Term Labs Loses $8.5M to an Attacker Who Simply Won the Vote

Term Labs, a fixed-rate lending protocol that runs on-chain auctions on Ethereum, lost roughly $8.5 million from its strategy vaults on Sunday. Nobody found a bug. The attacker instead accumulated a controlling share of the vaults' governance tokens, the tokens that give holders votes over how vault funds are managed, and voted the money out to a wallet of their own. Crypto Briefing published the first detailed account at 10:45 UTC and COINOTAG followed in the afternoon; both carry verification from the security firms PeckShield and CertiK. Term Labs confirmed the incident on X the same day.
Two ETH in, $8.5 million out
The reconstruction in Sunday's reports begins with a wallet funded with just 2 ETH withdrawn from Tornado Cash, the mixing service that hides where money came from. From that stake the attacker built 100 percent of the voting power in four of Term Labs' five USDC strategy vaults, plus about 91 percent of its Ethereum Meta Vault, per Crypto Briefing's breakdown. Then the votes did the rest. Proposals directing vault funds to an address beginning 0xD5183 passed and executed exactly as the contracts were written to allow.
The take, itemized across Sunday's coverage: 2,843 ETH, worth about $6.87 million, plus roughly $1.68 million in USDC that the attacker promptly swapped into a matching amount of DAI. Those figures were consistent across Crypto Briefing, COINOTAG and BeInCrypto as of Sunday evening.
A vote, not a bug
Term's vaults, like much of DeFi, hand control of management functions to whoever holds the voting tokens. The design assumes a dispersed electorate. Here there was none. One actor held every vote that mattered on four vaults, and the transfer proposals passed as routinely as a parameter change.
The attack "passed through audited contracts without breaking a single line of code," Crypto Briefing wrote in its Sunday report.
The hole, in the same report's phrasing, sat "at the intersection of tokenomics, voter apathy, and insufficient access controls on vault management functions." The shape is not new. In July, as reporting at the time showed, an attacker bought their way just past quorum in BonkDAO's treasury vote and moved about $20 million on a 2.9 percent turnout. Term Labs' attacker did not need quorum games. Total control made the outcome arithmetic.
The attack surface keeps moving
By this desk's count, Sunday's drain is the fourth protocol-level security event in five days, and the only one aimed at governance. The others were failures of code: MANTRA halted its chain over a Cosmos EVM module bug and BounceBit shut its L1 for good over an authorization flaw, the pair covered here when two chains hit the kill switch. The same week, the poisoned arrayref Rust crate carried the threat upstream into Solana-adjacent build pipelines. Sunday completed the progression. First code, then configuration and supply chains, now the voting layer itself, where an audit of the contracts is no defense at all.
A two-line statement, and a wallet to watch
Term Labs' public response by press time was a single post on X: "We are aware of a governance exploit impacting Term vaults. We will share more details once it has been further investigated." No post-mortem had appeared by Sunday evening, and no recovery plan either. We could not establish whether the swapped DAI had moved beyond the attacker's address. What comes next runs through two questions: whether those funds head toward exchanges, and whether the promised details explain how one Tornado-funded wallet gathered total voting control of four vaults without anyone noticing.
Read also: Harmony's Forged Mint Took 106 Seconds