Term Finance Hack

Reported loss $1.6M
Ethereum
Oracle Misconfiguration

What happened

On April 26, 2025, a faulty update to Term Finance's tETH oracle caused the Ethereum fixed-rate lending protocol to undervalue Treehouse tETH collateral, and healthy loans were liquidated. The loss was about 918 ETH, roughly $1.6 to $1.65 million. Term Labs said it was not a hack: no smart contract was exploited, and the cause was human error during a sensitive system update.

One oracle component returned prices with 18 decimals where the protocol expected 8, so tETH positions looked under-collateralized. Liquidators seized the collateral in two transactions 12 seconds apart. Term captured about 223.2 ETH (about $400,000) internally and negotiated the return of another 333 ETH (about $600,000), leaving about 362 ETH (about $650,000) unrecovered. Term said affected users would be fully reimbursed.

How it happened

  1. Term Labs pushed an update to the oracle that priced tETH collateral.
  2. One oracle component output its value with 18 decimals while the rest of the pricing path assumed 8, an internal inconsistency that made tETH look drastically cheaper than it was.
  3. Against that price, tETH-backed loans appeared under-collateralized, so they became eligible for liquidation.
  4. Liquidators seized the collateral in transactions 0x8da015d7c362a082fd23736b08dc17d3a9794086b713590273c9535a4c47a7e2 (block 22353826) and 0xaa10cc076f27fcf7fc0b0a83ad170983e6791f5349d097ef4db0592a55d64048 (block 22353827), about 918 ETH in total.
  5. Term recovered about 556 ETH through internal capture and negotiation; about 362 ETH was not recovered.

Protocol details

Classification Oracle Manipulation
Protocol Type DeFi Protocol
Implementation language Solidity

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.