
Governance attack on Term Finance stole 2,843 ETH and 1.68M USDC, draining 70% of protocol TVL. Attacker used Tornado Cash. April oracle exploit hit same team.
Alpha Score of 45 reflects weak overall profile with weak momentum, weak value, strong quality, weak sentiment.
DeFi lending protocol Term Labs lost roughly $8.5 million to a governance exploit that emptied its vaults. The attacker removed 2,843 ETH, worth about $6.87 million at the time, along with 1.68 million USDC, which was later swapped into DAI, according to on-chain data.
Term Labs confirmed that its vaults had been hit by a governance exploit and said it would release more details after an investigation. The company has not identified the specific governance function or vulnerability used.
Blockchain security researchers traced the attack wallet back to a 2 ETH transfer from Tornado Cash, a mixer frequently used to obscure fund origins before or after thefts. The trail did not identify the attacker, researchers said.
Term Finance offers fixed-rate lending through on-chain auctions. The protocol's vaults hold roughly $12.26 million in total value locked, with $8.64 million deployed on Ethereum, according to DefiLlama. The $8.5 million drain removed about 70% of that liquidity, leaving approximately $3.76 million across the remaining vaults.
Governance attacks are less common than private-key compromises or bridge exploits, security researchers said. They allow attackers to use a protocol's own control mechanisms against it, turning administrative functions into attack vectors.
The incident adds to a difficult stretch for crypto security. July alone produced about $247.4 million in losses, more than triple June's total, with the Coldcard exploit accounting for roughly $116 million, according to blockchain analytics. August brought more: a flaw in the Coreum-XRPL bridge allowed nearly 200,000 XRP to be drained without compromising validator keys, and Coinsbuy lost about $7.9 million in another attack.
Term Labs was hit in April 2025 as well, when an oracle misconfiguration caused about $1.65 million in losses, the company said. The latest event puts renewed attention on whether DeFi protocols are locking down governance functions as attackers shift beyond conventional smart-contract bugs, several security researchers said. A repeat attack on the same team, even through a different mechanism, raises questions about whether Term Labs has strengthened its guardrails since the earlier incident.
The exploit also presses broader concerns for fixed-rate lending platforms that rely on on-chain auctions. If governance controls cannot protect the auction logic itself, other protocols using similar mechanisms may face scrutiny, researchers noted.
Prepared with AlphaScala editorial tooling from the source reporting linked above. Indexable analysis may include a cited Alpha Score value. Publishing checks screen each story before release. Educational coverage, not personalized advice.