EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Term treasury is used-governance power becomes administrator key

2026-08-24 00:23:10
Bookmark

Key Points

Term Labs confirmed that its treasury was hit by a governance vulnerability and that official damage accounting is still in progress.

On-chain tracking by PeckShield and CertiK shows that stolen assets are approximately 2,843 ETH plus USDC/DAI.

It is estimated that the stolen amount accounted for approximately 78% of the total locked value of US$10.87 million recorded by DefiLlama at the time of release.

This attack revealed a deadly DeFi attack vector: attackers use protocol governance paths to pass "legitimate" system calls.

Term confirms that it was attacked, but the forensic report has not yet been completed.

Term Labs confirmed the governance vulnerability attack on the X platform and said the investigation is ongoing. The protocol team has not yet released a final forensic analysis report, nor has it specified the specific functions attacked, or disclosed how the attacker obtained management rights.

"We have noted governance loopholes that affect Term Treasury. We will share more details after further investigation."-- Term Labs (@term_labs), August 23, 2026

Current loss data relies on external on-chain analysis

PeckShield marks the initial withdrawal of 2843 ETH, as well as approximately US$1.68 million in USDC (subsequently converted to DAI), which came from an address deposited into 2ETH via Tornado Cash. CertiK Alert then traced the funds to the attacker's main wallet.

"#PeckShieldAlert @term_labs lost approximately US$8.5 million due to a governance breach that affected its treasury. The attackers have withdrawn approximately 2843 ETH ($6.87 million) and 1.68 million USDC ($1.68 million)-the latter has been exchanged for approximately 1.68 million DAI. The attacker initially injected funds through 2ETH... pic.twitter.com/6ZRoDD9QK7 "--PeckShield, August 23, 2026

These numbers highlight the severity of the attack, but they are still third-party estimates. Once a complete post-mortem analysis report is released, differences will often appear in the total assets ultimately withdrawn, the real-time balance of the wallet, and the actual irreparable losses.

Background analysis on the 78% TVL loss

When the news broke, DefiLlama's data showed that the TVL of Term Finance Treasury was approximately US$10.87 million. Compared with the $8.5 million stolen amount, this represents approximately 78% of the agreement's visible TVL.

This ratio does not mean that 78% of depositors 'funds have been erased. DefiLlama tracks liquid-strategy treasury balances-including idle capital and external ERC-4626 reserves-while filtering out Term repurchase tokens to avoid double counting. These dynamic indicators change rapidly as users withdraw money or asset prices revalue.

Even so, losing $8.5 million in an $11 million ecosystem turned what was originally a niche smart contract issue into a major solvency test for depositors and strategy managers.

When governance rights and capital are too close

Term's architectural document outlines a decentralized control model: operations managers oversee daily auction parameters, while the governor role controls risk limits, integrated hooks, and emergency switches. Crucially, the governor role has the following rights: designate alternate governors, replace Term controllers, adjust reserve thresholds, modify mortgage rules, and suspend core policy execution. Security mechanisms listed in the Term public document include multi-signature Gnosis Safe, seven-day time locks, and LP veto power.

The framework was supposed to protect user funds. This attack exposed another side: What happens when the regulatory mechanism itself becomes an attack vector?

Legal execution and true security

Standard smart contract vulnerabilities rely on logical flaws or mathematical errors that force code into unexpected behavior. Governance loopholes are completely different. Code usually works exactly as designed-it simply executes malicious instructions issued by an entity with privileged access.

If an attacker hijacked governance privileges rather than bypassing smart contract boundaries, then Term's contract is likely to handle technically "legitimate" operations. This provides no comfort to affected depositors. A protocol is not safe because its management functions are performed correctly; it is only safe if it becomes impossible or costly to obtain those management rights maliciously.

Auditing verifies whether the code enforces its configured permissions. They cannot ensure that voting rights are decentralized, that passive liquidity providers will detect malicious proposals, and that time locks provide enough time to prevent malicious execution.

Red Team Test for Treasury Governance

The Term event provides a clear audit list for any protocol that relies on management governance:

Access scope: Can governance parameters change policy routing, oracle pricing, or withdrawal conditions with a single call?

Voting concentration: Can voting weights or management signatures be easily obtained or borrowed?

Proposal visibility: Will the status change of the proposal be readable (in clear text) to depositors before implementation?

Emergency circuit breakers: Can independent emergency multi-signature prevent execution during an active time-lock window?

Atomic changes: Is there an upper limit on the number of risk variables that a single proposal can change?

If the proposal is difficult to understand, veto the key holder offline, or a single payload can change all security parameters at once, then a seven-day time-lock provides little protection.

Term Information that must be disclosed in the post-mortem report

Term's upcoming post-mortem report cannot just stop at the total amount. The community needs precise details: Which coffers were emptied? What specific governance operations were invoked? How do attackers seize the right to vote? And why did existing timelocks or emergency vetoes fail to stop the transaction?

Tracking wallets can show where stolen funds are going. Explaining whether Term's governance system has been bypassed, misconfigured, or weaponized as it was designed to reveal the real root cause-the key difference between code flaws and authority failures.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP