T
iTokenly

Term Finance (Term Labs) hack — August 2026

Verified — 4 sourcesLast checked September 15, 2026

Incident facts

Date of incident
Target typeLending protocol
Loss$8,500,000Price at time of incident
MethodGovernance attackThe attacker bought about $951 of governance tokens, enough to control the vault votes, passed proposals that cut to zero the delays in which liquidity providers could have intervened, then sold a counterfeit repo token priced at each USDC strategy's entire liquid balance
ChainsEthereum
OutcomeUnresolved

What happened

Term Finance lost an estimated $8.5m on 23 August 2026 when an attacker used the protocol's own governance machinery to make its vaults hand over their assets. The take was 2,843 ETH, worth roughly $6.9m, from the ETH meta vault, plus 1.68m USDC drawn from five USDC vaults and swapped into DAI. Part of the ETH meta vault's holdings had been allocated through a Morpho vault, from which about $6.8m was withdrawn during the exploit.

No contract was broken. The attacker obtained voting control through a custom governance wrapper around the vaults, and the vaults then executed the attacker's proposals as designed. Term Labs published an incident report on 2 September. According to crypto.news, a review of the takeover found that roughly $951 had bought enough governance tokens to control the votes on vaults holding millions of dollars in deposits. The proposals cut the governance delay to zero, removing the seven days and one hour in which liquidity providers could have stopped the ETH strategy change, and the three days and one hour on each of five USDC proposals. In the USDC strategies a counterfeit repo token was then priced through a redemptionValue() function that returned exactly the liquid USDC each strategy held, so a single unit could be sold for nearly its whole available balance.

Term Labs then moved every affected fixed-rate loan position out of the vaults before maturity, the last at 14:52 UTC on 25 August, so none could redeem into a compromised vault. That protected positions the attacker had not reached and recovered nothing that was taken. The Meta Vaults and affected strategies are shut, with new deposits permanently disabled and withdrawals still available. Term Labs says its V1 and V2 contracts were not compromised and its direct borrowing and lending markets kept running.

The attacker's wallet was funded with 2 ETH from Tornado Cash before the operation. PeckShield and CertiK both put the loss near $8.5m.

This is the second entry in this registry within five weeks where the exploited component was a governance path rather than a contract bug, and the pattern is the same in both: the protections existed, and the attacker acquired the authority to act inside them.

Sources

  1. The BlockSecondary · retrieved 2026-09-15
  2. Steakhouse FinancialSecondary · retrieved 2026-09-15
  3. The CryptonomistSecondary · retrieved 2026-09-15
  4. crypto.newsSecondary · retrieved 2026-09-15

Changes to this entry

  • Updated with Term Labs' incident report of 2 September, as reported by crypto.news, which explains how the timelock and liquidity-provider veto were removed, and with the recovery of fixed-rate loan positions before maturity. Those positions were never taken, so the amount is unchanged and nothing is recorded as recovered.

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Term Finance (Term Labs) hack — August 2026", iTokenly, accessed 2026-10-10, https://itokenly.com/hacks/term-finance-vaults
https://itokenly.com/hacks/term-finance-vaults

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.