Term Labs said a governance attack affected several Term Finance lending vaults, with early estimates putting the loss at about $8.5 million in ETH and DAI. According to the company’s initial assessment, the attacker did not exploit a software bug but instead used the protocol’s own governance design to gain control over key vault decisions.

The incident hit a protocol that markets fixed-rate ETH lending and, as of Aug. 23, reported more than $25 million in total value locked. With vault holdings previously at roughly $12.25 million, the drained amount appears to have removed most of the lending capacity tied to the affected vaults, though Term Labs said the full impact was still being evaluated.

How the governance setup was used

Term Finance lets users deposit into lending vaults in a model described as similar to Morpho, earning passive yield from those positions. Alongside that, the protocol used Aragon for governance, and users could optionally convert their vault share tokens into governance tokens.

That extra conversion step appears to have been central to the attack. Term Labs said ordinary vault users did not manually claim the governance tokens, allowing the attacker to gain disproportionate influence at very low cost by completing the process and accumulating the voting power attached to those vault positions.

Initial reporting on the exploit says the attacker ended up controlling four of the five drained vaults by holding all of the governance token tied to them. In that way, the attacker reportedly gained effective control for just a few dollars, despite the far larger value sitting inside the vaults.

Proposal, delay, and fund movement

On-chain data cited in the report shows the attacker’s wallets were funded with 2 ETH that came through Tornado Cash. That funding source was linked in the report to previous exploits attributed to DPRK hackers, though no further confirmation was provided in the article.

The attacker is said to have submitted a proposal on Aug. 17. The report states that the proposal included actions that were not immediately visible to voters, and after a six-day waiting period the attacker was able to change vault parameters.

Those changes then allowed funds to be withdrawn from five USDC lending vaults. After the drain, the assets were reportedly consolidated into a single known wallet holding about $1.6 million in DAI and roughly $6.9 million in ETH. As of the report, the funds had not been mixed or moved further.

Impact on the protocol

Term Labs presents Term Finance as a decentralized lending protocol focused on fixed-rate ETH loans, with an emphasis on offering more predictable lending conditions. The company has also highlighted a team with traditional finance and quantitative backgrounds, including former Citibank and Morgan Stanley professionals.

As of Aug. 23, the protocol was reported to have more than $25 million in total value locked, about $3.92 million in active loans, and a larger amount of collateral sitting in vaults. The article said all Term Finance vaults together held around $12.25 million before the incident.

Against that backdrop, the estimated $8.5 million drain represents a severe hit to the platform’s available lending reserves. Based on the figures cited, the exploit appears to have almost entirely stripped the protocol of its lending capacity in the affected vault system.

Broader context and what comes next

The report framed the incident as another example of governance risk in decentralized finance. Protocols that attach control rights to tokens can become vulnerable when participation is low, voting mechanics are poorly understood, or concentrated holders can push through proposals that favor them.

Term Labs said the real impact was still being estimated, making that the next confirmed step in the aftermath of the attack. The exploit also came during a period of other notable crypto security incidents, including cases involving Maya Protocol and The Sandbox, underscoring how governance design can become as important to protocol safety as smart contract code.

Source: Cryptopolitan