Skip to main content
Sign in

Term Finance — Governance Exploit (August 2026)

avoid.net/term-finance-governance-exploit-august-202610/100·88% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

Summary

On August 23, 2026, an unknown attacker exploited the governance mechanism of Term Finance's strategy vaults, draining approximately 2,843 ETH and 1.68 million USDC — an estimated $8.5 million — representing roughly 68% of the protocol's total vault TVL at the time. The attacker acquired 0.4852 tmvETH for approximately $951, which secured 90.66% of all active voting power in the affected pool, then self-approved malicious governance proposals to redirect vault funds to a controlled wallet. No smart contract bug was involved; the exploit operated entirely within the designed governance mechanism.

Connected Entities

1 entities
Protocols
Term Finance — Governance Exploit (August 2026)
Relationships
    Have evidence about Term Finance — Governance Exploit (August 2026)?
    0
    Accepted
    1
    Under review
    0
    Rejected / revoked

    Community submissions

    • Under reviewincriminatingWayback pending8/28/2026, 10:10:31 PM

      [Scout] The Block confirmed on August 23 that an attacker accumulated sufficient governance voting power to instruct vaults to hand over 2,843 ETH and 1.68M USDC totaling .5M from a protocol with .8M TVL. The attacker exploited the governance mechanism directly rather than any smart contract bug, representing a governance-design vulnerability that is increasingly common across DeFi in 2026. Additional sources: https://finance.yahoo.com/markets/crypto/articles/another-defi-hack-term-labs-123536364.html, https://cryptorank.io/news/feed/23afa-crypto-scams-watch-term-labs-hit-by-8-5m-governance-exploit, https://en.cryptonomist.ch/2026/08/23/term-labs-governance-exploit/

      avoid-scout

    Timeline(6 events)

    1 April 2025

    Term Finance suffers an oracle misconfiguration event that triggers approximately 918 ETH in unintended liquidations. The protocol recovers approximately 556 ETH and reimburses affected users. Term Labs pledges greater governance transparency and third-party validation for critical updates.

    CoinDesk

    23 August 2026

    Attacker seeds a wallet with 2 ETH sourced via Tornado Cash. Attacker spends approximately $951 to purchase and stake 0.4852 tmvETH, securing 90.66% of all active voting power in the Term Finance Ethereum Meta Vault and 100% voting control over four of five USDC strategy vaults.

    Crypto Briefing

    23 August 2026

    Attacker submits and self-approves malicious governance proposals using the acquired supermajority, directing vaults to transfer approximately 2,843 ETH and 1.68 million USDC to wallet 0xD5183d8BfC65a50863C62aF2538198A8288FFc13. Stolen USDC is subsequently converted to approximately 1.68 million DAI.

    AMBCrypto

    23 August 2026

    Term Labs acknowledges the exploit publicly, stating: 'We are aware of a governance exploit impacting Term vaults. We will share more details once it has been further investigated.' Term Labs irreversibly shuts down all Term Meta Vaults, revokes DAO governance roles, and keeps withdrawals open.

    crypto.news

    23 August 2026

    PeckShield and CertiK independently confirm the exploit and estimate total losses at approximately $8.5 million. PeckShield traces initial funding to Tornado Cash. CertiK identifies attacker wallet 0xD5183d8BfC65a50863C62aF2538198A8288FFc13.

    CoinTelegraph

    24 August 2026

    Multiple major crypto outlets publish analysis of the incident. Yearn, whose V3 vault infrastructure Term used, publicly clarifies that the exploit targeted Term's custom governance wrapper and did not affect standard Yearn vault deployments.

    CoinTelegraph
    Provenance & Audit Trail
    18 Wayback Archives

    Decision Log

    • #1publish⛓ pending8/27/2026, 11:09:57 PM
      hash: 3MsoRafN4NGTH2nNjqE2ZzrhDR5jhWPX2F7MC1wQMPzZ

    18 of 19 cited source URLs have an Internet Archive snapshot.

    model: claude-sonnet-4-6

    generated: 8/27/2026, 11:09:48 PM

    last updated: 8/28/2026, 3:45:07 PM

    avoid.net — verified advice for a post-truth world