Term Labs lost approximately $8.5 million on August 23, 2026, in a governance exploit that required no smart contract bug—only near-zero voter participation and a wallet willing to spend 0.5 ETH.

The attacker acquired 90.7% of the ETH Meta Vault's voting supply and all voting power in five USDC vaults. Six days after the initial deposit, a quietly filed proposal became executable, allowing the attacker to eliminate the timelock delay and drain the funds.

The Exploit Mechanics

Term Labs' vaults used Aragon TokenVoting, with voting power represented separately from ordinary vault shares. Users had to deposit into a strategy vault and then opt in by wrapping their shares into a governance token to obtain voting power. Depositing alone conferred no voting rights.

Almost no users wrapped their shares, creating a vulnerability: total voting-token supply on the ETH Meta Vault was just 0.5352. The attacker held 0.4852, or roughly 90.7% of the supply, after depositing about 0.5 ETH and wrapping the resulting vault shares. Across the USDC vaults, the attacker reportedly held all active voting power in four of the five affected vaults.

While the formal governance settings appeared reasonable—a 50% support threshold, 5% minimum participation, and a voting window of just over six days—these thresholds created no meaningful opposition when a single wallet constituted nearly all active voting power. The minimum proposer-voting-power setting was zero, meaning the attacker could file proposals without any prior commitment.

Attack Execution

The attacker's first action upon proposal execution was to set the Zodiac Delay module's cooldown and expiration to zero, eliminating the transaction delay designed to slow dangerous actions. The attacker then recalled capital from legitimate strategies, added an attacker-controlled strategy contract to the vault, assigned it an effectively unlimited debt ceiling, and funded it with the recalled assets.

Approximately 2,843 WETH and 1.68 million USDC were drained, according to monitoring firm PeckShield. The USDC was subsequently swapped into DAI.

Response and Aftermath

Defimon, a Decurity monitoring bot, first flagged the exploit on August 23, posting transaction hashes and attacker addresses. Term Labs confirmed the governance exploit shortly afterward but did not initially provide a loss estimate or technical explanation.

In a later public update, Term Labs stated that all Term Meta Vaults had been shut down irreversibly and their DAO governance roles revoked. The shutdown permanently prevented further deposits, though withdrawals remained open. The protocol stated that its investigation indicated the underlying Term protocol and direct borrowing and lending markets had not been affected.

Yearn, whose V3 architecture Term's vault contracts were built on, clarified that the exploit ran through a custom governance wrapper and did not apply to standard Yearn vault setups. Funds in standard Yearn vaults remained safe and unaffected.

Governance Vulnerability

The incident highlights the risks of low-participation governance systems. When the cost of acquiring a controlling stake is minimal—0.5 ETH in this case—and the payoff is $8.5 million, the economic incentive for such attacks becomes clear. The vulnerability was not in Term's core vault contracts but in the governance arithmetic paired with governance authority broad enough to turn that arithmetic into an exit.

Term Labs did not explain how a wallet with minimal economic exposure could acquire effective governance control in the first place, nor did it address why its end-of-day update disclosed less information than the public record had already established.

The incident raises questions about the adequacy of timelock protections when the same governance mechanism that sets the timelock can also disable it, and whether governance participation rates should be a key security metric for DeFi protocols.