Term Labs hackers transferred 300 ETH to Tornado Cash after stealing $8.5 million in governance funds
According to monitoring by blockchain security agency PeckShield, a hacker who used a DeFi protocol Term Labs governance vulnerability last weekend has begun to transfer stolen funds through the cryptocurrency mixing service Tornado Cash. The attacker deposited a total of 300 ETH (approximately US$741,000) into the privacy agreement in three transactions of 100 ETH each, a move likely aimed at covering up the traces of stolen assets.
Vulnerability details and funding trends
This breach occurred on July 13, 2025. The attacker stole approximately US$8.5 million in cryptocurrency from the agreement by manipulating Term Labs 'governance mechanism. PeckShield discovered the transactions deposited in Tornado Cash on July 14 and pointed out that attackers split the transactions to circumvent detection and make it more difficult to track. Tornado Cash is a popular mixed-currency service that cuts the link between source and destination addresses on the chain, making it difficult for investigators to track the flow of funds.
This is not the first time Tornado Cash has been used in a major cryptocurrency theft. The service has been a common tool for hackers and money launderers since 2019, despite the U.S. Treasury Department imposing sanctions on it in August 2022. The sanctions target the agreement's role in laundering more than $7 billion in virtual currency, including funds from North Korean hacking groups.
Impact on DeFi Security and Regulation
The Term Labs incident highlights continuing vulnerabilities in the decentralized finance space, especially governance systems that rely on the vote of token holders. Such attacks have become increasingly common, with attackers often targeting agreements with weak enforcement mechanisms or lack sufficient checks and balances. The use of Tornado Cash in this case further highlights the ongoing tension between privacy tools and regulatory compliance.
For users and investors, this incident is a reminder of the inherent risks of DeFi. While smart contract audits and vulnerability bounty programs are common, governance vulnerabilities often escape because they involve human decision-making processes rather than code flaws. Currently, all parties are urging the agreement to implement time-locks and multi-signature requirements to prevent malicious proposals from taking effect quickly.
Importance to the cryptocurrency community
This successful money-laundering attempt may embolden other malicious actors, triggering a surge in similar attacks. At the same time, it has also put pressure on regulators to intensify their review of privacy agreements and on-chain forensic tools. For law enforcement, the case demonstrates the difficulty of tracking funds once they enter a currency mixer, although blockchain analytics companies like PeckShield continue to develop methods to de-anonymize transactions.
Term Labs has not made a public statement about the breach or the transfer of funds. The protocol team is likely coordinating with security experts and law enforcement to investigate incidents and recover stolen assets. Historically, recovery efforts have had mixed results: some funds have been frozen by exchanges or partially returned after negotiation, but there is no guarantee of success.
Conclusion
The hacking of Term Labs and subsequent deposit of funds into Tornado Cash highlights the continuing security challenges in the decentralized finance sector and the methods used by attackers to launder stolen funds. As the investigation unfolds, the incident will become a key case for the industry, emphasizing the urgency of strengthening governance safeguards and anti-money laundering measures in the crypto ecosystem.
FAQs
Q: What is Tornado Cash? How does it work?
Answer: Tornado Cash is a decentralized privacy protocol that allows users to deposit and withdraw cryptocurrency from a pool of funds, cutting the connection between senders and recipients on the chain. It uses zero-knowledge proof to enable private transactions, making it difficult to track the flow of funds.
Question: How was Term Labs attacked?
Answer: The attacker exploited a governance vulnerability in the Term Labs protocol to steal approximately $8.5 million in crypto assets, possibly by creating malicious proposals and obtaining approval from token holders, or manipulating the voting process.
Question: Can stolen funds be recovered?
Answer: Recovery is challenging, but not impossible. If funds remain on the public blockchain, law enforcement agencies and blockchain analysis companies can track them; but once funds enter currency mixers such as Tornado Cash, the difficulty of tracking will increase significantly. In the past, exchanges have frozen funds or negotiated partial return, but success is not guaranteed.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
ETH