Crypto news report · source clearly identified

Term Labs DeFi Lending Protocol Hit by Governance Exploit Losing $8.5 Million

Term Labs confirmed a governance exploit that drained approximately $8.5 million, including 2,843 ETH and 1.68 million USDC, from its vaults on Sunday.

DeFi lending platform Term Labs suffered a governance‑related breach that resulted in the loss of roughly $8.5 million. The attack, reported by security firm PeckShield, involved the unauthorized withdrawal of 2,843 Ethereum (ETH) and 1.68 million USDC from the protocol’s vaults.

How the Funds Were Moved

PeckShield valued the stolen ETH at about $6.87 million and the USDC at $1.68 million. After the withdrawal, the attacker swapped the USDC for an equivalent amount of Dai (DAI). The wallet used in the attack was initially funded with 2 ETH that had been withdrawn from the Tornado Cash mixer, a step often used to obscure the source of funds before on‑chain theft.

Impact on Term Labs

Term Labs operates fixed‑rate lending through on‑chain auctions. According to DefiLlama, the protocol’s vaults hold a total value locked (TVL) of $12.2 million, with $8.6 million on Ethereum. The specific governance function exploited has not been disclosed. The team confirmed the incident and indicated that a detailed report will follow the investigation.

Broader DeFi Security Landscape

August has seen a surge in DeFi security incidents. Prior to the Term Labs breach, DefiLlama recorded 17 incidents totaling $18.8 million for the month. The additional $8.5 million loss pushes August’s cumulative losses above $27 million, though still below July’s $254 million total from 38 incidents.

Governance attacks remain relatively rare but costly. In 2026, DefiLlama identified five governance‑related incidents amounting to $25.1 million, highlighted by a $20 million malicious proposal against BonkDAO in July. Term Labs has previously been targeted; an April 2025 incident at Term Finance resulted in a $1.65 million loss due to an oracle misconfiguration.

Other Notable August Incidents

  • Harmony suffered an unauthorized minting of roughly 4 billion tokens.
  • Payment processor Coinsbuy was drained of $7.9 million.
  • A vulnerability in the SAND bridge was exploited on Saturday.

Source & attribution

News Source

Publisher
BeInCrypto
Original date
August 23, 2026, 12:35 PM
Original headline
Another DeFi Hack: Term Labs Loses $8.5 Million in Governance Exploit
View original report ↗