
An attacker seized governance control of Term Labs, draining $8.5M from four USDC vaults and the Ethereum Meta Vault without breaking any code.
Term Labs lost around $8.5 million after an attacker seized control of its governance system and drained multiple vaults.
The attacker did not break the protocol's code. Instead, they accumulated enough voting power to pass proposals that moved funds from four USDC strategy vaults and about 91% of the Ethereum Meta Vault, according to blockchain security firm PeckShieldAlert. The attacker funded the initial wallets with 2 ETH from Tornado Cash.
The exploit is primarily a governance attack, not a typical smart contract hack. The attacker secured enough control to approve the transfers, and the vaults then followed the orders, moving roughly 2,843 ETH ($6.87 million), plus about $1.6 million in DAI and previously swapped USDC, to the attacker's wallet.
Term Labs acknowledged the breach, saying in a statement: "We are aware of a governance exploit impacting Term vaults. We will share more details once it has been further investigated." The firm has not yet provided a recovery plan or confirmed how much might be recoverable.
This is the protocol's second significant loss. In May 2025, Term Finance lost roughly $1.5 million due to an oracle decimal error during an upgrade. Those funds were later returned.
The attack underscores a class of risk in DeFi: even audited smart contracts leave governance systems exposed. An attacker who can acquire enough voting power does not need to find a bug in the code. The stolen assets currently sit in a wallet that appears to hold most of the reported haul, PeckShieldAlert said.
The timeline for a response, or for any law enforcement involvement, remains unclear.
Prepared with AlphaScala editorial tooling from the source reporting linked above. Indexable analysis may include a cited Alpha Score value. Publishing checks screen each story before release. Educational coverage, not personalized advice.