Term Labs lost about $8.5 million on Sunday after an attacker took over voting control of its lending vaults and drained Ethereum and stablecoins.

What to Know:

  • An attacker pulled 2,843 Ether and 1.68 million in stablecoins out of Term Labs vaults on Sunday.

  • The wallet behind the theft began with 2 Ether routed through a mixer.

  • August losses across DeFi now sit above $27 million after the drain.

How the Term Labs Vault Exploit Worked

Blockchain security firm PeckShield flagged the drain on Sunday and valued the stolen Ether at $6.87 million, with another $1.68 million taken in USDC. The attacker swapped those stablecoins into roughly 1.68 million DAI. CertiK confirmed the losses separately, and neither firm found a broken contract, which points to a governance takeover rather than a coding flaw.

Term Labs acknowledged the exploit on Sunday and said it had begun investigating the affected vaults. The attacker collected 100% of the vote in four of five USDC strategy vaults and roughly 91% of the Ethereum Meta Vault, then approved transfers to a single address beginning with 0xD5183.

That wallet started with just 2 Ether withdrawn from Tornado Cash, and mixer funding often precedes onchain theft because it cuts the trail back to an exchange deposit. Term Labs runs fixed-rate lending through onchain auctions, and DefiLlama pegged the vaults at $12.2 million in deposits, with $8.6 million of that on Ethereum. The team has not named the specific governance function the attacker abused.

Also Read: Alibaba Group AI Bets Dazzling $10B on Risky Expansion Race

Why Governance Attacks Beat Audits

Security firm Blockaid tracked seven governance takeovers across three chains between Jun. 9 and Aug. 6, with combined losses of about $22 million. The wave hit DAO tooling, memecoin treasuries and DeFi protocols across Ethereum, Solana and Base.

Its analysts keep finding the same design gaps across every incident. Voting majorities cost less than the money they unlock, and nothing stands between a passing proposal and its execution. Governance also sits on top of a protocol’s most dangerous powers, including minting, treasury transfers and contract upgrades.

Blockaid recommends snapshot voting, higher quorum thresholds and real execution delays, so a community or an emergency multisig can still cancel a proposal before it moves money. Attackers can also borrow or corner voting power, so they never need a real stake in the protocol they empty.

Audits rarely catch any of this, because the code runs exactly as written and the vote does the stealing.

August DeFi Hack Losses Top $27M

DefiLlama had logged 17 incidents worth about $18.8 million in August before the Term Labs drain. The $8.5 million loss alone pushes the month past $27 million, though the tally still trails July, when 38 incidents cost roughly $254 million, including $116 million from a Coldcard wallet firmware flaw.

Other August victims include Harmony, where an attacker minted about 4 billion tokens without authorization, and payment processor Coinsbuy, drained of $7.9 million. Sandbox contained a SAND bridge vulnerability on Saturday, one day before the Term Labs drain. SlowMist counted 182 incidents worth about $956 million across the first half of 2026.

Term is also a repeat target. DefiLlama recorded a $1.65 million loss at Term Finance in April 2025, which it attributed to an oracle misconfiguration.

Governance failures stay rare but expensive, and the tracker counts five such attacks in 2026 worth $25.1 million combined, led by the $20 million BonkDAO drain in July.

Read Next: Nvidia AI Servers Jump More Than 15% in Price From Early Next Year