Term Labs exploited for $8.5M through a governance vulnerability.
Security & Exploits ·
Term Labs suffered an approximately $8.5 million exploit stemming from a governance vulnerability affecting its vaults. The attacker extracted roughly 2,843 ETH valued at $6.87 million alongside 1.68 million USDC, which was subsequently converted to an equivalent amount of DAI. The wallet used in the attack was initially seeded with 2 ETH sourced from Tornado Cash.
The incident targeted Term Labs' governance mechanism, creating an opening that allowed the unauthorized drainage of vault assets. The attacker's conversion of stablecoin holdings and the use of privacy-mixing services to fund the wallet point to deliberate obfuscation of capital flows.
Details about the specific governance flaw, whether the protocol has halted operations, and steps being taken to recover funds or compensate users remain unclear at this stage.