Term Finance acknowledged a governance exploit affecting its vaults on August 23, 2026, after two Ethereum transactions removed 2,841.7435 wrapped ether and 1,679,639.29 USDC from six vaults. The transfers were worth an estimated $8.46 million using an ETH price of $2,387.30 at 06:25 UTC and treating USDC at its $1 nominal value.

The dollar figure is a reconstruction, not a loss total confirmed by Term Labs. The underlying token movements and transaction times are recorded on Ethereum; the protocol’s initial statement did not identify the affected vaults, publish reconciled accounting or explain how its controls were defeated.

The incident mattered because the attacker did not need to compromise Ethereum or exploit the standard Yearn V3 vault code beneath Term’s product. The attack instead used Term’s vault-governance machinery—the layer intended to supervise strategy and risk changes—to authorize the withdrawals.

What Ethereum recorded

The first proposal execution was confirmed at 06:25:47 UTC in Ethereum block 25,816,049. Its transaction transferred 2,841.7435 WETH from Term’s ETH Meta Vault through a newly added strategy controlled by the attacker.

An analysis of the transaction calls found that the proposal first set a governance delay module’s cooldown from 608,400 seconds to zero, set its expiration parameter to zero and enabled the proposal executor as a module. Subsequent actions recalled WETH from four underlying strategies, added the attacker-controlled strategy, assigned it effectively unlimited debt capacity and deposited the recalled WETH into it.

A second transaction was confirmed at 06:47:47 UTC in block 25,816,159. It executed proposals against five USDC vaults and removed a combined 1,679,639.29 USDC. The USDC was subsequently exchanged for approximately the same number of DAI before the proceeds were consolidated with the ether-side funds.

Those records establish asset movement, contract calls and chronology. They do not identify the person controlling the addresses or prove any attribution beyond the wallets and contracts visible on-chain.

A veto system without an effective veto

Term’s published governance documentation described a separation between vault managers, governors and liquidity providers. Proposed changes were subject to a delay, while holders of vault liquidity-provider tokens could vote to veto queued transactions.

The malicious ETH proposal had been created on August 17, 2026. On-chain analysis found that it remained visible for nearly six days, received the attacker’s vote and received no veto before becoming executable. The five stablecoin proposals were created on August 21 with shorter voting windows and similarly advanced without an effective opposing vote.

This makes the event more than a conventional smart-contract bug. The available evidence indicates that low participation allowed a small amount of voting power to dominate governance, while the executable proposal could alter the delay mechanism intended to constrain it. The controls existed, but their composition did not prevent governance from becoming the withdrawal path.

Measurement limits on August 23

The $8.46 million estimate is calculated as 2,841.7435 WETH multiplied by the $2,387.30 ETH observation reported for 06:25 UTC, producing approximately $6.784 million, plus 1,679,639.29 USDC at nominal value. Different ETH venues, timestamps or stablecoin marks would produce a different dollar estimate.

Term Labs had not published a technical postmortem or final depositor-loss accounting in the contemporaneous record reviewed for August 23. Dashboard total-value-locked figures were also unreliable immediately after the transactions because affected vault contracts could continue reporting assets as debt assigned to a strategy even after the tokens had left that strategy.

The verified event is therefore narrower than a final loss determination: six vaults experienced documented asset outflows through executed governance proposals. The unresolved questions were whether any funds could be recovered, how Term would write down the affected positions, whether depositors would be reimbursed and which governance permissions allowed the proposals to proceed.

Primary sourceEthereum transaction removing WETH from the Term ETH Meta Vault

The complete source packet and revision history are retained with the newsroom record.

Automated desk disclosure

Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.

Financial-risk note

This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.