Term Labs Confirms Governance Exploit
DeFi lending protocol Term Labs confirmed that a governance exploit drained approximately $8.5 million from its vaults on August 23. Security firms including PeckShield and CertiK identified an attacker-controlled address holding stolen assets following the breach.
According to PeckShield, the attacker removed 2,843 ETH—valued at about $6.87 million—alongside 1.68 million USDC. The stolen USDC was subsequently swapped into approximately 1.68 million DAI, while transaction tracing showed the attack was initially funded with 2 ETH from Tornado Cash. CertiK similarly identified an attacker-controlled address holding about 2,843 ETH and roughly $1.6 million in DAI.
Governance Controls Under Examination
Unlike a conventional smart contract failure, early security reports indicate that the attacker utilized a governance route to access vault assets. Term Finance's documentation outlines a control structure utilizing a Gnosis Safe, a Zodiac Delay Module, and a seven-day timelock paired with DAO veto rights.
Under normal operations, vault liquidity providers act as DAO participants who can veto proposals during the delay window to invalidate queued transactions before execution. However, Term Labs had not released a complete postmortem by August 23, leaving the exact method used to bypass these governance protections unconfirmed.
Vault Design and Unresolved Questions
Term Finance offers non-custodial, fixed-rate, overcollateralized lending modeled on traditional repurchase agreements. Its Strategy Vaults integrate Yearn V3's ERC-4626 infrastructure alongside custom logic for auctions, portfolio limits, reserves, and maturity controls. Available evidence does not point to a vulnerability in Yearn V3 or the underlying Ethereum network, keeping the focus squarely on Term's governance and permissions layer.
Prior to the incident, DeFiLlama reported TermFinance Vault Total Value Locked (TVL) at approximately $10.87 million, including about $7.23 million on Ethereum. At the time of writing, Term Labs had not announced a recovery plan, a reimbursement framework, or total user losses, nor had it disclosed whether specific vaults, deposits, or governance functions had been paused.


