How $8.5 Million Was Drained From DeFi Vaults

Coinbase
Changelly


DeFi lending protocol Term Labs has suffered a governance exploit that drained roughly $8.5 million from its vaults, adding another sizable loss to an already active year for crypto attackers.

The attacker removed 2,843 ETH, valued at about $6.87 million at the time, along with 1.68 million USDC. The stablecoins were subsequently converted into approximately 1.68 million DAI, according to on-chain analysis.

Term Labs confirmed that its vaults had been affected by a governance exploit and said further details would be released after an investigation. The protocol has not yet disclosed the specific governance function or vulnerability used in the attack.

Attacker moves ETH and stablecoins

Blockchain security researchers traced the attack wallet back to an initial 2 ETH transfer from Tornado Cash. The funding trail does not identify the attacker, but mixers are frequently used to make the origin of funds harder to trace before or after crypto thefts.

Binance

Term Finance uses on-chain auctions to provide fixed-rate lending. Its vaults currently hold about $12.26 million in total value locked, according to DefiLlama, with roughly $8.64 million deployed on Ethereum.

The size of the drain is particularly notable compared with the protocol’s remaining liquidity. Governance attacks are less common than private-key compromises or bridge exploits, but they can allow attackers to use a protocol’s own control mechanisms against it.

DeFi exploits continue to pile up

The incident follows a difficult summer for crypto security. July alone produced about $247.4 million in losses, more than triple June’s total, with the Coldcard exploit accounting for roughly $116 million. The latest hack report shows that attackers have increasingly targeted not only smart contracts but also wallets, oracles, bridges and operational infrastructure.

August has brought further incidents. A flaw in the Coreum-XRPL bridge allowed nearly 200,000 XRP to be drained without compromising validator keys, while Coinsbuy lost about $7.9 million in another attack.

The broader record remains far larger. Some of the biggest crypto hacks have resulted in hundreds of millions of dollars in losses, including the $1.5 billion Bybit theft in 2025 and the $615 million Ronin Network attack.

Term Labs was also hit in April 2025, when an oracle misconfiguration caused about $1.65 million in losses. The latest incident therefore puts fresh attention on governance controls and whether DeFi protocols are adequately protecting administrative functions as attackers move beyond conventional smart-contract bugs.



Source link

BTCC

Be the first to comment

Leave a Reply

Your email address will not be published.


*