Mastodon Skip to content
pulseofnations. Real News. Global Impact.
live markets
S&P 5007,666.74▲ 3.44%NASDAQ26,090.82▲ 4.46%DOW53,452.03▲ 2.90%GOLD4,717.50▲ 15.98%WTI84.79▼ 5.06%BRENT92.37▼ 4.56%EUR/USD1.1670▲ 2.58%USD/JPY159.08▼ 2.90%DXY98.96▼ 2.47%BTC$79,516▲ 2.96%ETH$2,500▲ 2.29%SOL$96.84▲ 1.71%TOTAL CRYPTO$2.69T▲ 0.32%

Term Finance Drains $8.5M via Governance Exploit, Not Code Bug

Attacker spent 2 ETH from Tornado Cash to buy voting majority and drain vaults in DeFi lending protocol attack

Partner Surfshark VPN

Ethereum fixed-rate lending protocol Term Finance lost approximately $8.5 million on Sunday after an attacker exploited its governance system, not a smart contract vulnerability. Blockchain security firms PeckShield and CertiK confirmed the loss, which accounted for roughly 68% of the protocol’s total value locked.

The attacker drained 2,843 ETH (approximately $6.9 million) and 1.68 million USDC from Term’s Strategy Vaults. The USDC was quickly swapped for DAI. PeckShield traced the attacker’s seed funding to just 2 ETH withdrawn from Tornado Cash, the mixing protocol. The exploit executed at 06:25 UTC on August 23, after a governance proposal sat unchallenged for six days.

How the Governance Attack Worked

Unlike a traditional smart contract hack, the attacker never broke any code. Instead, they accumulated enough of Term’s thinly traded governance tokens to command a voting majority, then passed legitimate proposals instructing the vault contracts to transfer funds. The vaults, built on Yearn V3 architecture, include a seven-day timelock and LP veto mechanism, yet neither control prevented the drain.

Yearn Finance moved quickly to distance itself from the incident. The protocol said its standard vaults remain unaffected, noting that Term’s exploit targeted a custom governance wrapper unique to its implementation. The attack vector does not apply to standard Yearn vault setups, Yearn said.

Governance Attacks Rising Across DeFi

The Term Finance exploit fits a growing pattern of governance-layer attacks. DefiLlama data shows five governance attacks in 2026 worth roughly $25.1 million combined, led by the $20 million BonkDAO treasury drain in July. August alone has now seen $27 million in losses across 18 incidents, while cumulative 2026 DeFi losses have crossed $1.1 billion across 182 incidents.

The common thread across these attacks is concentrated voting power over thinly traded governance tokens. In the BonkDAO case, attacker wallets controlled nearly 99.9% of votes cast, with only seven addresses voting at all. The Term proposal sat live for six days without challenge, identical to the BonkDAO pattern.

This was not a hack. No smart contracts were exploited, and user funds were not directly targeted.

Term Labs acknowledged the exploit on X and said it would provide more detail after investigating. The protocol did not confirm the scale of losses or identify the affected vaults. Term previously recovered from a $1.6 million oracle configuration error in May 2025, which it also classified as not a hack.

SourcesPeckShield; CertiK; The Block; Yearn Finance; DefiLlama
React to this dispatch
Share this dispatch X WhatsApp Bluesky Report an error
Written by

Founder and editor of Pulse of Nations, an independent wire service covering war, geopolitics, markets and technology.

discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Next dispatch Fasset Hits $1B Valuation as SBI Group Leads $68M Series C Read →