< Back to all clusters
[TECHNOLOGY] · United States · 18 sources

started · updated

Term Finance loses $8.5 million in governance exploit

Term Finance, an Ethereum-based lending protocol developed by Term Labs, suffered a governance exploit on August 23, 2026, resulting in an estimated loss of $8.5 million. Security firms PeckShield and CertiK reported that the attacker drained approximately 2,843 ETH and 1.68 million USDC, which was subsequently swapped for DAI.

The attack was characterized as a governance manipulation rather than a smart contract code vulnerability. The attacker reportedly acquired a significant portion of the protocol’s thinly distributed governance tokens to gain voting power. This allowed them to approve proposals that granted control over the Meta Vaults, bypassing existing protections like the seven-day timelock and liquidity provider veto rights.

In response, Term Labs has permanently shut down the Term Meta Vaults, blocked new deposits, and revoked the DAO governance permissions that enabled the exploit. While the broader lending and borrowing markets remain unaffected, the company is working with external security teams to investigate the incident and explore potential asset recovery or compensation for users.

Entities

CertiK · Dion Chu · Ethereum · PeckShield · Term Finance · Term Labs

Claims

What the coverage asserts, and how many sources carry each claim.

Sources

19 days ago
19 days ago
20 days ago