Tuesday, September 15, 2026 BTC -- / --
🔍

Governance exploit drains $8.5 million from Term Labs

Make CryptoTips a preferred source on Google
Governance exploit drains $8.5 million from Term Labs
Governance exploit drains $8.5 million from Term Labs

DeFi lending protocol Term Labs has been hit by a governance exploit that has drained around $8.5 million from a number of vaults. Security researchers are now tracking a wallet that has received thousands of Ethereum and millions in stablecoins. Term Labs is investigating the incident and has not yet published a full analysis of the attack.

Attacker drains thousands of Ethereum from Term vaults

According to blockchain security firm PeckShield, the attack targets the governance of the Term vaults. The attacker managed to steal approximately 2,843 Ethereum, worth around $6.87 million, along with 1.68 million USDC, valued at $1.68 million.

The stolen USDC does not remain in that form for long. PeckShield observed the attacker swapping the full amount for roughly 1.68 million DAI. That brings the total haul to about $8.5 million.

The accompanying blockchain transaction also shows positions being unwound via Aave. In one of the visible transactions, more than 44.37 aEthWETH is burned and approximately 44.37 WETH is withdrawn, worth over $107.000 at the time.

Also notable is the origin of the initial funds in the attacker’s wallet. The address first receives 2 Ethereum through Tornado Cash. A transaction of this kind does not in itself reveal who is behind the wallet, but it does make it harder to trace the original source of the money.

Governance exploit exposes risk of DeFi vaults

In a governance exploit, an attacker abuses the mechanisms used to manage settings, parameters or permissions within a protocol. In this case, the attack appears to have specifically affected Term Labs’ vaults.

PeckShield puts the amount of stolen crypto at around $8.5 million. Security firm CertiK has also flagged the incident. Term Labs has confirmed it is investigating but has not yet shared a detailed technical explanation of the exact vulnerability.

That leaves a number of questions open. It is unclear how the attacker obtained the necessary governance rights, which vaults were specifically hit, and whether all affected components are now secure.

Term Labs is meanwhile working to assess the damage and has promised to publish more information once its investigation is further advanced. Until a full analysis is available, it remains unclear whether additional measures are needed to prevent new attacks through the same vulnerability.

Summarize this article with AI

Not financial advice. CryptoTips We are not a financial advisor and the content on this website is not financial advice. All information on this website is informative and not a recommendation to buy or sell anything. Consult an expert when making financial decisions and only invest money you can afford. You are responsible for your own investments. We use affiliate referrals and may receive commissions for these. Read our full disclaimer.

Affiliate disclosure. Some links on this site are partner/affiliate links. If you sign up with a partner through such a link, we may receive a commission at no extra cost to you. This never influences our reporting. Read our editorial guidelines.

More News

More news ›