TLDR: Quick overview of key points
Contents
TLDR: Term Vault governance control mechanism under review after $8.5 million vulnerability incident
Treasury design, total lockdown volume and recovery plan are still pending
Term Labs confirmed a governance vulnerability incident that security companies estimated cost its treasury approximately $8.5 million.
PeckShield tracked approximately 2,843 ETH (worth approximately US$6.87 million) and 1.68 million USDC, which was subsequently exchanged for approximately 1.68 million DAI.
Term's treasury governance mechanism uses Gnosis Safe, the Zodiac delay module, and a seven-day time lock with a DAO veto.
DeFiLlama data shows that before the breach occurred, TermFinance Vault's total locked positions were approximately US$10.87 million, of which approximately US$7.23 million was located on the Ethereum chain.
Term Labs is investigating a governance breach that security firm estimates stole approximately $8.5 million from Term Finance's treasury on August 23. The incident shifted the focus from smart contract code to the governance control mechanisms that protect agreement vaults and assets.
CertiK found that after the breach occurred, an address controlled by the attacker held approximately 2,843 ETH and approximately US$1.6 million in DAI. PeckShield estimated that the attackers stole 2,843 ETH (worth approximately $6.87 million) and 1.68 million USDC from the affected systems.
Term Labs suffers $8.5 million governance breach, affecting treasury
DeFi lending agreement @term_labs suffered a governance breach and its treasury was affected. According to PeckShieldAlert and CertiK Alert, the attack caused approximately US$8.5 million in losses held by the exploit...
USDC was subsequently exchanged for approximately 1.68 million DAI, and the attacker's initial funding came from Tornado Cash's 2ETH. Term Labs confirmed that its treasury was affected by a governance breach, but had not released a complete analysis report as of August 23. As a result, the specific steps of the attack, the treasury affected, and the specific method of breaching governance protections have not yet been confirmed.
Term Vault governance controls under review after $8.5 million vulnerability
This incident differs from traditional contract failures because early security reports pointed out that governance is an obvious way for attackers to gain treasury assets. The difference has put Term Finance's control structure at the forefront of an investigation, as investigators determine how the attackers gained access to protected funds.
The documentation forTerm specifies separate administrator and governor roles, and governance operations require delay modules through Gnosis Safe and Zodiac. These operations require a seven-day lock-up before they are implemented, providing a window for review of changes.
The treasury's liquidity provider is described as a DAO participant and has the right to veto the proposal during the delay period. According to the documentation, a successful veto can invalidate queued transactions before execution, adding a layer of protection.
However, Term Labs has not confirmed whether the vulnerability was caused by voting influence, permissions issues, configuration errors, or other governance approaches. In the absence of post-mortem analysis reports, the available evidence cannot determine which safety precautions failed, nor can it confirm that the control mechanisms described in the document are operating as designed.
Treasury design, total lock-up volume and recovery plan are still pending
Term Finance offers non-custodial, fixed-rate, over-collateralized loans based on the traditional repurchase agreement model and matches borrowers with lenders through sealed bid auctions. Lenders receive repurchase tokens representing maturing principal and interest claims, while Strategic Treasury automatically performs participation and liquidity management.
These vaults use Yearn V3 's ERC-4626 infrastructure and custom logic for auctions, portfolio limits, reserves and maturity control. Therefore, there is no evidence that Yearn V3 or Ethereum itself is vulnerable. Instead, the review remains focused on the authority and governance layers surrounding the Term Treasury implementation.
Before the breach, DeFiLlama listed total lockings of TermFinance Vaults as approximately $10.87 million, including $7.23 million on Ethereum. However, the data excludes capital deployed in Term repo tokens to avoid double counting, which makes comparisons with the estimated loss of $8.5 million unreliable. As of the time of writing, Term Labs has not announced a recovery plan, compensation framework, or confirmed the total losses to users.
It also did not disclose whether deposits, withdrawals, governance functions or specific vaults were suspended after the incident. The wallet controlled by the attacker remains the focus of tracking, but Tornado Cash's funding source alone cannot determine the attacker's identity.
For depositors, subsequent disclosures must clarify malicious governance transactions, affected contracts, proposal timing, and time-locking activities. These details will determine whether the incident involved a governance capture, authority error, or other implementation failure in the Term Finance treasury control mechanism.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
ETH