On August 23, the Ethereum-based decentralized finance lending and borrowing protocol Term Finance fell victim to a security breach. Rather than exploiting a smart contract bug, the attacker compromised the protocol's DAO governance system.
How the Attack Unfolded
The malicious actor funded the operation using 2 ETH obtained via Tornado Cash. Taking advantage of a relatively small amount of Term's governance tokens available in the market, the attacker purchased enough tokens at a low cost to secure majority voting power.
With this voting control, the attacker submitted and approved malicious governance proposals, granting them access to Term Finance vaults holding user assets. The exploit resulted in a drain of approximately $8.5 million from Ethereum. Specifically, 2,843 ETH—valued at $6.87 million—alongside 1.68 million USDC were compromised and subsequently swapped for roughly 1.68 million DAI.
Broader Ethereum Security Trends in 2026
A security report from Blockaid indicated that crypto theft and fraud losses exceeded $1 billion in the first half of 2026. Ethereum accounted for the largest share of these losses, totaling approximately $332 million, driven largely by smart contract and application-layer exploits such as bridge vulnerabilities, privileged accounts, and protocol logic issues.
This incident follows other notable events, including the Verus-Ethereum Bridge hacks which compromised approximately $7.54 million in July and nearly $11.58 million in May. Meanwhile, CoinGecko data showed that ETH declined by 48.9% over a one-year period, trading at $2,412 at press time amid attacks, regulatory uncertainty, geopolitical tensions, and macroeconomic factors.


