$8.5 Million Drain: Governance Exploit Hits Term Labs Vaults
A governance exploit drained around $8.5 million from Term Labs' vault infrastructure on August 23, 2026. The attacker accumulated enough voting power to direct the vaults to hand over their funds, and they complied.
The attack targeted Term Vaults built on Yearn v3 contracts, rather than Term Finance's core repo lending structure. This is notable because governance-driven voting mechanisms can be exploited if there are not sufficient guardrails in place.
According to PeckShield, the attacker initially funded their operation with just 2 ETH sourced through Tornado Cash, a privacy tool designed to sever on-chain links between sender and receiver.