Skip to main content
Sign in

Term Finance — Governance Exploit (August 2026)

avoid.net/term-finance-governance-exploit-august-202610/100·88% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

Summary

On August 23, 2026, an unknown attacker exploited the governance mechanism of Term Finance's strategy vaults, draining approximately 2,843 ETH and 1.68 million USDC — an estimated $8.5 million — representing roughly 68% of the protocol's total vault TVL at the time. The attacker acquired 0.4852 tmvETH for approximately $951, which secured 90.66% of all active voting power in the affected pool, then self-approved malicious governance proposals to redirect vault funds to a controlled wallet. No smart contract bug was involved; the exploit operated entirely within the designed governance mechanism.

Connected Entities

1 entities
Protocols
Term Finance — Governance Exploit (August 2026)
Relationships
    Have evidence about Term Finance — Governance Exploit (August 2026)?

    Timeline(6 events)

    2025-04-01

    Term Finance suffers an oracle misconfiguration event that triggers approximately 918 ETH in unintended liquidations. The protocol recovers approximately 556 ETH and reimburses affected users. Term Labs pledges greater governance transparency and third-party validation for critical updates.

    CoinDesk

    2026-08-23

    Attacker seeds a wallet with 2 ETH sourced via Tornado Cash. Attacker spends approximately $951 to purchase and stake 0.4852 tmvETH, securing 90.66% of all active voting power in the Term Finance Ethereum Meta Vault and 100% voting control over four of five USDC strategy vaults.

    Crypto Briefing

    2026-08-23

    Attacker submits and self-approves malicious governance proposals using the acquired supermajority, directing vaults to transfer approximately 2,843 ETH and 1.68 million USDC to wallet 0xD5183d8BfC65a50863C62aF2538198A8288FFc13. Stolen USDC is subsequently converted to approximately 1.68 million DAI.

    AMBCrypto

    2026-08-23

    Term Labs acknowledges the exploit publicly, stating: 'We are aware of a governance exploit impacting Term vaults. We will share more details once it has been further investigated.' Term Labs irreversibly shuts down all Term Meta Vaults, revokes DAO governance roles, and keeps withdrawals open.

    crypto.news

    2026-08-23

    PeckShield and CertiK independently confirm the exploit and estimate total losses at approximately $8.5 million. PeckShield traces initial funding to Tornado Cash. CertiK identifies attacker wallet 0xD5183d8BfC65a50863C62aF2538198A8288FFc13.

    CoinTelegraph

    2026-08-24

    Multiple major crypto outlets publish analysis of the incident. Yearn, whose V3 vault infrastructure Term used, publicly clarifies that the exploit targeted Term's custom governance wrapper and did not affect standard Yearn vault deployments.

    CoinTelegraph
    Provenance & Audit Trail
    16 Wayback Archives

    Decision Log

    • #1publish⛓ pending8/27/2026, 11:09:57 PM
      hash: 3MsoRafN4NGTH2nNjqE2ZzrhDR5jhWPX2F7MC1wQMPzZ

    16 of 19 cited source URLs have an Internet Archive snapshot.

    model: claude-sonnet-4-6

    generated: 8/27/2026, 11:09:48 PM

    last updated: 8/28/2026, 4:56:10 AM

    avoid.net — verified advice for a post-truth world