Original briefings. Zero spin.
Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.
Term Labs Loses $8.5 Million After Attacker Bought Governance Control With 2 ETH

Term Labs confirmed on August 23, 2026, that a governance exploit hit its vault system, and blockchain security firms CertiK and PeckShieldAlert estimate the damage at approximately $8.5 million.
How It Happened
Term Labs runs Term Finance, a decentralized lending protocol built by a team that touts former Citibank and Morgan Stanley quants, promising fixed-rate ETH loans instead of the volatile floating rates common in DeFi. Vault depositors could optionally convert their share tokens into governance tokens through Aragon, the platform Term Labs used to manage voting.
According to PeckShieldAlert, the attacker funded a wallet with just 2 ETH traced to Tornado Cash, the sanctioned mixing service long associated with North Korean hacking operations. That small stake was enough because most depositors never bothered converting their shares into governance tokens. The attacker did, and ended up controlling 100% of governance on four vaults and roughly 91% of the Ethereum Meta Vault, according to PeckShieldAlert and Coinpedia.
On August 17, the attacker submitted a governance proposal containing hidden actions that weren't obvious to anyone reviewing it, according to Cryptopolitan. After a mandatory six-day waiting period, that proposal executed, changing vault parameters and authorizing withdrawals straight to the attacker's wallet. Coingabbar reported the exploit routed around Term's usual safeguards, including a timelock and an LP veto mechanism, by exploiting custom governance logic tied to the underlying Yearn V3 strategy vaults.
The haul: about 2,843 ETH, worth roughly $6.87 million, plus $1.68 million in USDC that was swapped into DAI, according to PeckShieldAlert. As of this reporting, the funds sit untouched in a single wallet, unlike faster-moving exploits where stolen crypto gets mixed within the first hour.
The Scale of the Damage
Term Labs held over $25 million in total value locked as of August 23, with $3.92 million in active loans, according to Cryptopolitan. But Coingabbar puts the vault-specific TVL at $12.45 million, meaning the attacker walked off with an estimated 68% of the vault system's funds. Cryptopolitan reported similarly, noting Term Finance vaults held $12.25 million total, meaning the exploit nearly wiped out the protocol's lending capacity.
Term Labs' public response has been minimal so far. Its only statement reads: "We are aware of a governance exploit impacting Term vaults. We will share more details once it has been further investigated."
Coingabbar reported that Term Labs has since permanently shut down all Meta Vault deposits and revoked DAO governance roles while keeping withdrawals open. Crypto News noted that as of its reporting, Term Labs had not confirmed CertiK's loss estimate, identified which vaults were affected, explained the mechanism publicly, or announced any reimbursement plan or postmortem deadline.
This isn't Term Finance's first incident. Coinpedia reported the protocol lost about $1.5 million in May 2025 due to an oracle decimal error during an upgrade, though those funds were later recovered.
Why This Matters Beyond Crypto Twitter
This exploit lands one week after other high-profile DeFi hacks hit Maya Protocol and The Sandbox, according to Cryptopolitan, part of a pattern where attackers increasingly go after governance mechanisms rather than code vulnerabilities. On-chain funding patterns tied to Tornado Cash have previously been linked to hacking operations attributed to North Korea, though no source in this reporting has attributed this specific attack to any named group or individual, and Term Labs has not identified a suspect.
The core lesson here isn't about smart contract security. Term Labs' code apparently worked exactly as designed. The problem is that "decentralized governance" in a lot of DeFi protocols is decentralized in name only, when almost nobody bothers to vote and a single wallet with a few dollars of tokens can dictate outcomes.
It's a design failure, and it's one dozens of other protocols using similar optional-governance-token schemes should be auditing right now, because the same trick works anywhere depositors don't bother converting their shares into voting power.
Term Labs has not announced a timeline for its full postmortem, has not confirmed whether users will be made whole, and has not said whether law enforcement or blockchain forensics firms are formally involved in tracing the wallet holding the stolen funds. Until Term Labs publishes that accounting, the $8.5 million figure remains an estimate from CertiK and PeckShieldAlert, not a confirmed final tally from the protocol itself.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.