Attacker Spends $951 to Drain $8.5M from Term Finance via Governance Exploit
On August 23, 2026, an attacker drained $8.5 million from Term Finance's Ethereum-based Meta Vaults by exploiting a governance mechanism rather than any code vulnerability. Using roughly $951, the attacker purchased enough governance tokens to control over 90% of voting power in the ETH Meta Vault, since the total staked supply was extremely thin at the time. With that majority, the attacker passed proposals to eliminate the 7-day timelock and add a malicious contract disguised as a yield strategy, which routed vault funds directly to their own wallet. A built-in LP veto window of five days passed without any challenge, as no monitoring system flagged the hostile proposals and no community discussion took place. The incident highlights how governance systems with low token participation can be more vulnerable than the smart contracts they oversee.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in