
Term Labs confirmed on Aug. 23 that a governance exploit had affected its lending vaults. Blockchain security firms estimated that the attacker extracted approximately $8.5 million in cryptocurrency.
Summary
- Term Labs confirmed a governance exploit affected its vaults while investigators assessed the full damage.
- CertiK estimated losses near $8.5 million, but Term Labs has not publicly confirmed that figure.
- The identified address held approximately 2,843 ETH and 1.6 million DAI after the attack transactions.
- PeckShield traced the exploiter’s initial two-ETH funding to Tornado Cash before the vault transactions began.
- Term Labs has not announced recoveries, reimbursement terms, contract pauses, or a completed technical postmortem.
The protocol said it was investigating and would release additional information afterward. It has not confirmed the loss estimate, identified the affected vaults or explained how the attacker gained governance control.
Term Labs confirms its vault governance exploit
“We are aware of a governance exploit impacting Term vaults,” Term said. “We will share more details once it has been further investigated.”
The statement did not say whether Term Labs had paused deposits, withdrawals or governance functions. It also did not identify any contracts that users should avoid. No recovery proposal, reimbursement commitment or deadline for a postmortem had been announced when this report was prepared.
Term Labs operates a decentralized lending system built around fixed-rate borrowing and lending. Its strategy vaults allocate deposited funds through programmed contracts. The protocol has not said whether every vault was exposed or whether the incident affected only specific deployments.
Security firms estimate losses at $8.5 million
CertiK classified the incident as a governance attack and estimated the loss at approximately $8.5 million. That amount remains an external estimate rather than a figure confirmed by Term Labs.
PeckShield reported that the exploiter drained approximately 2,843 ETH, valued at about $6.87 million at the time, plus 1.68 million USDC. According to its tracing, the attacker subsequently exchanged the USDC for approximately 1.68 million DAI.
Those amounts broadly support CertiK’s estimate. However, valuations can change with asset prices, transaction fees and subsequent transfers. A complete accounting will require Term Labs to identify every affected vault and reconcile the relevant transactions.
The findings also resemble other recent attacks on protocol-controlled funds. In related coverage, a Summer.fi vault exploit reportedly drained approximately $6 million. That case involved different contracts and does not establish how the Term Labs incident occurred.
Governance mechanism remains unconfirmed
Term Labs has described the event as a governance exploit, but neither the protocol nor the cited security firms has published a full transaction-level explanation. It remains unclear whether the attacker accumulated voting power, abused an existing permission or exploited a weakness in the proposal process.
Governance attacks can let an entity use authorized voting or administrative functions to transfer protocol assets. As crypto.news previously explained after the BonkDAO governance attack, weak quorum rules, concentrated voting power and missing execution delays can expose controlled funds. Those risks are general examples, not confirmed causes in the Term Labs case.
PeckShield also reported that the attacker’s address initially received 2 ETH from Tornado Cash. The transfer obscures the wallet’s earlier funding source, but it does not identify the attacker or prove who controlled the address.
A Tornado Cash connection should therefore be treated as an on-chain funding trail, not an attribution finding. Investigators will need exchange records, wallet clustering or other evidence to connect the address to a person or organization.
Term Labs still owes users a recovery timeline
The next verified update should establish which vaults and contracts were affected. Users also need confirmation about whether deposits, withdrawals, governance voting and strategy execution remain active.
A technical report would normally document the malicious transactions, control path and safeguards that failed. Term Labs has not announced when it will publish that material. It has also not disclosed whether it contacted the attacker, law enforcement, stablecoin issuers or centralized exchanges.
Any repayment plan would require a confirmed loss total and a clear assessment of recoverable assets. As crypto.news reported following another DeFi breach, the Resupply recovery plan used treasury payments, insurance funds and governance approval. Term Labs has not proposed a comparable process.
Until the investigation is complete, the $8.5 million figure and reported asset balances remain security-research estimates. The protocol’s only confirmed disclosure is that a governance exploit affected Term vaults.

Leave feedback about this