The decentralized lending protocol Term Finance lost $8.5 million due to an exploit of its governance mechanism, while the smart contracts themselves were not hacked. The attacker took advantage of specific features of the voting system in Meta Vaults and withdrew funds through a legitimate proposal that gained support due to extremely low voter turnout among token holders. The development team, Term Labs, confirmed the incident and announced the irreversible closure of all Meta Vaults along with the revocation of DAO roles, while the core protocol and direct lending markets remained unaffected.
Mechanics of Gaining Control Over Voting
The success of the attack was made possible by a misalignment between economic participation and voting rights within the protocol's ecosystem. When users deposited funds into a vault, they received a receipt token, tmvETH, confirming their share in the pool, but this asset by itself did not grant governance rights. To obtain a vote, the receipt had to be separately converted into a special governance token, gtmvETH, a step which most depositors ignored. The malicious actor deposited only 0.5 $ETH, received 0.485 tmvETH, and wrapped them into voting tokens. Their actual share of the vault's capital was a mere 0.017%, but among the issued ballots, they controlled 90.66% of the votes.
The governance rules also facilitated the exploit. Any user could create a proposal, even without holding any votes, and achieving a quorum required the participation of only 5% of the issued ballots. A simple majority was sufficient to pass a decision. After winning the vote, the attacker proposed to disable the seven-day withdrawal delay (timelock), connect their own contract, and direct the depositors' assets there. The proposal, containing 17 actions, was publicly available on the blockchain for about 145 hours. For nearly six days, a notice effectively announcing the upcoming disabling of security mechanisms and the withdrawal of funds was posted in the public ledger, yet no one utilized the possibility to veto or challenge the decision.
Chronology of Fund Withdrawal and Team's Response
The voting concluded on August 23, 2026, and just 12 seconds after the voting window closed, the `executeProposal` function was executed. The first action of the proposal set the seven-day delay (timelock) to zero, allowing for the immediate withdrawal of assets from the sub-vaults Shorewoods $ETH, August Digital $ETH, Parity Prime $ETH, and Parity Core $ETH. The funds were routed through a specially added "Fixed Recipient WETH Exit Strategy" to the attacker's address. A total of 2,841 WETH was withdrawn. Following this, similar operations occurred across five $USDC vaults, from which 1,679,639 coins were extracted. All funds were consolidated into a single wallet.
Analysts from PeckShield estimated the total damage at approximately $8.5 million, including around 2,843 $ETH (approximately $6.87 million) and 1.68 million $USDC, which were later swapped for DAI. The initial funding for the attack was carried out via Tornado Cash: the attacker's wallet received 1 $ETH from this mixer on August 17, 2026. After confirming the incident, the Term Labs team stated that all DAO governance roles had been revoked and the closure of Meta Vaults was irreversible, blocking new deposits. However, withdrawals for users remain open. The developers of the Yearn V3 infrastructure, on which the vaults were built, separately noted that the attack vector was specific to Term's custom wrapper and did not affect standard Yearn products.
Systemic Vulnerabilities of Decentralized Governance
The incident highlights critical risks that arise from the combination of a low barrier to entry for governance participation and the lack of mandatory activity from stakeholders. The quorum and threshold values allowed practically any participant to create proposals, and with the passivity of LP token holders, control over the issued ballots shifted to a minimal share of capital. Security mechanisms such as timelocks and veto rights proved ineffective because the attacker had the technical ability to disable these protections from within the proposal itself before its execution. According to on-chain analysis detailed by experts, the proposal was publicly accessible for about six days, and the only vote was cast by the attacker themselves.
Prior to the incident, the total value locked (TVL) in Term Finance vaults was about $12.45 million, with approximately $8.8 million on the Ethereum network. The withdrawn amount corresponds to roughly 68% of this product's TVL. The situation indicates the need to reconsider governance architecture in DeFi protocols, where voting rights are automatically tied to economic participation, and parameters like quorum and delay settings are protected from modification through ordinary proposals. The current state of the protocol implies the continued functionality of the core lending markets alongside the complete shutdown of the Meta Vaults segment.
The hack of Term Finance through the voting mechanism exposed fundamental design flaws in governance systems with low participant turnout and separable voting rights. The withdrawal of 68% of a product's TVL through a legitimate procedure underscores that formal correctness in smart contract execution does not guarantee the safety of assets when there are architectural oversights in decision-making logic.
AI Opinion
The situation demonstrates the classic problem of an "empty quorum," where minimal activity is interpreted by the system as legitimate consensus. Statistics confirm that over the past decade, hackers have stolen over $17 billion, and the primary cause of losses has not been code vulnerabilities but the compromise of keys and governance logic. The technical architecture of protocols often allows for the alteration of security parameters by the very same mechanism those parameters are meant to protect.
The machine sees here not a coding error, but an inevitable consequence of a design where the silence of the majority is equated with consent. Should decentralized systems implement rigid constitutional limits on modifying fundamental security rules, even if this contradicts the idea of the community's complete sovereignty?





