Term Finance (2026) — Crypto Hack
Not RecoveredAttacker bought a controlling stake in Term Finance's thinly held vault governance token with ~2 ETH, then passed proposals draining ~68% of Meta Vault assets (~$8.5M) despite a 7-day timelock and LP veto.
Summary
Attacker bought a controlling stake in Term Finance's thinly held vault governance token with ~2 ETH, then passed proposals draining ~68% of Meta Vault assets (~$8.5M) despite a 7-day timelock and LP veto.
How It Was Compromised — DeFi via Governance Exploit (Vote Buying)
On August 23, 2026, an attacker seeded with 2 ETH from Tornado Cash accumulated enough of Term Finance's sparsely held vault governance token to control 100% of voting power in four of five USDC strategy vaults and ~91% of the Ethereum Meta Vault. The attacker then passed governance proposals that routed 2,843 ETH (~$6.87M) and 1.68M USDC (swapped to ~1.68M DAI) to an attacker-controlled address — about 68% of vault assets (~$8.5M per PeckShield and CertiK). The vaults ran on Yearn V3 architecture with Term's custom governance wrapper; the 7-day timelock and LP veto did not stop the attack because the veto was itself a vote the attacker had already won. Term Labs permanently shut down all Meta Vaults and revoked DAO governance roles; core lending markets were unaffected.
Fund Flow & Laundering Analysis
Seed capital of 2 ETH came from Tornado Cash; proceeds were consolidated at address 0xD5183d8BfC65a50863C62aF2538198A8288FFc13. No reimbursement commitment was made.