DeFi lending protocol Term Labs suffered a governance attack, losing approximately US$8.5 million.
DeFi lending protocol Term Labs became the target of a governance attack, and its product Term Vaults was affected. The attacker's address contained 2,843 ETH and approximately 1.6 million DAI. The DeFi market has hit a hot event: Term Labs announced that it has been attacked due to a governance vulnerability, affecting Term Vaults. According to preliminary data from security companies PeckShield and CertiK, the attack caused approximately $8.5 million in damage.
Term Labs has confirmed knowledge of the incident and is investigating the details of the attack. The parties to the agreement said they would share more information after the review was completed.
Term Labs announced for the first time
Term Labs confirmed in its statement that this incident was a governance exploit that affected Term Vaults. However, the parties to the agreement have not provided details on the specific implementation of the attack or the mechanism utilized. Therefore, it is too early to draw conclusions on the technical means of attack. Preliminary information shows that the incident is directly related to the governance mechanism of Term Vaults.
2,843 ETH in attacker address
According to CertiK's sharing, approximately 2,843 ETH were held in addresses related to the attack, and the assets were worth approximately $7.1 million at the time of the incident's announcement. There is also approximately $1.6 million in DAI in the address. As a result, the total value of these two assets in the attacker's address is approximately $8.7 million. Preliminary testing by PeckShield pointed out that the attacker extracted approximately 2,843 ETH and 1.68 million USDC, which were subsequently exchanged for approximately 1.68 million DAI. Therefore, there are differences between USDC and DAI in reporting on asset distribution from different security monitoring sources. At this stage, the total damage is estimated at approximately US$8.5 million.
An attacker obtained funds through Tornado Cash
A noteworthy detail in the incident is the historical record of the attacker's address. According to PeckShield, the attackers obtained 2ETH funding through Tornado Cash before launching the attack. This information itself does not reveal the identity of the individual or group behind the attack, but from the perspective of chain traceability, the attacker's original source of funding attracts attention.
Term Vaults incident still under investigation
Although Term Labs confirmed that this incident was a governance vulnerability exploit, it has not yet stated how the attacker specifically utilized the governance mechanism. Therefore, it is inappropriate to present the attack process as a determined technical solution at this stage. As CertiK and PeckShield monitor activity on the chain, the movements of assets in the hands of attackers are also closely watched. It is expected that when Term Labs completes its investigation, it will provide a clearer picture of how the attack occurred, which vaults were affected, and how much risk user assets are at. What is currently certain is that Term Labs 'Term Vaults system has been exploited by a governance vulnerability, initially estimated that approximately US$8.5 million in assets have been affected, and the parties to the agreement are reviewing the incident.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
ETH