Term Labs confirms governance vulnerability affects its lending treasury
Term Labs confirmed on August 23 that a governance vulnerability has affected its lending treasury. The blockchain security company estimates that the attackers extracted approximately $8.5 million in cryptocurrency.
Summary of the incident
Term Labs confirmed that its treasury was affected by a governance breach and investigators are assessing the full damage. CertiK estimated the loss at approximately $8.5 million, but Term Labs has not publicly confirmed this figure. After the attack transaction, the identified addresses held approximately 2,843 ETH and 1.6 million DAI. PeckShield traces back to the attacker's initial access to 2 ETH funds through Tornado Cash before the vault transaction began. Term Labs has not announced a financial recovery, compensation terms, contract suspension or a technical review report on completion. The agreement said it was investigating and that more information would be released later. It has not confirmed damage estimates, the treasury affected, or explained how the attacker gained governance control.
Term Labs confirms that its vault was hit by a governance vulnerability
"We noticed a governance breach that affected Term Treasury," Term Labs said. "We will share more details after further investigation." The statement did not say whether Term Labs suspended deposits, withdrawals or governance features, nor did it identify any contracts users should avoid using. As of the writing of this report, no recovery proposals, compensation commitments or review deadlines have been announced. Term Labs operates a decentralized lending system built around fixed-rate lending, with strategic vaults allocating funds through programmed contracts. The agreement does not say whether every vault is exposed to risk or whether only specific deployments are affected.
Security firm estimates damage at US$8.5 million
CertiK classified the incident as a governance attack and estimated the damage at approximately US$8.5 million. The amount remains an external estimate and not a figure confirmed by Term Labs. PeckShield reported that the attackers stole approximately 2,843 ETH (valued at approximately $6.87 million at the time) and 1.68 million USDC. Based on its tracking, the attacker then exchanged USDC for approximately 1.68 million DAIs. These data broadly support CertiK's estimates. However, valuations may change due to asset prices, transaction costs and subsequent transfers. A complete accounting requires Term Labs to identify all affected vaults and reconcile related transactions. These findings are also similar to other recent attacks on protocol controlled funds. In related reports, a Summer.fi vault breach allegedly stole approximately $6 million. The case involves different contracts and does not explain how the Term Labs incident occurred.
Governance mechanism not yet confirmed
Term Labs described the incident as a governance breach, but neither the agreement itself nor the security companies cited have released a complete transaction-level explanation. It is unclear whether the attacker was accumulating voting rights, abusing existing powers, or exploiting weaknesses in the proposal process. Governance attacks can allow entities to transfer protocol assets using authorized voting or management functions. As explained in a previous analysis of BonkDAO governance attacks, weak quorum rules, centralized voting rights, and missing execution delays can all put controlled funds at risk. These risks are general examples rather than identified causes in the Term Labs case. PeckShield also reported that the attacker's address initially received 2 ETH from Tornado Cash. The transfer concealed the wallet's early source of funds, but did not identify the attacker or prove who controlled the address. Therefore, the association with Tornado Cash should be regarded as an on-chain fund tracking clue rather than an attribution conclusion. Investigators need exchange records, wallet clusters or other evidence to connect the address to an individual or organization.
Term Labs still needs to provide users with a recovery schedule
The next verified update should clarify which treasury and contracts were affected. Users also need to confirm whether deposits, withdrawals, governance voting and policy execution are still active. Technical reports often document malicious transactions, control paths, and failed security measures. Term Labs has not announced when it will release the material, nor has it disclosed whether it contacted attackers, law enforcement agencies, stablecoin issuers or centralized exchanges. Any repayment plan requires a confirmed total loss and a clear assessment of recoverable assets. As previously reported on another DeFi vulnerability, Resupply's recovery program uses treasury payments, insurance funds and governance approvals. Term Labs has not proposed a similar process. Until the investigation is completed, the amount of $8.5 million and the reported asset balance remain within the safety study estimate. The only confirmed disclosure in the agreement was that a governance breach affected Term Treasury.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
ETH