An attacker took majority governance control of Term Labs with just $951 and transferred $8.5 million in funds. The Term Labs team confirmed the incident on X on August 23, 2026, a finding subsequently verified independently by security firms PeckShield and CertiK. The attacker, using wallet address 0xD5183d8BfC65a50863C62aF2538198A8288FFc13, drained the funds from four USDC strategy vaults and Ethereum Meta Vaults through a governance proposal that was technically valid.
Unlike most crypto exploits that rely on code complexity, this attack involved no reentrancy tactics, oracle manipulation, or flash loan schemes. The Term Labs governance system functioned exactly as designed. The attacker simply bought tokens on the open market to secure a voting majority, submitted a proposal to transfer funds to their own wallet, and executed it without hindrance.
No Delays and No Oversight
The smooth execution of the operation stemmed from the absence of protective safeguards within the protocol. Term Labs’ governance system lacked a timelock mechanism to introduce a delay before execution. It also did not implement multi-sig approvals or secondary reviews between the voting process and asset transfers. As soon as the proposal secured the majority vote, the system immediately routed $8.5 million to the attacker’s address.
The Term Finance platform operates as a fixed-rate lending provider via on-chain auctions. The protocol stated that its core lending infrastructure remained unaffected by the vault drain. Yearn Finance also clarified that the vulnerability was located purely within Term Labs’ custom governance layer built on top of Yearn V3 infrastructure, not within the Yearn framework itself.
A Recurring Pattern of Identical Tactics
The Term Labs breach marks the fifth governance exploit of 2026 and the second incident within the past seven weeks. Seven weeks prior, BonkDAO was exploited using a similar method. The only difference was the scale of initial capital required: the BonkDAO attacker had to purchase $4 million worth of BONK tokens to secure a 99.878% majority vote, then used those voting rights to siphon approximately $20 million from the project’s treasury.
Two identical incidents in close succession demonstrate that structural vulnerabilities in DAO governance remain largely unpatched. When a multi-million-dollar vault can be unlocked simply by purchasing a majority vote without a timelock, attackers no longer need smart contract hacking skills. They simply appear as regular investors, spend $951, and follow the protocol’s own rules to drain its treasury.
Sourced from crypto.news.
Read also: What Is DeFi (Decentralized Finance)?
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




