Term Labs Vault Exploit Sees $8.5M Drain as Governance Vulnerability Exposed
A recent governance exploit on Term Labs' vault infrastructure resulted in the loss of approximately $8.5 million in Ethereum and stablecoins.
The attack, which occurred on August 23, 2026, involved an attacker buying enough voting power to seize control of four Term Finance strategy vaults, including the Ethereum Meta Vault and five USDC vaults.
No contract was broken or coding flaw exploited; instead, the vulnerability lay in the governance design, low voter turnout, and insufficient guardrails on who could accumulate decision-making power over vault operations.
The attacker's initial funding traced back to just 2 ETH sourced through Tornado Cash, a privacy tool designed to sever the on-chain link between sender and receiver.