Term Labs Governance Attack Drains $8.5 Million From Fixed-Rate Lending Vaults

The attacker gained 100% voting control over four of five USDC strategy vaults and about 91% control of the Ethereum Meta Vault, enabling the drain.
The exploit drained roughly 2,843 ETH (about $6.87 million) and 1.68 million USDC, which were swapped into about 1.68 million DAI.
The initial seed funding was 2 ETH sourced via Tornado Cash, illustrating how mixer-linked funds can seed governance power.
The drained funds were funneled to a single wallet address beginning with 0xD5183.
Term’s fixed-rate vaults total value locked is about $12.2 million, with roughly $8.6 million on Ethereum, providing context for the scale of the exposure.
A governance exploit drained $8.5 million from Term Labs' fixed-rate lending vaults, making it the latest DeFi protocol hit by an attack that bypassed code vulnerabilities entirely. PeckShield confirmed the attacker removed roughly 2,843 ETH and 1.68 million USDC, which were then converted to DAI. The incident highlights a growing DeFi weakness: hackers can steal funds by seizing voting control over a protocol instead of finding software bugs.
Term Labs, a decentralized lending platform built around fixed-rate on-chain loans similar to traditional finance, reported the exploit affecting its vaults. CertiK and PeckShield both traced the attack and confirmed the scale of losses. The attacker started with just 2 ETH sourced through Tornado Cash, then used it to gain near-total voting power over multiple vaults — a method that exposes a critical weakness in how DeFi governance systems work.
The hacker achieved near-total voting dominance across Term Labs' vaults with a tiny initial investment. BeInCrypto reported the attacker gained 100% voting control over four of five USDC strategy vaults and about 91% control of the Ethereum Meta Vault. This voting power let them authorize the transfer of all funds directly, bypassing normal withdrawal limits and security checks.
The attacker funneled all drained funds to a single wallet address beginning with 0xD5183. The speed and completeness of the takeover suggest the attacker either found a flaw in how voting was weighted or purchased enough governance tokens to reach these thresholds quickly after seeding the initial 2 ETH through Tornado Cash.
Term Labs' loss fits a growing pattern of governance exploits that have repeatedly targeted DeFi protocols. Unlike traditional hacks that find software bugs, governance attacks use voting mechanisms themselves as weapons. Attackers accumulate enough voting tokens to pass malicious proposals and transfer user funds — a tactic that's proven effective because most protocols assume token holders act in good faith.
Crypto.news noted that Term Labs' vaults held approximately $12.2 million in total value locked, with roughly $8.6 million on Ethereum. This means the $8.5 million drain represented roughly 70% of the protocol's Ethereum exposure, a massive blow to the platform's user base and confidence in its security model.
Term Labs confirmed it is investigating the exploit but has not yet disclosed which vaults were affected or exactly how the attacker gained voting control. Yahoo Finance reported that the protocol has not committed to a public postmortem or timeline for explaining what happened. This silence raises concerns among users about transparency and whether Term Labs fully understands the vulnerability.
The incident is particularly damaging because Term Labs positions itself as a TradFi-like fixed-rate lending platform with institutional-grade security. Coinfomania highlighted that the protocol has a history of prior losses, making this exploit a second major blow. Users are now questioning whether governance-based lending protocols can be secure enough for the assets they're protecting.
Publishers
21
Articles
14
Reach
35