Term Finance — Governance Exploit (August 2026)
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
Summary
On August 23, 2026, an unknown attacker exploited the governance mechanism of Term Finance's strategy vaults, draining approximately 2,843 ETH and 1.68 million USDC — an estimated $8.5 million — representing roughly 68% of the protocol's total vault TVL at the time. The attacker acquired 0.4852 tmvETH for approximately $951, which secured 90.66% of all active voting power in the affected pool, then self-approved malicious governance proposals to redirect vault funds to a controlled wallet. No smart contract bug was involved; the exploit operated entirely within the designed governance mechanism.
Connected Entities
1 entitiesTimeline(6 events)
2025-04-01
Term Finance suffers an oracle misconfiguration event that triggers approximately 918 ETH in unintended liquidations. The protocol recovers approximately 556 ETH and reimburses affected users. Term Labs pledges greater governance transparency and third-party validation for critical updates.
CoinDesk2026-08-23
Attacker seeds a wallet with 2 ETH sourced via Tornado Cash. Attacker spends approximately $951 to purchase and stake 0.4852 tmvETH, securing 90.66% of all active voting power in the Term Finance Ethereum Meta Vault and 100% voting control over four of five USDC strategy vaults.
Crypto Briefing2026-08-23
Attacker submits and self-approves malicious governance proposals using the acquired supermajority, directing vaults to transfer approximately 2,843 ETH and 1.68 million USDC to wallet 0xD5183d8BfC65a50863C62aF2538198A8288FFc13. Stolen USDC is subsequently converted to approximately 1.68 million DAI.
AMBCrypto2026-08-23
Term Labs acknowledges the exploit publicly, stating: 'We are aware of a governance exploit impacting Term vaults. We will share more details once it has been further investigated.' Term Labs irreversibly shuts down all Term Meta Vaults, revokes DAO governance roles, and keeps withdrawals open.
crypto.news2026-08-23
PeckShield and CertiK independently confirm the exploit and estimate total losses at approximately $8.5 million. PeckShield traces initial funding to Tornado Cash. CertiK identifies attacker wallet 0xD5183d8BfC65a50863C62aF2538198A8288FFc13.
CoinTelegraph2026-08-24
Multiple major crypto outlets publish analysis of the incident. Yearn, whose V3 vault infrastructure Term used, publicly clarifies that the exploit targeted Term's custom governance wrapper and did not affect standard Yearn vault deployments.
CoinTelegraphDecision Log
- #1publish⛓ pending8/27/2026, 11:09:57 PMhash: 3MsoRafN4NGTH2nNjqE2ZzrhDR5jhWPX2F7MC1wQMPzZ
16 of 19 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/27/2026, 11:09:48 PM
last updated: 8/28/2026, 4:56:10 AM
avoid.net — verified advice for a post-truth world