Term Labs lost roughly $8.5 million on Sunday after an attacker exploited a governance vulnerability in its Term vaults, according to blockchain security firm PeckShield, cited in a Yahoo Finance report published that same day, August 23, 2026. The attacker pulled 2,843 ETH and 1.68 million USDC out of the protocol, then swapped the stablecoins into roughly 1.68 million DAI.
How the Attacker Moved the Funds
Term Labs acknowledged the breach directly in a post on its official X account, confirming that the governance exploit affected its Term vaults and that the incident remained under investigation.
According to a Yahoo Finance report on the exploit, blockchain security firm PeckShield valued the ETH portion of the theft at $6.87 million and the stablecoin portion at $1.68 million. PeckShield traced the wallet behind the attack to an initial seed of 2 ETH withdrawn from Tornado Cash, a pattern researchers flag because it breaks the trail back to an exchange deposit.
Term Labs runs fixed-rate lending through onchain auctions, and its vaults carry a combined $12.2 million in total value locked, with $8.6 million of that sitting on Ethereum, per DefiLlama.
The team has not yet named the specific governance function the attacker abused. This is not the first time Term’s infrastructure has been hit. Term Finance, run by the same team, lost $1.65 million in April 2025 to an oracle misconfiguration, and Sunday’s exploit brings a second security failure to the same protocol family within roughly sixteen months.
What This Means for DeFi Lenders
For anyone parking funds in fixed-rate DeFi protocols, the Term Labs breach is a reminder that governance code carries the same risk as the lending logic itself. Governance-specific attacks remain rarer than standard smart contract bugs, but they are far from cheap.
Our news coverage has tracked five governance-related incidents in 2026 worth a combined $25.1 million, led by a $20 million malicious proposal against BonkDAO in July, and Kelp DAO’s own $293 million exploit that drained its Ethereum restaking vaults shows how quickly a single vault-level bug can scale into a nine-figure loss.
Term Labs’ Promised Report Is the Next Signal
Term Labs said a full account of the incident would follow its investigation, and that report is the detail worth watching. Naming the exact governance function that failed will show whether other fixed-rate lending platforms built on similar vault architecture carry the same exposure, or whether this was a flaw unique to Term’s own contracts.
What this means for you: If your funds sit in a DeFi lending protocol, treat any promised post-mortem as your cue to hold off on new deposits until the team confirms exactly how the exploit happened.
This article is for informational purposes only and does not constitute financial advice. Do your own research before making any investment decisions.

