On August 23, 2026, approximately US$8.5 million flowed out of the deposit pool of Ethereum lending agreement Term Finance
The attackers did not exploit a security hole in the program code. They acquired enough voting rights to win votes on these pools alone. Subsequently, they decided to pay the funds to themselves and implemented the resolution.
As investors, this is the more important part of the news. An audited protocol can be hollowed out without breaking a single line of code. Therefore, anyone holding a balance in the DeFi agreement should know who has the right to vote on the use of the balance and how long it will take for such a resolution to take effect.
Term Finance Governance Attack: What Happened on August 23
Term Finance is a lending agreement on the Ethereum blockchain that arranges loans at a fixed interest rate. Users deposit the balance in so-called vaults, from which they negotiate to issue mortgages. The protocol was developed by Term Labs.
According to a report by Cryptobriefing, which cited confirmation from security companies CertiK and PeckShield, approximately 2,843 ETH and 1.6 million DAIs flowed into a single receiving address. The address identifier starts with 0xD5183. At current prices, the outflow amounts to the US$8.5 million mentioned above. Term Labs has publicly confirmed the incident and announced that it will provide a more comprehensive explanation after the investigation is completed. The team clearly distinguished this matter from a smart contract vulnerability.
Ethereum is a blockchain on which protocols run; the price movements of relevant cryptocurrencies are covered in our Ethereum price forecasts. However, price does not play a role when assessing this incident. The key is who has the right to dispose of the deposit pool.
Governance attack analysis: How voting empties the treasury
In the DeFi protocol, governance refers to the rules that decide changes. People with voting tokens can submit proposals and vote on them; once the proposal reaches the required majority, it will be implemented. This design is designed to allow protocols to operate without centralized management.
Governance attacks reverse this design. The attacker gains enough voting power to hold a majority alone and then decides what is in his favor. From a formal point of view, everything follows the rules of the agreement. There was no intrusion, no password stolen, no contract manipulated, just a winning vote.
The difference betweenand more widely known attack types is important in practice. Lightning loan attacks or re-entry vulnerabilities presuppose programming errors that can be discovered in principle by audits. Governance attacks only assume that voting rights can be sold, and no one intervened in time.
Strategic treasury and meta treasury: Which pools does the attacker control
In Term Finance, a treasury is a separate pool of deposits with its own investment strategy. Yuan Treasury collects multiple such pools and distributes the deposited funds to each pool.
Cryptobriefing details the level of control achieved: In the five USDC policy vaults, the attacker achieved 100% voting power, and in the Ethereum meta vault, it reached approximately 91%. Both far exceed the simple majority. This voting status allows proposals to be forced through and resisted any opposition.
These numbers also explain why losses were limited to specific pools. What is affected is the pool where the attacker holds a majority of voting rights. According to the information that has been released so far, people with balances in other pools have not been affected in the same way. The exact number of positions lost by each treasury has not yet been fully announced;Term Labs has said it will announce it at the end of the investigation.
Two ETH from Tornado Cash: How seed money became a voting majority
According to Cryptobrieving, seed money for the attack was surprisingly low. It is said to include only two ETH obtained through Tornado Cash. Tornado Cash is a service that obscures the connection between sender and recipient addresses on the blockchain, making tracking more difficult.
The attackers started with this seed money and gradually accumulated voting weight until they reached the above-mentioned majority. This is the troubling lesson of the case: the cost of taking over is determined by the price of the voting rights required, and has little to do with the size of the pool. When voting rights are cheap or narrowly distributed, a small amount of money can determine the fate of a large position.

In many agreements, voting rights are a tradable good: whoever collects enough can decide alone.
Audit code, empty treasury: Why audits can't detect governance attacks
Auditing is a review of program code by professional companies. It tests whether the code is performing as expected and whether it may be induced to unexpected behavior. In this case, Cryptobriefing documented that the attack process went through an audited contract and did not break a single line of code.
This is not an accusation to the auditors, but a description of the scope of the audit. The audit answers the question of whether the code is working properly. It does not answer the question of whether the distribution of voting rights allows for hostile access. Therefore, Cryptobriefing classifies this vulnerability as structural and positions it to the interplay of token distribution, low voting rates, and lack of access restrictions in vault management.
For you, this means that the official seal of the audit report describes the code, but does not explain how power is allocated in the agreement. If you use DeFi lending products, it is valuable to pay attention to both points before depositing funds. Which providers operate in this area and how they differ are described in detail in our comparison of crypto lending providers.
Timelock: Why the delay between resolution and execution determines the outcome
Timelock is a built-in waiting period between the majority of a resolution and the actual execution. During this window period, anyone can read the resolution in clear text. Anyone who does not want to leave the balance in the pool that was just passed by an unfavorable resolution can withdraw it.
Therefore, the time-lock is the only protection that will work after the vote has been lost. It cannot prevent a takeover, but it can prevent the resolution from occurring at the same second as the outflow of funds.
The consequences of the lack of a time lock can be accurately seen from another case. Whether Term Finance has set such a waiting period and how long it may be is not clear from the reports that have been published so far. Therefore, I hereby clearly record this point as pending rather than determined.
Power Tokens: How the same sequence worked in June 2026
The Token of Power case (TOP for short) is a more detailed twin of this attack pattern. TRM Labs and Blockaid analyzed this, and their descriptions were consistent on key points.
TOP is a voting token built on Ethereum. It is built based on Aragon and has a total supply of only 16,384 units. Aragon is a toolkit used to assemble agreement voting rules. According to analysis, the attacker acquired more than half of the total supply, then used voting capabilities to submit, pass and execute a proposal in a single transaction. There is no waiting period in between.
The resolution itself created 10 billion new TOPs for attackers. These tokens were put into the liquidity pool and converted into 944.2 WETH, worth approximately US$1.5 million to US$1.6 million, depending on the reference source. The analysis points to multiple reasons: the original total supply is extremely small, there is no waiting period, there is no cap on new token issuance, and protections in voting configurations are too weak.
The similarity to Term Finance lies in the sequence rather than the details. Both were purchases of voting rights, both were funding through services that confused the source, and both ended with rules-compliant resolutions that harmed depositors.
Seven takeovers on three chains: What does Blockaid statistics show for it
These are not two isolated cases, but a pattern that can be quantified. Security provider Blockaid counted seven governance takeovers on three blockchains between June and early August 2026 and estimated the total loss at approximately US$22 million in its analysis. This analysis is publicly available.
One example can be found in our own archives. On July 7, 2026, we reported on a governance attack against BONK DAO involving tens of millions of dollars in community coffers. This number comes from our report that day. This is not an independent source, but is used as a background reminder.
This month is an eventful one anyway. Prior to the outflow of Term Finance funds, data service provider DefiLlama had recorded 17 security incidents in August 2026, resulting in losses of approximately US$18.8 million.

The time lock is a component: it can only be protected if it is installed and set for a sufficient time.
Examining governance risks: Five questions to be clarified before each deposit
The following points can be found in the agreement document or its governance page. It takes a few minutes to answer the question of how easy it is for a pool to be opened by voting.
Who has the right to vote? How are voting rights distributed?
If the total supply of voting tokens is small, or if most of the shares are concentrated in a few addresses, it is cheap to get a majority of voting rights. In the TOP case, the total supply was only 16,384 tokens, and a little more than half was enough to constitute a majority.
Is there a waiting period between resolution and implementation?
If you cannot find a description of time locks, assume there is no such explanation. Without this delay, you would have no opportunity to withdraw your balance at critical moments.
Can voting directly transfer the balance?
Some agreements allow resolutions to change only parameters, such as interest rates or caps. Other agreements allow deposits to flow to any address. The second situation is dangerous.
Is there a cap on the issuance of new tokens?
If a cap is missing, majority voting rights can be expanded at will through resolution, or supply can be diluted. In the TOP case, this is the actual leverage.
What is the participation rate in recent polls?
Low participation rates significantly lower the threshold for takeover because attackers only need to exceed the actual number of votes cast.
What cannot this check achieve
It cannot protect you from attacks; it only tells you how expensive an attack is. An agreement with widely distributed voting rights and a waiting period of several days is far more difficult to take over than an agreement with neither. But in each case there is residual risk.
Revoke token authorizations: Why it doesn't help much governance attacks
After the DeFi incident, the standard recommendation is to revoke token authorizations that have been granted. Authorization is your permission to allow a contract to dispose of a certain amount of your tokens. This is a reasonable habit that you should maintain.
However, its effectiveness is limited for this type of attack. In a governance attack, it is the pool you have deposited that is emptied, not your wallet. The agreement would naturally dispose of the balances; the resolution simply changed the direction of the funds. Revoking authorization prevents future access to your wallet, but cannot retrieve the balance that has been deposited.
In this case, the only effective method is to exit the affected pool, which is only possible if the waiting period allows. This comes back to the issue of time locks.
Loss after DeFi vulnerability: What to record for tax files
If you encounter an incident like this, recording is the first thing you can do and the only thing you can't make up for it afterwards. Record when you deposit, which pool you deposit, and how much, and keep transaction records on the blockchain and dated communications from suppliers.
How to deal with such losses in tax matters is an individual case and is partially controversial. This should be left to your tax adviser and not discussed in an article; any generalizations are not serious. What you can do is provide a complete record. Tools that integrate transactions across multiple wallets can help you do most of the work.
Term Finance in May 2025: Why the nature of previous incidents is different
Term Finance already suffered a loss in May 2025. According to Cryptobrief, the loss was about $1.5 million at the time due to the wrong decimal point position in the price data service during the regular update process. The mistake was not malicious, and according to the same report, the funds were eventually returned.
The differences from current cases are important for any assessment. Internal errors can be corrected and the other party can be contacted. In the August 23 incident, the other party was external actors who received seed money through obfuscation services. As a result, Cryptobriefing described the prospects for affected depositors to recover their funds as unclear.
Term Finance Governance Attack: Information Determined and Pending Clarification
The approximate history of the incident has been determined: approximately 2,843 ETH and 1.6 million DAI were flown, voting status in the affected pool, receiving address, source of seed money, and confirmation from Term Labs, CertiK and PeckShield. These details are from Cryptobriefing's report on August 23, 2026, and are consistent with CoinDesk and BeInCrypto's reports of the same incident.
But more issues remain unclear than the title suggests. It did not disclose the specific number of positions each treasury lost, nor did it disclose how many depositors were affected. Whether there will be a waiting period between resolution and implementation, and how long, have not been announced. There is no knowledge about compensation and the identity of the attacker is unknown. Term Labs has announced that it will provide a more comprehensive explanation; until then, any statements of liability are just speculation and we will not make any assertions here.
Limitations of this paper
This paper is based on publicly available reports and analysis by Blockaid and TRM Labs. We do not analyze blockchain data ourselves. Price data at the time of the outflow comes from the sources cited and may have changed since then.
Examining governance risks: Key points
Find out who has the right to vote on your deposit pool.
Address the five issues above, especially the waiting period between resolution and execution, before depositing the balance into DeFi lending products. Our comparison of crypto lending provides an overview of vendors in this space.
Separate static assets from operating assets.
Assets you hold for a long time should not be placed in a pool that can be opened by voting. For storage that is not controlled by others, a comparison of our hardware wallets can help. If you prefer to stay on a regulated platform, a licensed supplier is more appropriate than a vault whose use is determined by vote.
If an incident is encountered, record it immediately.
Save deposit records, transaction data, and dated communications from suppliers before the interface closes. Tools from our crypto tax tool versus portfolio tracker compare you to integrate your transactions across multiple wallets.
(As of August 23, 2026. This article is not investment advice. Price and fee structures may change; please confirm terms with your supplier before purchasing.)

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BONK
ETH