Crypto news report · source clearly identified

Term Labs Governance Takeover Drains $8.5 M After $951 Token Purchase

An attacker bought a controlling stake in Term Labs’ governance token for under $1,000, passed proposals and moved $8.5 million from strategy vaults, highlighting a structural governance vulnerability in DeFi.

An attacker acquired enough Term Labs governance tokens for approximately $951, giving them a majority voting share. Using that authority, they submitted and approved proposals that transferred assets from four USDC strategy vaults and the Ethereum Meta Vault to a wallet they controlled.

How the exploit unfolded

The attacker purchased the tokens on the open market, achieving roughly 91 % control of the Ethereum Meta Vault and full control of the USDC strategy vaults. The proposals were submitted correctly, voted on with the newly‑acquired tokens, and executed by the vault contracts exactly as the governance system dictated. No smart‑contract bug, oracle manipulation, or flash loan was involved; the code functioned as designed.

Assets stolen

  • 2,843 ETH (about $6.87 million)
  • 1.68 million USDC, later swapped for roughly 1.6 million DAI

The initial funding for the attack traced to two ETH moved through Tornado Cash.

Protocol response

Term Labs halted all Meta Vault deposits, revoked DAO governance roles, and kept withdrawals open for existing depositors. The incident was confirmed on X on August 23 2026, and security firms PeckShield and CertiK verified the exploit, identifying the attacker’s address as 0xD5183d8BfC65a50863C62aF2538198A8288FFc13.

Broader context

This is the fifth governance‑related exploit recorded in 2026, bringing total losses for the year to $25.1 million. A similar attack on BonkDAO in July 2026 involved a $4 million token purchase to seize a $20 million treasury.

Underlying vulnerability

The attacks exploit a structural weakness: when a protocol’s governance token market cap is far lower than the value of assets it controls, acquiring a majority stake becomes economically feasible. Without safeguards such as time‑locks, multi‑signature execution, or secondary review mechanisms, a malicious proposal can be enacted immediately.

Implications for DeFi

Term Labs’ custom governance layer sits atop Yearn V3 vault infrastructure. Yearn clarified that the vulnerability resides in the additional governance wrapper, not in its core vault code. The incident underscores the risk of thinly distributed governance tokens and the need for protocols to monitor the token‑to‑asset ratio and implement protective controls.

Source & attribution

News Source

Publisher
crypto.news
Original date
August 25, 2026, 7:43 AM
Original headline
The $8.5M DAO heist that cost $951 to pull off: how Term Labs got governance hijacked
View original report ↗