers.
After withdrawing the assets, the exploiter consolidated them within one identified wallet. That address held approximately $1.6 million in DAI and around $6.9 million in ETH.
The stolen assets had not been mixed or transferred further. That behavior differed from other incidents where attackers began obscuring funds within an hour.
Term Finance held more than $25 million in total value locked on August 23. It also reported $3.92 million in active loans, supported by larger collateral balances across its vaults.
The lending vaults collectively contained $12.25 million before the incident. Consequently, the $8.5 million loss removed most of the protocol’s available lending capacity.
Low participation increases governance risk
The Term Labs incident followed recent attacks involving Maya Protocol and The Sandbox, where a separate mint exploit occurred. Governance attacks became more visible during 2026 as limited user participation weakened oversight across several Web3 protocols.
Many decentralized organizations connect voting authority to specific token holdings. Whales, team allocations, or aggressive purchasers can therefore acquire enough influence to target reserves, treasuries, and protocol vaults.
Proposal activity and voter understanding also vary among decentralized organizations. When users remain inactive or overlook proposals, one participant can advance favorable changes and approve them through concentrated voting power.

