Term Finance, an Ethereum-based fixed-rate lending protocol built by Term Labs, lost roughly $8.5 million on August 23 after an attacker quietly bought up enough voting power to seize its strategy vaults and then voted the money out. On-chain trackers show about 2,843 ETH and 1.6 million DAI moved to a single wallet beginning with 0xD5183. No smart contract bug was involved. The attacker used the protocol’s own voting rules against it, which makes this one of the cleaner examples yet of a governance takeover draining real user deposits.
A governance attack is when someone acquires enough votes in a decentralized protocol to pass a proposal that benefits them, in this case a proposal to send the vaults’ assets to their own address. Term Finance lets holders vote on how its strategy vaults, the pooled accounts that deploy user deposits, are managed. The attacker turned that democratic control into a withdrawal button.
- An attacker drained about $8.5 million from Term Finance on August 23 through a governance vote, not a code exploit.
- They gained 100% voting control of four of five USDC strategy vaults and about 91% of the Ethereum Meta Vault, then approved a transfer to their own wallet.
- The whole operation was seeded with 2 ETH routed through Tornado Cash to hide its origin.
- The theft pushes reported August DeFi losses past $27 million, with DefiLlama already logging 17 incidents worth about $18.8 million earlier in the month.
Published: August 23, 2026 16:00 UTC
How the takeover worked
The attacker did not need a flash loan or a reentrancy trick. They accumulated voting power over time until they held a supermajority in Term Finance’s vault governance. According to Crypto Briefing, that came to full control of four of the five USDC strategy vaults and roughly 91% of the Ethereum Meta Vault.
With that majority, the attacker submitted and passed a proposal directing the vaults to send their assets to address 0xD5183. The starting capital was tiny. Reports trace the initial funding to just 2 ETH pulled through Tornado Cash, a mixing service that breaks the link between a wallet’s deposits and withdrawals. From that seed the attacker bootstrapped enough influence to command vaults holding millions.
Term Labs acknowledged the incident publicly and said it is investigating. The team has not confirmed whether affected depositors will be made whole.
Why governance attacks keep working
The weak point here was not the code. It was voter apathy. Studies of major decentralized autonomous organizations, the token-holder groups that run these protocols, find that a handful of addresses cast most votes while the majority of holders never participate. Turnout in many DAOs sits below 10% and sometimes drops toward 0.1%. That gap is exactly what a governance attacker buys into. When almost no one votes, a determined buyer can reach a majority cheaply.
The pattern has precedent. In 2022 an attacker took a roughly $1 billion flash loan to grab two-thirds of Beanstalk’s votes and drained about $180 million in a single block. Compound faced its own governance scare in 2024 after participation collapsed. Security firm Blockaid tracked seven governance takeovers between June and early August 2026 across Ethereum, Solana, and Base, hitting DAO tooling, memecoin treasuries, and lending protocols alike.
Term Finance’s loss is smaller than Beanstalk’s, but the mechanism is the same and the defenses are still thin. Many protocols route treasury and vault decisions through on-chain votes without time delays, spending caps, or independent review that would catch a malicious proposal before it executes.
What it means for DeFi users
For depositors, the lesson is that a protocol’s governance design is now part of its risk profile, alongside its code. A vault can be audited and still lose funds if the voting rules let one party approve a withdrawal. The Term Finance drain follows a heavy stretch for onchain security, including this week’s $3 million BounceBit exploit and the earlier Maya Protocol hack, part of a wave of 2026 incidents that also drained payment processor Coinsbuy.
Expect more attention on governance safeguards: timelocks that delay proposals, quorum floors, caps on how much a single vote can move, and emergency pause powers held by a trusted multisig. Term Labs’ response and any recovery effort will show whether the industry treats governance security as seriously as it now treats smart contract audits.
Frequently asked questions
What is Term Finance?
Term Finance is an Ethereum-based lending protocol built by Term Labs that offers fixed-rate loans. Users deposit assets into strategy vaults that put the funds to work, and token holders vote on how those vaults are managed.
How did the attacker steal $8.5 million without hacking the code?
They bought enough governance voting power to control the vaults, then passed a proposal sending the assets to their own wallet. The protocol executed the vote as designed, so no software bug was needed.
Can Term Finance recover the funds?
Recovery is uncertain. The stolen ETH and DAI went to one address, and the attacker used Tornado Cash to obscure their trail. Term Labs says it is investigating but has not committed to reimbursing depositors.








