๐Ÿ“… Sunday, 30 August 2026 ยท --:-- UTC Follow us
Ecosystem โ–ผ
ID EN
Celah Tata Kelola Kuras $8,5 Juta dari Vault Term Labs - Modus Lama yang Kembali Memakan Korban

Governance Loophole Drains $8.5 Million from Term Labs Vaults - A Classic Exploit Strikes Again

A governance system designed to secure the protocol instead became the gateway for theft. On August 23, 2026, Term Labs confirmed an exploit on their voting mechanism, an incident that directly impacted the lending vaults on the platform.

Blockchain security firm CertiK immediately classified the hack as a governance attack, with estimated losses reaching $8.5 million. On-chain monitor PeckShield detailed the flow of funds out of the system. According to their records, the perpetrator managed to drain approximately 2,843 ETH, valued at $6.87 million at the time of the incident. Not stopping there, the attacker also withdrew 1.68 million USDC in liquidity, which was immediately swapped for 1.68 million DAI to complicate tracking.

The preparation for this attack appeared systematic. The wallet address used by the attacker was found to have received an initial funding of 2 ETH from Tornado Cash before the theft began. This step was deliberately taken to break the trail of the funds financing the exploit, keeping the real identity behind the hack hidden.

A Repeat of a Classic Decentralization Loophole

Term Labs operates as a decentralized lending system that offers fixed-rate borrowing and lending features. This service is run through various strategy vaults controlled by the community. Unfortunately, this infrastructure ultimately turned against them.

This attack highlights recurring weaknesses in decentralized protocol design, with a pattern closely resembling the previous BonkDAO governance exploit. The perpetrator exploited three key loopholes that are often overlooked: loose quorum requirements, voting power concentrated in a few holders, and the absence of an execution delay after a decision is approved. The combination of these vulnerabilities allowed the malicious proposal to be passed and executed in a single breath, without giving the community a single second to block it.

What Remains Unanswered

To date, Term Labs’ official response remains limited to an initial confirmation of the incident. The protocol has not yet validated the exact total loss and has not announced the list of vaults successfully breached by the attacker.

Users whose funds are locked must face a lack of further information. Term Labs has not yet released a postmortem analysis document, proposed asset recovery plans, or outlined any compensation scheme for liquidity providers. The exact deadline for when further announcements will be released has also not been announced.

When the security of a smart vault is left entirely to a voting mechanism without a safety delay, it is the users who ultimately bear the risk of these split-second decisions.

Reported from crypto.news.


Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.

Share this article:
๐Ÿ“ฉ KABAR BITCOIN IN 1 MINUTE

Daily crypto news, straight to your inbox

A 1-minute digest for people always on the move. Free, unsubscribe anytime.

Total
0
Share