Skip to main content
Sign in

Audit log

Every state-changing event for Term Finance — Governance Exploit (August 2026): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-08-27 23:09:57Z
    Score: ?? (no score change)
    anchorpending
    chain
    hash
    3MsoRafN4NGT…C1wQMPzZsha256 → base58
    verifying row…
    canonical bytes (19466 B) ▸
    {"actor":"system:backfill","investigation_id":"e249837f-438c-40a6-87fa-16668503fc14","kind":"publish","page_slug":"term-finance-governance-exploit-august-2026","published_at":"2026-08-27T23:09:57.646Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Term Finance — Governance Exploit (August 2026)","sections":[{"content":"Term Finance, an Ethereum-based fixed-rate lending protocol operated by Term Labs, suffered a governance capture attack on August 23, 2026. An unknown attacker acquired a supermajority of voting power in Term's strategy vault governance system at negligible cost and used that power to pass proposals directing vault assets to an attacker-controlled wallet. Blockchain security firms PeckShield and CertiK independently estimated total losses at approximately $8.5 million. Term Labs acknowledged the incident publicly on the day of the attack, stating: 'We are aware of a governance exploit impacting Term vaults. We will share more details once it has been further investigated.' No technical postmortem had been published as of the date of this report.","heading":"Incident Overview","severity":"critical","sources":[{"credibility":2,"name":"DeFi lending protocol Term Finance loses an estimated $8.5 million to governance exploit — The Block","type":"news_article","url":"https://www.theblock.co/news/defi/2026-08-23-defi-lending-protocol-term-finance-loses-an-estimated-8-5-million-to-governance-exploit-412543"},{"credibility":2,"name":"Term Finance Vault Governance Exploit Drains Estimated $8.5M — CoinTelegraph","type":"news_article","url":"https://cointelegraph.com/news/term-finance-8-5m-vault-governance-exploit"},{"credibility":2,"name":"Term Labs vault exploit drains estimated $8.5M — crypto.news","type":"news_article","url":"https://crypto.news/term-labs-vault-exploit-drains-estimated-8-5m/"}]},{"content":"The exploit did not involve a smart contract bug. Instead, it took advantage of an extremely low participation rate in Term Finance's vault governance system. The total staked supply across the affected pool stood at approximately 0.5352 gtmvETH prior to the attack — a negligible amount relative to the value of assets under governance control. The attacker purchased and staked 0.4852 tmvETH for approximately $951, which was sufficient to secure 90.66% of all existing voting power in the Ethereum Meta Vault. The attacker also obtained 100% voting control over four of five USDC strategy vaults. With that supermajority established, the attacker submitted and self-approved malicious governance proposals that directed the vaults to transfer assets to an attacker-controlled wallet. The attack was initially funded with 2 ETH sourced via Tornado Cash, as traced by PeckShield. CertiK identified the attacker's wallet address as 0xD5183d8BfC65a50863C62aF2538198A8288FFc13. The affected vaults were built on Yearn V3 infrastructure with a custom governance wrapper; Yearn publicly clarified that standard Yearn vault setups were not affected by this attack vector.","heading":"Attack Mechanism","severity":"critical","sources":[{"credibility":2,"name":"Term Finance Loses $8.5M After Attacker Hijacks DAO Governance Vote — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/23/term-finance-loses-8-5m-after-attacker-hijacks-dao-governance-vote/"},{"credibility":2,"name":"Term Labs suffers $8.5M governance exploit as attacker seizes control of strategy vaults — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/term-labs-governance-exploit-vaults/"},{"credibility":2,"name":"Ethereum DeFi takes another hit — Term Finance governance attack drains $8.5M — AMBCrypto","type":"news_article","url":"https://ambcrypto.com/ethereum-defi-takes-another-hit-term-finance-governance-attack-drains-8-5m/"},{"credibility":2,"name":"Crypto Scams Watch: Term Labs Hit by $8.5M Governance Exploit — CryptoRank","type":"news_article","url":"https://cryptorank.io/news/feed/23afa-crypto-scams-watch-term-labs-hit-by-8-5m-governance-exploit"}]},{"content":"The attacker extracted approximately 2,843 ETH, valued at roughly $6.87 million at the time of the attack, and approximately 1.68 million USDC, which was subsequently swapped for approximately 1.68 million DAI. Combined estimated losses were approximately $8.5 million. This represented approximately 68% of Term Finance's total vault TVL, which stood at $12.45 million prior to the incident. Nearly all of the protocol's approximately $8.8 million in Ethereum vault deposits were drained. Term Labs' core fixed-rate lending markets and direct borrowing/lending operations were not affected by the exploit. According to reporting by Yahoo Finance, the incident was the fifth governance-related attack in 2026, contributing to estimated combined governance attack losses of $25.1 million across the industry by that date.","heading":"Financial Impact","severity":"critical","sources":[{"credibility":2,"name":"Term Finance Loses $8.5M in Governance Attack — GNCrypto","type":"news_article","url":"https://www.gncrypto.news/news/term-finance-loses-8-5m-governance-attack-drains-2843-eth-1-68m-usdc/"},{"credibility":2,"name":"Another DeFi Hack: Term Labs Loses $8.5 Million in Governance Exploit — Yahoo Finance","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/another-defi-hack-term-labs-123536364.html"},{"credibility":2,"name":"Term Finance Loses $8.5 Million as Governance Exploit Drains 68% of Vault Assets — The Currency Analytics","type":"news_article","url":"https://thecurrencyanalytics.com/stable-coins/term-finance-loses-8-5-million-as-governance-exploit-drains-68-of-vault-assets-287155"}]},{"content":"Term Labs responded on August 23, 2026 by irreversibly shutting down all Term Meta Vaults and permanently revoking their DAO governance roles. Withdrawals were kept open while new deposits were permanently blocked. The protocol stated that its core fixed-rate lending markets remained operational and unaffected. Term Labs indicated it was coordinating with external security teams on asset recovery prospects. As of the date of this report, the protocol had not published a technical postmortem, announced a reimbursement commitment, or set a deadline for further disclosures. Recovery of stolen funds was assessed by multiple analysts as unlikely given the use of Tornado Cash for initial funding and the subsequent conversion of USDC to DAI.","heading":"Protocol Response and Remediation","severity":"high","sources":[{"credibility":2,"name":"Term Finance Hack Today: What Happened After $8.5 Million Funds Lost? — CoinGabbar","type":"news_article","url":"https://www.coingabbar.com/en/crypto-currency-news/term-finance-hack-today-8-5-million-lost-meta-vaults-shutdown"},{"credibility":2,"name":"Term Labs Governance Exploit Drains $8.5M From Vaults — Cryptonomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/08/23/term-labs-governance-exploit/"},{"credibility":2,"name":"Term Finance Loses $8.5M in Governance Exploit Targeting Strategy Vaults — MoneyCheck","type":"news_article","url":"https://moneycheck.com/term-finance-loses-8-5m-in-governance-exploit-targeting-strategy-vaults"}]},{"content":"This was not Term Finance's first security incident. In April 2025, an oracle misconfiguration triggered approximately 918 ETH in unintended liquidations in the protocol's tETH market. Term recovered approximately 556 ETH of the lost amount and reimbursed affected users, with the protocol's treasury covering the shortfall. Term Labs characterized the April 2025 event as 'not a hack' and noted that no smart contracts were exploited and user funds were not directly targeted. Following that incident, the protocol pledged greater governance transparency and third-party validation for critical updates. The August 2026 governance exploit occurred approximately 16 months after those pledges were made.","heading":"Prior Incident History","severity":"high","sources":[{"credibility":1,"name":"Ethereum lending app Term Finance loses $8.5 million after attacker buys voting power — CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2026/08/24/ethereum-lending-app-term-finance-loses-usd8-5-million-after-attacker-buys-voting-power"},{"credibility":3,"name":"Term Finance $8.5M Governance Exploit Explained (2026) — SpotedCrypto","type":"news_article","url":"https://www.spotedcrypto.com/term-finance-governance-exploit-2026/"}]},{"content":"The attack exposed a systemic design risk in DeFi governance systems where the staked voting token supply is very low relative to the value of assets under governance control. In Term Finance's case, the total active staked supply in the affected pool was approximately 0.5352 gtmvETH, meaning an attacker could acquire a controlling supermajority for under $1,000. This attack pattern — sometimes called a 'governance capture' or 'governance takeover' — requires no exploitation of contract logic. It operates through the protocol's own intended voting mechanisms. The vulnerability is distinct from smart contract bugs and is not necessarily detectable by standard code audits. CoinTelegraph reported that Yearn V3, on whose infrastructure Term's vaults were built, clarified that the exploit relied on Term's custom governance wrapper and was not applicable to standard Yearn vault deployments. The incident has been cited by analysts as illustrative of the broader risk that governance systems with low token participation can become attack surfaces even when underlying code is sound.","heading":"Governance Design Risk","severity":"high","sources":[{"credibility":3,"name":"When Governance Becomes the Attack Surface: What the $8.5M Term Finance Exploit Reveals About DeFi Security — W3Rooster","type":"news_article","url":"https://w3rooster.com/when-governance-becomes-the-attack-surface-what-the-8-5m-term-finance-exploit-reveals-about-defi-security/"},{"credibility":2,"name":"Term Finance Exploit Details and Governance Risks — Cryptonomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/08/24/term-finance-exploit-governance/"},{"credibility":2,"name":"Term Finance Vault Governance Exploit Drains Estimated $8.5M — CoinTelegraph","type":"news_article","url":"https://cointelegraph.com/news/term-finance-8-5m-vault-governance-exploit"}]},{"content":"CertiK identified the attacker's wallet address as 0xD5183d8BfC65a50863C62aF2538198A8288FFc13. PeckShield independently traced the wallet and confirmed it as the recipient of the drained funds. Both firms classified the incident as a governance exploit rather than a code exploit. The attacker's initial 2 ETH in operating capital was sourced from Tornado Cash, a privacy mixing service, prior to executing the attack. Following the drain, the attacker converted the 1.68 million USDC proceeds to approximately 1.68 million DAI. The identity of the attacker is unknown as of the date of this report. No law enforcement action or regulatory filing related to this incident has been publicly confirmed.","heading":"On-Chain Attribution","severity":"critical","sources":[{"credibility":3,"name":"Term Finance Loses $8.5M as Attacker Hijacks Governance Vote — CryptocurrencyHelp","type":"news_article","url":"https://cryptocurrencyhelp.com/news/term-finance-loses-8-5m-as-attacker-hijacks-governance-vote/"},{"credibility":2,"name":"Ethereum DeFi Protocol Term Finance Hit by $8.5M Governance Attack — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/ethereum-defi-protocol-term-finance-hit-by-8-5m-governance-attack"},{"credibility":2,"name":"Term Finance Governance Exploit: $8.5 Million Drained — CryptoTicker","type":"news_article","url":"https://cryptoticker.io/en/term-finance-governance-exploit-defi-deposits/"}]}],"sources_used":[{"credibility":2,"name":"DeFi lending protocol Term Finance loses an estimated $8.5 million to governance exploit — The Block","type":"news_article","url":"https://www.theblock.co/news/defi/2026-08-23-defi-lending-protocol-term-finance-loses-an-estimated-8-5-million-to-governance-exploit-412543"},{"credibility":1,"name":"Ethereum lending app Term Finance loses $8.5 million after attacker buys voting power — CoinDesk","type":"news_article","url":"https://www.coindesk.com/markets/2026/08/24/ethereum-lending-app-term-finance-loses-usd8-5-million-after-attacker-buys-voting-power"},{"credibility":2,"name":"Term Finance Vault Governance Exploit Drains Estimated $8.5M — CoinTelegraph","type":"news_article","url":"https://cointelegraph.com/news/term-finance-8-5m-vault-governance-exploit"},{"credibility":2,"name":"Term Labs suffers $8.5M governance exploit as attacker seizes control of strategy vaults — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/term-labs-governance-exploit-vaults/"},{"credibility":2,"name":"Term Labs vault exploit drains estimated $8.5M — crypto.news","type":"news_article","url":"https://crypto.news/term-labs-vault-exploit-drains-estimated-8-5m/"},{"credibility":2,"name":"Another DeFi Hack: Term Labs Loses $8.5 Million in Governance Exploit — Yahoo Finance","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/another-defi-hack-term-labs-123536364.html"},{"credibility":2,"name":"Ethereum DeFi takes another hit — Term Finance governance attack drains $8.5M — AMBCrypto","type":"news_article","url":"https://ambcrypto.com/ethereum-defi-takes-another-hit-term-finance-governance-attack-drains-8-5m/"},{"credibility":2,"name":"Term Finance Exploit Details and Governance Risks — Cryptonomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/08/24/term-finance-exploit-governance/"},{"credibility":2,"name":"Term Labs Governance Exploit Drains $8.5M From Vaults — Cryptonomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/08/23/term-labs-governance-exploit/"},{"credibility":2,"name":"Ethereum DeFi Protocol Term Finance Hit by $8.5M Governance Attack — KuCoin","type":"news_article","url":"https://www.kucoin.com/news/flash/ethereum-defi-protocol-term-finance-hit-by-8-5m-governance-attack"},{"credibility":2,"name":"Term Finance Loses $8.5M After Attacker Hijacks DAO Governance Vote — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/08/23/term-finance-loses-8-5m-after-attacker-hijacks-dao-governance-vote/"},{"credibility":2,"name":"Term Finance Hack Today: What Happened After $8.5 Million Funds Lost? — CoinGabbar","type":"news_article","url":"https://www.coingabbar.com/en/crypto-currency-news/term-finance-hack-today-8-5-million-lost-meta-vaults-shutdown"},{"credibility":2,"name":"Crypto Scams Watch: Term Labs Hit by $8.5M Governance Exploit — CryptoRank","type":"news_article","url":"https://cryptorank.io/news/feed/23afa-crypto-scams-watch-term-labs-hit-by-8-5m-governance-exploit"},{"credibility":2,"name":"Term Finance Loses $8.5M in Governance Attack — GNCrypto","type":"news_article","url":"https://www.gncrypto.news/news/term-finance-loses-8-5m-governance-attack-drains-2843-eth-1-68m-usdc/"},{"credibility":2,"name":"Term Finance Loses $8.5M in Governance Exploit Targeting Strategy Vaults — MoneyCheck","type":"news_article","url":"https://moneycheck.com/term-finance-loses-8-5m-in-governance-exploit-targeting-strategy-vaults"},{"credibility":2,"name":"Term Finance Governance Exploit: $8.5 Million Drained — CryptoTicker","type":"news_article","url":"https://cryptoticker.io/en/term-finance-governance-exploit-defi-deposits/"},{"credibility":2,"name":"Term Finance Loses $8.5 Million as Governance Exploit Drains 68% of Vault Assets — The Currency Analytics","type":"news_article","url":"https://thecurrencyanalytics.com/stable-coins/term-finance-loses-8-5-million-as-governance-exploit-drains-68-of-vault-assets-287155"},{"credibility":3,"name":"When Governance Becomes the Attack Surface — W3Rooster","type":"news_article","url":"https://w3rooster.com/when-governance-becomes-the-attack-surface-what-the-8-5m-term-finance-exploit-reveals-about-defi-security/"},{"credibility":3,"name":"Term Finance $8.5M Governance Exploit Explained (2026) — SpotedCrypto","type":"news_article","url":"https://www.spotedcrypto.com/term-finance-governance-exploit-2026/"}],"summary":"On August 23, 2026, an unknown attacker exploited the governance mechanism of Term Finance's strategy vaults, draining approximately 2,843 ETH and 1.68 million USDC — an estimated $8.5 million — representing roughly 68% of the protocol's total vault TVL at the time. The attacker acquired 0.4852 tmvETH for approximately $951, which secured 90.66% of all active voting power in the affected pool, then self-approved malicious governance proposals to redirect vault funds to a controlled wallet. No smart contract bug was involved; the exploit operated entirely within the designed governance mechanism.","timeline":[{"date":"2025-04-01","event":"Term Finance suffers an oracle misconfiguration event that triggers approximately 918 ETH in unintended liquidations. The protocol recovers approximately 556 ETH and reimburses affected users. Term Labs pledges greater governance transparency and third-party validation for critical updates.","source":"CoinDesk","source_url":"https://www.coindesk.com/markets/2026/08/24/ethereum-lending-app-term-finance-loses-usd8-5-million-after-attacker-buys-voting-power"},{"date":"2026-08-23","event":"Attacker seeds a wallet with 2 ETH sourced via Tornado Cash. Attacker spends approximately $951 to purchase and stake 0.4852 tmvETH, securing 90.66% of all active voting power in the Term Finance Ethereum Meta Vault and 100% voting control over four of five USDC strategy vaults.","source":"Crypto Briefing","source_url":"https://cryptobriefing.com/term-labs-governance-exploit-vaults/"},{"date":"2026-08-23","event":"Attacker submits and self-approves malicious governance proposals using the acquired supermajority, directing vaults to transfer approximately 2,843 ETH and 1.68 million USDC to wallet 0xD5183d8BfC65a50863C62aF2538198A8288FFc13. Stolen USDC is subsequently converted to approximately 1.68 million DAI.","source":"AMBCrypto","source_url":"https://ambcrypto.com/ethereum-defi-takes-another-hit-term-finance-governance-attack-drains-8-5m/"},{"date":"2026-08-23","event":"Term Labs acknowledges the exploit publicly, stating: 'We are aware of a governance exploit impacting Term vaults. We will share more details once it has been further investigated.' Term Labs irreversibly shuts down all Term Meta Vaults, revokes DAO governance roles, and keeps withdrawals open.","source":"crypto.news","source_url":"https://crypto.news/term-labs-vault-exploit-drains-estimated-8-5m/"},{"date":"2026-08-23","event":"PeckShield and CertiK independently confirm the exploit and estimate total losses at approximately $8.5 million. PeckShield traces initial funding to Tornado Cash. CertiK identifies attacker wallet 0xD5183d8BfC65a50863C62aF2538198A8288FFc13.","source":"CoinTelegraph","source_url":"https://cointelegraph.com/news/term-finance-8-5m-vault-governance-exploit"},{"date":"2026-08-24","event":"Multiple major crypto outlets publish analysis of the incident. Yearn, whose V3 vault infrastructure Term used, publicly clarifies that the exploit targeted Term's custom governance wrapper and did not affect standard Yearn vault deployments.","source":"CoinTelegraph","source_url":"https://cointelegraph.com/news/term-finance-8-5m-vault-governance-exploit"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision b73c3330-3088-41d4-9c81-95725f93cd68
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.