Term Labs Project Hacked and Lost $8.5 Million

cryptonews.ruPublicado em 2026-08-23Última atualização em 2026-08-23

Resumo

The Term Labs project suffered a hack resulting in a loss of $8.5 million. The attacker exploited a vulnerability in the protocol's management mechanism to gain access to Term Vaults, withdrawing 2,843 ETH and approximately 1.6 million DAI stablecoins. The developers acknowledged the breach was caused by a critical error in the management system's logic and have imposed restrictions on the affected smart contracts to prevent further outflows. According to CertiK, the stolen funds remain in a single wallet, and the hacker has not attempted to launder them through mixers like Tornado Cash or transfer them to centralized exchanges. This is not the first incident for the Term architecture, which previously lost $1.5 million in Spring 2025 due to an incorrect liquidity oracle update. The report follows a separate security alert from PeckShield regarding a $1.7 million hack on the cross-chain project Maya Protocol.

A hacker exploited a vulnerability in the protocol's governance mechanism and gained access to the Term Vaults. As a result, they withdrew 2,843 Ether and approximately 1.6 million DAI stablecoins.

The developers of Term Labs acknowledged that the service's Term Vaults were compromised due to a critical error in the governance system's logic. Restrictions have been imposed on smart contracts associated with the vulnerable module to prevent further leaks.

The stolen funds are currently held in a single wallet belonging to the hacker. According to specialists at CertiK, the malicious actor has not attempted to transfer the assets to crypto mixers like Tornado Cash or withdraw them to centralized exchanges.

This is not the first incident for the Term architecture. Previously, in the spring of 2025, the project faced a loss of $1.5 million due to an incorrect update of the liquidity oracle.

Earlier, security specialists from the PeckShield platform reported that the decentralized cross-chain project Maya Protocol suffered a hacker attack, resulting in the withdrawal of about $1.7 million in crypto assets.

end-content

Perguntas relacionadas

QWhat vulnerability did the hacker exploit in the Term Labs attack?

AThe hacker exploited a vulnerability in the protocol's management mechanism to gain access to the Term Vaults storage.

QWhat were the approximate amounts and types of cryptocurrency stolen in the Term Labs hack?

AThe attacker withdrew 2843 ETH and approximately 1.6 million DAI stablecoins.

QWhat steps did Term Labs developers take after discovering the hack?

AThey acknowledged the critical error in the management system logic and imposed restrictions on the smart contracts related to the vulnerable module to prevent further leaks.

QWhat is notable about the current location of the stolen funds according to CertiK?

AAccording to CertiK specialists, the stolen funds are currently held in a single wallet belonging to the hacker, who has not attempted to move them to crypto mixers like Tornado Cash or centralized exchanges.

QWhat previous security incident had Term architecture experienced before this hack?

APreviously, in the spring of 2025, the project suffered a loss of $1.5 million due to an incorrect update of its liquidity oracle.

Leituras Relacionadas

Hardware Wallet Owners Lose Money: The Nuances of Cold Bitcoin Storage in 2026

The article discusses a wave of distrust towards hardware wallets by the summer of 2026, primarily triggered by security incidents. The most significant involved Coldcard wallets from Coinkite, where a firmware bug dating back to 2021 drastically reduced the cryptographic entropy for seed phrase generation. This allowed attackers to brute-force private keys, leading to losses estimated between $115-$153 million in Bitcoin. While Coldcard issued a fixed firmware, the incident damaged the reputation of all hardware wallets. Other manufacturers like Trezor and Ledger issued statements assuring their devices' security, citing their use of secure hardware elements for true random number generation. However, separate data breaches affected SafePal (exposing personal data of ~40,000 users) and Trezor (via a logistics partner, compromising data for ~14,000 users), though no private keys or crypto assets were stolen in these cases. The article clarifies that hardware wallets themselves don't "hold" crypto but store the keys to access it on the blockchain. It argues against abandoning hardware wallets entirely, pointing out that alternatives like paper, memory, or custodial exchange storage have their own significant risks. It concludes that these incidents should be viewed as specific failures, not a condemnation of the entire category. A key underlying challenge highlighted is the dual role of advancing AI, which empowers both defenders to enhance security and attackers to find vulnerabilities more efficiently.

cryptonews.ruHá 32m

Hardware Wallet Owners Lose Money: The Nuances of Cold Bitcoin Storage in 2026

cryptonews.ruHá 32m

Trading

Spot
活动图片