Flash News

Term Labs Suffers Governance Attack Resulting in Approximately $8.5 Million Loss

According to CertiK monitoring, Term Labs experienced a governance attack, resulting in an asset loss of approximately $8.5 million.
The attacker's address currently holds 2,843 ETH (approximately $7.1 million) and about 1.6 million DAI, with funds transferred from Term Vaults to a single address.
The attacker initially used only 2 ETH (from Tornado Cash) to accumulate enough voting power, gaining nearly 100% control of multiple USDC strategy vaults and about 91% control of the Ethereum base vault, subsequently closing the time lock and withdrawing funds through a governance proposal.
PeckShield confirmed that the attacker first withdrew approximately 2,843 ETH and 1.68 million USDC, then exchanged the USDC for about 1.68 million DAI, with the entire process involving no smart contract vulnerabilities, purely a manipulation of governance mechanisms.
Term Labs responded that they have identified a governance vulnerability affecting Term Vaults and are currently investigating further, with more details to be released upon completion.
The governance layer of the DeFi fixed-rate lending protocol became the focus of the attack, with funds flowing to the attacker's controlled address, benefiting the attacker who acquired voting rights at a low cost, while depositors and the protocol's TVL were under pressure. This incident drives the market to re-examine the concentration of DAO voting weight and the design of time locks.
Source: Public Information

ABAB AI Insight

Term Labs previously lost approximately $1.5 million in May 2025 due to an oracle decimal mismatch. This governance attack continues its security exposure path in the fixed-rate lending sector, where capital has previously focused more on automating strategy vaults rather than strengthening governance thresholds.
The attacker leveraged very low initial funds to gain voting rights and execute proposals, motivated by the sparse governance token structure to achieve low-cost takeover, with resources directly transferred from user deposits to the attacker's address, highlighting a structural weakness in the imbalance of voting weight distribution in DAO governance.
Comparing to previous cases where multiple DeFi protocols were maliciously passed through governance proposals, the current fixed-rate and strategy vault sector is transitioning from code audits to governance process audits, with the industry overall shifting from defending against smart contract vulnerabilities to strengthening voting participation and time lock execution.
Essentially, this represents a technological substitution before regulatory changes, where sparse governance tokens make the attack cost far lower than potential gains, and the mechanism renders time locks and veto rights virtually ineffective under low participation, exposing user assets directly to proposal execution risks.
ABAB News · Cognitive Laws

  1. Voting rights equal withdrawal rights
  2. Sparse governance equals zero-threshold attacks
  3. Time locks fail under silent majorities

Source

·ABAB News
·
4 min read
·4 hrs ago
分享: