The DeFi agreement, Term Labs, was subjected to a governance attack and multiple treasury funds were transferred, at a loss of approximately $8.5 million. The project has confirmed the incident, but the full recovery programme has not yet been published. The attack did not take direct advantage of the smart contract code gap, but instead controlled the transfer from the vault by obtaining sufficient voting rights.
The attackers took control of multiple vaults.
Peck Shield, a chain security agency, disclosed that the attackers had accumulated voting rights sufficient to influence governance and subsequently controlled four USDC strategic vaults, as well as about 91 per cent of Etheum Meta Vault voting rights. Upon taking the lead, the address concerned can facilitate the proposal and complete its approval.
Following the adoption of the proposal, the Treasury transferred assets to the purses controlled by the attackers, in accordance with the governance directive. This means that the incident is closer to a lack of governance rather than a common contractual gap being exploited.
Transferred assets include ETH and DAI
Peck Shield states that the assets transferred included approximately 2,843 ETH, approximately $6.87 million at current prices and approximately $1.6 million DAI. The report also mentioned that USDC, which had earlier been converted to DAI, had been approximately US$ 1.68 million.
- About 2,843 ETH were transferred out
- About $1.6 million DAI was transferred
- About $16.8 million.
The stolen funds are known to have subsequently been pooled into a major wallet address. The security agencies also indicated that the attackers had used the wallets for the operation in question and that the initial funds allegedly came from only two ETHs transferred from Tornado Cash.
The project party is still investigating the extent of the loss
Term Labs stated that the governance gap affected its vault and that the investigation was still ongoing. The amount recoverable has not yet been accounted for by the project participants, nor has a complete user funding treatment been provided.
The incident also revealed another risk at DeFi’s governance level. The attackers do not need to find the wrong code in the contract or to be able to complete the transfer of funds through governance mechanisms, suggesting that the audit does not cover all security issues.
This is the second big financial accident.
In May 2025, Term Finance lost approximately $1.5 million due to a small-digital error in an upgrade, and the funds were subsequently recovered. This loss is larger than the previous one, and the problem is in governance control rather than prophecies.
