Term Labs confirmed on August 23, 2026, that a governance exploit had hit Term Vaults, the vault layer built on top of its fixed-rate lending protocol, Term Finance. Blockchain security firm CertiK put the estimated damage at roughly $8.5 million.
In response, Term Labs permanently shut down all Meta Vault deposits, revoked DAO governance roles, and kept withdrawals open while it investigates.
The protocol first acknowledged the incident publicly, saying it was aware of a governance exploit impacting Vaults and would share more information as the investigation progressed.
At that early stage, the team had not disclosed the full scope of the attack or exactly how it was carried out. What was clear was that the exploit specifically targeted vault governance, not the core protocol, and that verification work was still underway.

TermLabs X Post on August 23
Attacker Gains Control Over Vault Governance
According to reporting on the incident, the attacker reportedly used just 2 ETH traced to Tornado Cash to acquire TERM governance tokens. That relatively small stake was apparently enough to gain majority control over the governance of strategy vaults built on Yearn V3, which Term Vaults relies on.
Malicious Proposals Trigger Asset Withdrawals
Once in control, the attacker allegedly pushed through governance proposals that authorized withdrawals from the affected vaults. Reports indicate the exploit sidestepped the protocol's usual safeguards, including a 7-day timelock and an LP veto mechanism, by routing the attack through custom governance logic. This is important context: the incident is being described as a governance-layer vulnerability rather than a flaw in Term's core smart contracts.
| Key Detail | Reported Information |
| Estimated loss | ~$8.5 million |
| ~2,843 ETH | |
| Additional assets | ~$1.68 million USDC, reportedly swapped to DAI |
| Protocol TVL affected | ~68% of the reported $12.45 million TVL |
| Loss estimate source | CertiK Alert |
| Final loss amount | Still subject to official confirmation |
CertiK's monitoring found the attacker-linked address holding around 2,843 ETH along with DAI valued near $1.6 million at the time it was tracked. These figures represent a snapshot rather than a final tally, and Labs has indicated the official accounting could still shift as the review continues.
The Labs moved quickly once the exploit was confirmed. All Meta Vaults were shut down, and DAO-governance roles tied to those vaults were revoked. The team described the shutdown as irreversible, meaning new deposits will be permanently disabled, though existing users can still withdraw their funds.
Notably, the Labs said its investigation so far indicates the core Protocol — including its direct borrowing and lending markets — was not affected by the exploit. That distinction matters for users who interact with Term's lending markets outside of the vault products.

Official X Update 4 Hours Ago
As a precaution, the protocol is telling users to temporarily revoke approvals granted to its contracts while the investigation continues. The team also urged the community to rely only on verified updates from its official accounts and to stay alert for impersonators pushing fake recovery links or compensation offers, a common tactic following major DeFi exploits.
| Date / Stage | Event |
| Before August 23 | Attacker allegedly accumulates tokens and positions for control |
| Attack phase | The proposals used to withdraw vault assets |
| August 23, 2026 | This crypto Hack confirms awareness of the exploit |
| Initial monitoring | CertiK estimates losses near $8.5 million |
| Following update | TermLabs shuts down all Meta Vaults, revokes DAO roles |
| Current status | Deposits disabled permanently, withdrawals open, investigation ongoing |
Based on Labs' review so far, the underlying lending protocol and its direct borrowing and lending markets remain unaffected. The exploit appears confined to Vault. The Labs has cautioned that this finding could change as the investigation deepens, so it should be treated as preliminary rather than final.

PeckShieldAlert X Post
The Labs says it is working alongside external security teams on remediation and possible recovery of funds. If a shortfall remains once the review concludes, the team has said it will explore ways to address it for affected users.
A full post-mortem detailing exactly how the governance safeguards were bypassed has not yet been published, and the final loss figure should not be treated as confirmed until Labs releases it officially.
The incident is a reminder that systems can become an attack surface of their own, even when a protocol's core lending and borrowing markets keep functioning normally.
With roughly $8.5 million reportedly at stake and 68% of Vaults' TVL affected, the next milestones to watch are the final loss confirmation, progress on fund recovery, and a detailed technical breakdown of how the attacker got around Term's timelock and veto protections.
Disclaimer: This article is for informational purposes only and does not constitute financial, investment, or legal advice. Cryptocurrency markets are volatile and carry significant risk. Figures related to the exploit are based on preliminary reports and may change as the investigation progresses. Always do your own research before making financial decisions.