Governance Exploit Devastates Term Labs
Term Labs, the developer behind the Ethereum-based fixed-rate lending protocol, has suffered a governance exploit that resulted in a $8.5 million loss.
The attack bypassed safeguards including a seven-day timelock and veto power from liquidity providers, which are meant to prevent unauthorized fund transfers.
Researchers traced the initial funding to Tornado Cash, a cryptocurrency mixing service often used to obscure transaction origins.
The attacker obtained majority control over Term vault governance using just 2 ETH as initial capital, before crafting proposals that bypassed or exploited gaps in the governance structure.
Term Labs shut down deposits to all Meta Vaults immediately after the exploit became public and revoked DAO governance roles while its security team investigated the attack.