toobit
Buy crypto
Buy cryptoThe fastest path to your first trade
P2P tradingTrade at the best prices with multiple local payment options
Bank cardPay with Visa or Mastercard
Third-partyPay via MoonPay, Advcash, Simplex, and more
DepositTransfer from another wallet
Markets
OpportunitiesTrack market sentiment and top movers
OverviewReal-time prices for all trading pairs
Futures
USDT-M PerpetualContracts settled in USDT
USDC-M PerpetualContracts settled in USDC
Event ContractsTrade on the outcome of market events
Prediction MarketTurn insights into value
Lite PerpetualSimple contracts made for easy trading
Demo TradingPractice trading in a risk-free environment
Trading BotsAutomated grid and DCA strategies
TradFi
Trade
SpotBuy and sell cryptocurrencies
DEX +Trade popular on-chain Web3 tokens in seconds
LaunchpadAccess early-stage token listings
ConvertZero-fee instant asset swaps
API TradingAutomate trading strategies with custom scripts and apps
Toobit SynapseMarket insights driven by AI analysis
Toobit x TradingViewTrade directly from TradingView charts
Agent Trade KitEquip AI agents with trading and account skills
Rewards
Copy
Follow Lead TradersCopy trades from top-performing profiles
Be a Lead TraderShare your trades and earn commissions
More
Finance
EarnPut your idle assets to work
Partnerships
Broker ProgramMonetize API volume and trading infrastructure
Ambassador ProgramRepresent the exchange and earn monthly incentives
Toobit x Nova.MemeLaunch and trade memecoins with instant liquidity
Learn
AcademyTechnical analysis and crypto trading guides
Support CenterSelf-service help and 24/7 technical assistance
Announcement CenterLatest listings, campaigns, and official product news
NewsBreaking crypto news and market moves
BlogMarket insights and exchange updates
Explore
Toobit VIP ProgramEnjoy fee discounts and many exclusive rewards.
InsightsStay updated on the latest crypto news
Toobit CommunityConnect with The Hive, our global community of traders
3 years togetherCelebrate our journey and the community that built it
About usThe story behind the award-winning exchange
Suggestions & FeedbackShare your ideas to improve the exchange
Proof of ReservesTrust built on 100% reserves
Log in
Sign up
🔥BTC/USDT
Scan to download
iOS or Android version app
More download options

Term Finance loses $8.5 million in exploit

2026-08-24 06:09

ExploitHack

Term Finance, an Ethereum-based fixed-rate lending protocol, suffered an estimated $8.5 million exploit on Sunday after an attacker used its vault governance system to transfer ether and stablecoins, according to blockchain security firms PeckShield and CertiK. The incident appears to have struck the protocol’s strategy vaults, where governance permissions can alter core settings governing assets and risk controls.

Term Labs said it was aware of a governance exploit affecting Term vaults and would provide more information once its investigation was complete. The company did not confirm the value of funds removed, identify the affected vaults, or explain how the attacker gained the authority needed to execute the transactions.

PeckShield estimated that the attacker withdrew 2,843 ETH, valued at roughly $6.9 million at the time of its assessment, alongside 1.68 million USDC. The USDC was subsequently exchanged for about 1.68 million DAI, the security firm said. PeckShield traced the assets to one address that had initially received 2 ETH through Tornado Cash, an Ethereum mixing protocol.

CertiK placed the total loss at around $8.5 million. The difference between the firms’ estimates may reflect fluctuating ETH prices or the valuation of assets moved after the initial withdrawals.

Vault losses could erase most Ethereum deposits

The reported loss represents a severe hit to the strategy vault product relative to the capital held there before the breach. DefiLlama showed approximately $12.45 million in total value locked in the vaults before the attack, including about $8.8 million deployed on Ethereum.

An $8.55 million loss would equal roughly 68% of the vault product’s cross-chain deposits and nearly all of the capital listed on Ethereum. Term Finance’s broader protocol had about $25.8 million in total value locked before the incident, according to DefiLlama, while active loans stood at $3.79 million.

That gap illustrates the concentrated exposure created by vault products. Term’s strategy vaults are designed to deploy deposited capital across fixed-rate lending markets and variable-rate lending protocols, aiming to give users managed yield exposure. A breach of the layer responsible for allocation and vault controls can therefore affect funds that may be spread across several underlying defi venues.

Custom governance wrapper is under scrutiny

Term’s strategy vaults use the ERC-4626 tokenized vault standard and are built on Yearn V3 infrastructure, according to Term’s developer documentation. ERC-4626 is a common Ethereum standard that governs how tokenized vault deposits and withdrawals are handled.

Yearn said the exploit involved a custom governance wrapper deployed around the Term vaults, rather than the standard Yearn V3 vault configuration. The statement narrows the immediate technical focus to Term’s added governance design, though it does not establish precisely how the exploit was executed.

Term’s documentation divides authority between two roles. A manager handles auction operations, while a governor controls broader risk settings, configuration decisions and emergency functions. Governors can change the protocol controller, alter the price oracle used by the system, modify risk limits, and pause deposits or strategy activity.

Those powers are intended to let the protocol respond to market stress or operational issues. In the wrong hands, they can also provide a route to redirect funds or change the conditions under which a vault operates.

Liquidity providers are described as DAO members with the ability to veto queued governance actions. The documentation says such transactions face a seven-day timelock and that a successful veto invalidates an action before it can be executed.

Term Labs has not said which governance role the attacker controlled, whether a malicious proposal passed through the normal queue, or why the timelock and veto mechanism did not prevent the transfers. Those details will determine whether the breach stemmed from compromised permissions, a flaw in the custom governance wrapper, an implementation error in the delay mechanism, or another weakness in the vault’s control structure.

A repeat problem for protocol risk controls

The exploit is Term Finance’s second known loss event. In April 2025, a misconfigured oracle — software that supplies external price information to blockchain applications — caused faulty liquidations in Term’s tETH market. The protocol said it recovered more than $1 million from a loss initially estimated at $1.6 million.

The two incidents involve different mechanisms, but both place attention on the systems surrounding a lending market’s core smart contracts. Oracle configuration determines whether collateral is valued correctly. Governance configuration determines who can modify the parameters that shape those valuations, strategies and emergency responses.

defi protocols often use governance to distribute administrative power rather than placing it with a single company-controlled account. The model can give depositors and token holders a formal role in major decisions, yet the protections depend on voting rules, permission boundaries and the practical ability of participants to monitor and challenge pending actions.

Previous attacks show how governance systems can become a direct route to protocol funds. In March, an attacker spent roughly $1,800 acquiring governance tokens in an incident involving Moonwell, according to reports on the event, and passed a proposal that threatened $1.08 million. In 2022, Beanstalk lost about $182 million after an attacker used a flash loan to obtain sufficient voting power for a malicious governance proposal.

The Term breach differs from those cases in one critical respect: available information does not yet show that the attacker accumulated voting tokens or used a flash loan. Term’s own documentation instead points to specialized governor and manager roles within its vault architecture. Treating the incident as a conventional token-voting takeover would go beyond the facts currently disclosed.

Recovery prospects depend on asset movement and controls

The conversion of USDC into DAI may make the stolen assets easier to move across Ethereum’s decentralized finance ecosystem, though both are traceable on public blockchains. Whether any funds can be frozen, recovered through negotiations, or intercepted at later exit points will depend on the attacker’s subsequent transactions and the legal or technical options available to affected parties.

Term Labs has not announced a compensation plan for vault depositors. Its response will likely face close scrutiny given the scale of the estimated loss relative to the vaults’ pre-exploit deposits and the unanswered questions around the seven-day governance delay.

For Term users, the immediate issue is less the protocol’s fixed-rate lending model than the governance layer that sat above its vaults. The incident has turned a set of administrative permissions, designed to manage risk, into the apparent channel through which most of the product’s Ethereum-held value was removed.


Worried about governance exploits? Strengthen your defenses by mastering DeFi basics with our DeFi security guide today.

Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.

About
About us
Terms of Use
Privacy Policy
Risk disclosure
Toobit Community
Announcement Center
Security solutions
Toobit Shield
Proof of Reserves
Services
Trade
Futures
Copy
Affiliate Program
API
Listing application
Bug bounty
Support
Support Center
Academy
Referral
Fee rate policy
Official verification
Network monitoring
Suggestions & Feedback
Buy crypto
Buy Bitcoin
Buy Ethereum
Buy Dogecoin
Buy TON
Buy SOL
Buy XRP
Contact
Customer Support
support@toobit.com
Business
listing@toobit.com
Overview
market@toobit.com
Legal
legal@toobit.com
Apps
Google Play
App Store
Android APK
Community
TwitterMediumYoutubeDiscordRedditFacebookCoinMarketCapCoinCodexCoinGeckoLinkedinQuoraThreads
Download app
Warning

© 2026 Toobit.com. All rights reserved.