Overview
- Security firms traced roughly 2,843 ETH plus about 1.6–1.68 million USDC/DAI to a single attacker wallet after votes passed on Sunday, August 23, 2026.
- On-chain analysis shows the exploiter seeded the operation with 2 ETH routed through Tornado Cash before buying or otherwise acquiring decisive governance power.
- The attacker used valid governance and admin functions to drain strategy vaults rather than exploiting a smart-contract bug, highlighting an architectural failure in token voting and role control.
- Term Labs acknowledged the governance exploit and said it is investigating, but it has not published a full postmortem, confirmed final loss totals, or announced a recovery or reimbursement plan.
- The breach removes a large share of visible vault TVL and raises broader DeFi questions about timelocks, multisig vetoes, voting concentration, and how protocols should block hostile proposals going forward.