Term Labs lost roughly $8.5 million from its strategy vaults after an attacker bought enough governance tokens to take effective control of the protocol’s DAO, according to the project’s reported response and on-chain analysis cited in the source report.
The malicious proposals were passed on Aug. 23, 2026. The attacker is said to have spent about $951 to build a controlling position, then used the authority recognized by the protocol to move funds from the vaults. Term Labs has since shut Meta Vault deposits permanently, revoked DAO governance roles, and left withdrawals open for existing depositors.
Takeover executed through governance
The reported exploit did not rely on a smart contract bug or coding error. Instead, the attacker used governance exactly as the system allowed, after obtaining enough of Term Labs’ governance token to become the protocol’s accepted governor.
That distinction is central to the incident. The transactions were described as valid governance actions, meaning the protocol followed instructions from an address it considered legitimate. In effect, the failure was not that the software malfunctioned, but that control of the software was acquired cheaply and then used to authorize treasury-moving actions.
Stolen assets and funding trail
The assets removed from the strategy vaults included 2,843 ETH, valued in the source report at about $6.87 million, and 1.68 million USDC. The USDC was later swapped for roughly 1.6 million DAI, bringing the total haul to around $8.5 million.
The attacker’s initial funding was traced to 2 ETH that reportedly came through Tornado Cash. From that starting point, the cost of accumulating the governance position was estimated at approximately $951, a small sum relative to the value ultimately controlled and withdrawn.
Protocol response after the drain
Following the incident, Term Labs permanently disabled all Meta Vault deposits. The project also revoked DAO governance roles as part of its containment steps.
At the same time, withdrawals remain available for users who were already deposited. That leaves the protocol in a restricted operating mode while it deals with the fallout from the governance compromise.
Part of a wider 2026 pattern
According to the source article, the Term Labs incident is the fifth governance exploit recorded in 2026. Those cases have together caused about $25.1 million in losses this year.
The largest event in that tally was a reported $20 million BonkDAO treasury drain in July. The common issue highlighted by the report is the mismatch between thinly traded governance tokens and much larger pools of protocol-controlled assets, which can let a relatively small buyer gain enough voting power to direct treasury funds.
What the incident highlights next
The report says several safeguards might have reduced the risk or slowed the attack, including time locks between proposal approval and execution, multi-signature checks for large transfers, and quorum or conviction-based voting systems that make instant token accumulation less effective.
Yearn Finance said the weakness was in Term Labs’ custom governance layer rather than in Yearn’s core vault architecture. The next confirmed state of play is that Term Labs has closed Meta Vault deposits, removed DAO governance authority, and continues to allow withdrawals while the consequences of the takeover are addressed.
Source: crypto.news