๐Ÿ“… Saturday, 5 September 2026 ยท --:-- UTC Follow us
Ecosystem โ–ผ
ID EN
Modal $951 Menguras $8,5 Juta dari Term Labs - Voting Tata Kelola Dikuasai Sendirian

$951 Capital Drains $8.5M from Term Labs - Governance Voting Seized Solo

It took an attacker only around $951 in capital to drain approximately $8.5 million from decentralized finance protocol Term Labs. A technical report from the development team detailed the timeline of the August 23, 2026 governance attack, which siphoned roughly 2,843 ETH and 1.68 million USDC from the protocol’s vaults.

Security firms CertiK and PeckShield estimated total losses reached $8.5 million after the attacker swapped the entire USDC loot for approximately 1.68 million DAI. The exploit did not touch Term Labs’ core V1 or V2 contracts, targeting instead the governance mechanism on Meta Vaults.

What makes the incident particularly striking is not just the size of the loss, but the negligible cost required to seize full control over the voting system.

How $951 in Capital Captured the Vote

The sequence of maneuvers began on August 17, 2026, when the first operator received funding from Tornado Cash. Just 24 minutes later, the account submitted a governance proposal titled “Vote YES to VETO curator’s proposed vault parameter changes”. Behind what appeared to be a routine veto, the proposal concealed instructions to slash the governance delay to zero.

The following day on August 18, a second operator received funds from Tornado Cash and deployed a singleton contract. This contract combined the roles of controller, price adapter, and fake repo token into one. The scheme peaked on August 21, when a helper contract submitted seven proposals at once and cast the sole votes in the balloting, capitalizing on the minimal cost to acquire overwhelming voting rights.

ETH Exit Routing Tricks and Fake USDC Tokens

Once governance control took effect with zero time delay, fund withdrawals were executed across two separate tracks. On the ETH strategy side, four active strategies were redirected to a new module dubbed frWETH-EXIT (Fixed Recipient WETH Exit Strategy), which routed the entire WETH balance straight to the first operator.

On the USDC strategy side, five strategy DAOs were infiltrated by an “fmTERT” contract masquerading as a legitimate controller and price adapter. Through price manipulation, the attacker sold a single unit of a fake repo token with a value set equal to the entire USDC balance in the strategies.

Yearn confirmed that the targeted contracts used Yearn V3 infrastructure with Term Labs’ custom wrapper governance, rather than standard Yearn V3 vaults. A similar pattern was previously used to exploit StrongBlock in early August, which drained approximately $72,000 worth of STRONG and STRNGR tokens with minimal capital.

Position Recovery and the Fate of Meta Vaults

Term Labs completed the migration of all affected fixed-rate lending positions on August 25 at 14:52 UTC. Direct lending and borrowing markets on V1 and V2 contracts remained uncompromised and continue to operate normally.

Nonetheless, Term Labs decided to permanently shut down Meta Vaults and the affected strategies by disabling new deposits, while keeping withdrawals open for users. Further investigations remain underway alongside the publicly released technical report.

For DeFi ecosystem participants, the Term Labs incident underscores how the most fatal vulnerability often lies in the low cost of acquiring voting power to seize millions of dollars in assets.

Reported by crypto.news.

Read also: Anthropic Admits Claude Breached 3 Corporate Systems - Ironically, the AI Believed It Was Still in a Simulation


Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.

Share this article:
๐Ÿ“ฉ KABAR BITCOIN IN 1 MINUTE

Daily crypto news, straight to your inbox

A 1-minute digest for people always on the move. Free, unsubscribe anytime.

Total
0
Share