Term Finance exploited for $8.47M via governance mechanism abuse — attacker wrapped $25 to cast the first-ever DAO veto vote after 16 months of zero participation.
Security & Exploits ·
An attacker drained $8.47M from six Term Finance vaults on Ethereum by exploiting empty electorates in the protocol's governance system. Five of the vaults had zero wrapped voting tokens, allowing the attacker to gain 100% voting power by depositing $5 into each and wrapping the resulting shares; in a sixth vault, the attacker acquired enough additional shares to control 90.66% of votes. After gaining control, the attacker disabled a seven-day delay and replaced price oracles with a contract under their control, siphoning 2,841.74 WETH and 1,679,639 USDC before Term Finance shut down the affected vaults and revoked DAO roles the same day.