Term Labs Hack
Reported loss
$8.5M
Malicious Proposal
What happened
On August 23, 2026, Term Labs reported a governance exploit affecting its Term Meta Vaults. Public reporting and an independent on-chain reconstruction estimated that roughly $8.5 million in WETH and USDC was removed.
How it happened
- An independent public reconstruction describes an attacker gaining effective voting control through very low active governance-token supply, then executing a proposal that removed the Zodiac Delay cooldown and expiration, recalled assets from existing strategies, and added an attacker-controlled strategy with an effectively unlimited debt ceiling.
- The reconstruction says this route did not require a defect in Term's core vault code.
- Term confirmed a governance exploit and later said its investigation had not found an impact on the core protocol or direct lending markets, but it had not published a completed technical root-cause report in the cited reporting.
Protocol details
Classification
Governance
Protocol Type
Lending Vaults
Implementation language
Solidity
Protocol links
Website
@term_labs
Evidence
Proof of concept
1 availableSources
- report Rekt: Term Labs governance incident reconstruction rekt.news
- report @PeckShieldAlert incident report x.com
- report Term Labs official incident disclosure x.com
- report @coinminutes_en incident report x.com
- analysis DeFiLlama defillama.com
- analysis The Block: Term Finance governance exploit theblock.co
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.