It took an attacker only around $951 in capital to drain approximately $8.5 million from decentralized finance protocol Term Labs. A technical report from the development team detailed the timeline of the August 23, 2026 governance attack, which siphoned roughly 2,843 ETH and 1.68 million USDC from the protocol’s vaults.
Security firms CertiK and PeckShield estimated total losses reached $8.5 million after the attacker swapped the entire USDC loot for approximately 1.68 million DAI. The exploit did not touch Term Labs’ core V1 or V2 contracts, targeting instead the governance mechanism on Meta Vaults.
What makes the incident particularly striking is not just the size of the loss, but the negligible cost required to seize full control over the voting system.
How $951 in Capital Captured the Vote
The sequence of maneuvers began on August 17, 2026, when the first operator received funding from Tornado Cash. Just 24 minutes later, the account submitted a governance proposal titled “Vote YES to VETO curator’s proposed vault parameter changes”. Behind what appeared to be a routine veto, the proposal concealed instructions to slash the governance delay to zero.
The following day on August 18, a second operator received funds from Tornado Cash and deployed a singleton contract. This contract combined the roles of controller, price adapter, and fake repo token into one. The scheme peaked on August 21, when a helper contract submitted seven proposals at once and cast the sole votes in the balloting, capitalizing on the minimal cost to acquire overwhelming voting rights.
ETH Exit Routing Tricks and Fake USDC Tokens
Once governance control took effect with zero time delay, fund withdrawals were executed across two separate tracks. On the ETH strategy side, four active strategies were redirected to a new module dubbed frWETH-EXIT (Fixed Recipient WETH Exit Strategy), which routed the entire WETH balance straight to the first operator.
On the USDC strategy side, five strategy DAOs were infiltrated by an “fmTERT” contract masquerading as a legitimate controller and price adapter. Through price manipulation, the attacker sold a single unit of a fake repo token with a value set equal to the entire USDC balance in the strategies.
Yearn confirmed that the targeted contracts used Yearn V3 infrastructure with Term Labs’ custom wrapper governance, rather than standard Yearn V3 vaults. A similar pattern was previously used to exploit StrongBlock in early August, which drained approximately $72,000 worth of STRONG and STRNGR tokens with minimal capital.
Position Recovery and the Fate of Meta Vaults
Term Labs completed the migration of all affected fixed-rate lending positions on August 25 at 14:52 UTC. Direct lending and borrowing markets on V1 and V2 contracts remained uncompromised and continue to operate normally.
Nonetheless, Term Labs decided to permanently shut down Meta Vaults and the affected strategies by disabling new deposits, while keeping withdrawals open for users. Further investigations remain underway alongside the publicly released technical report.
For DeFi ecosystem participants, the Term Labs incident underscores how the most fatal vulnerability often lies in the low cost of acquiring voting power to seize millions of dollars in assets.
Reported by crypto.news.
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




