Term Labs loses $8.5M in governance exploit, DAI among assets drained
Security & Exploits ·
An attacker exploited a governance vulnerability at Term Labs, draining protocol vaults and walking away with 2,843 ETH and $1.6M in DAI.
The theft, valued at roughly $8.5M in total, was carried out by manipulating the protocol's governance mechanism rather than through a smart-contract bug in collateral pricing or liquidation logic, according to a report on X. Governance exploits of this kind typically allow an attacker to push through malicious proposals or seize control of parameters that gate access to protocol funds, letting them redirect vault assets without needing to break the underlying lending code.
The stolen funds included a substantial ETH position alongside DAI, the decentralized stablecoin originally issued by MakerDAO. DAI's design relies on overcollateralized vaults and governance-set parameters such as the stability fee and liquidation ratio to maintain its dollar peg, a structure that depends on the integrity of the governance layer that sets those levers. An exploit that compromises governance at a protocol integrating with or holding DAI underscores how the token's exposure extends beyond Maker's own contracts to the wider ecosystem of platforms that hold or route it.
The incident is corroborated by at least one additional account describing the same $8.5M loss, 2,843 ETH, and 1.6M DAI figures, indicating consistent reporting of the exploit's scale across sources.
It remains unclear how the attacker gained the governance access needed to drain the vaults, whether Term Labs has paused affected contracts or issued a public postmortem, and whether any funds can be recovered or frozen. Also unresolved is whether the exploit has broader implications for other protocols using similar governance structures or holding DAI in comparable vault arrangements.