Term Labs Vault Exploited for Estimated $8.5 Million
Term Labs' lending vaults have been hit by a governance exploit, draining an estimated $8.5 million in cryptocurrency. The attack occurred on August 23 and was confirmed by Term Labs, but the protocol has not publicly disclosed details of the incident.
CertiK security firm estimates that the attacker extracted approximately $8.5 million, with PeckShield tracing the exploiter's initial funding to Tornado Cash before the vault transactions began. The affected address held around 2,843 ETH and 1.6 million DAI after the attack transactions.
Term Labs has stated that it is investigating the incident but has not announced any recoveries or reimbursement terms. The protocol's strategy vaults allocate deposited funds through programmed contracts, but it remains unclear whether every vault was exposed or if the incident affected only specific deployments.
The governance mechanism behind the exploit remains unconfirmed, with Term Labs describing it as a governance attack without providing further details. Governance attacks can allow an entity to use authorized voting or administrative functions to transfer protocol assets.