EGW-NewsTerm Finance, Saldırgan Birinin Yönetim Koltuğuna Rüşvet Vererek Gelmesi Sonucu 8,5 Milyon Dolar Kaybetti
Term Finance, Saldırgan Birinin Yönetim Koltuğuna Rüşvet Vererek Gelmesi Sonucu 8,5 Milyon Dolar Kaybetti
302
Add as a Preferred Source
0
0

Term Finance, Saldırgan Birinin Yönetim Koltuğuna Rüşvet Vererek Gelmesi Sonucu 8,5 Milyon Dolar Kaybetti

Bu makale aşağıdaki dillerde mevcuttur

Someone found a $2 ETH shortcut into an $8.5 million heist on Sunday. Term Finance, an Ethereum lending protocol that lets users borrow and lend at fixed rates, watched an attacker quietly buy up TERM governance tokens, push through a vote, and walk out with control of four of its five USDC strategy vaults and roughly 91% of its Ethereum Meta Vault. No bug, no exploit in the traditional sense. Just a vote that went the wrong way.

That's the part that makes this one sting differently. There was no smart contract flaw here, no reentrancy trick, nothing for auditors to have caught in a code review. The attacker used the protocol exactly as designed. TERM holders vote on protocol decisions, including vault management, and enough voting power in one wallet is enough to pass whatever that wallet wants. Once the attacker had the votes, they had the vaults.

Security firms CertiK and PeckShield both confirmed the outflow: about 2,843 ETH, worth close to $6.87 million, plus 1.68 million USDC that got swapped into DAI shortly after. PeckShieldAlert flagged the wallet publicly, tracing it back to a starting balance of just 2 ETH pulled from Tornado Cash. That's the whole seed capital for an $8.5 million payday. Mixer funding at the front end of an attack like this is basically a tell at this point, a way to break the trail before anyone's watching.

Term Labs, the company behind the protocol, posted a short acknowledgment on X within hours: " We are aware of a governance exploit impacting Term vaults." No further detail yet on which governance function got abused, or whether depositors will see any of it back. The company said a fuller writeup would follow the investigation.

Not Term's First Rodeo

This isn't even the protocol's first eight-figure scare. Back in May 2025, Term lost roughly $1.5 million to an oracle decimal mismatch during a routine upgrade. That one was internal, non-malicious, and the funds eventually made their way back to users. This time is different. An external actor routed funds through Tornado Cash, built voting power from scratch, and drained vaults built on Yearn v3 infrastructure. Per DefiLlama, those vaults were only holding about $12.2 million in total value locked before Sunday, with $8.6 million of that sitting on Ethereum. The attacker took most of it.

Term Labs was founded in 2022 by CEO Dion Chu and raised a modest $2.5 million seed round in 2023. The protocol's pitch has always been about bringing something TradFi-familiar, fixed-rate lending through onchain auctions, into DeFi without sacrificing decentralization. The irony of losing funds specifically because of that decentralization isn't lost on anyone watching this unfold.

Governance Is Having A Rough Year

Term isn't alone here, and honestly, that's the more unsettling part of this story. DefiLlama has tagged five governance attacks in 2026 worth $25.1 million combined. BonkDAO lost about $20 million in July after an attacker built up enough BONK on Solana's Realms system to pass a proposal draining the DAO treasury, and BONK dropped nearly 40% once the stolen tokens hit the market. A smaller Ethereum protocol called TOP got hit in June with the same playbook: buy a majority of a tiny token supply, mint billions of new tokens, cash out through whatever liquidity pool is available.

The common thread is thin token supplies and low voter turnout. When most holders don't vote, the number of tokens needed to seize control drops fast, sometimes cheaply enough that an attacker can fund the whole operation with pocket change and a mixer. Term's governance system had been live for barely over a year, since staking and voting launched in April 2025.

August has already been an expensive month for DeFi security. Harmony saw roughly 4 billion tokens minted without authorization. Payment processor Coinsbuy lost $7.9 million. The Sandbox found a bridge vulnerability tied to SAND over the weekend. Add Term's $8.5 million and DefiLlama's August tally pushes past $27 million, though that's still well behind July's roughly $254 million, most of it from a Coldcard wallet firmware flaw. SlowMist's mid-year report put total 2026 incidents at 182 events worth about $956 million through June alone.

What Happens Now?

Term Labs hasn't said whether depositors will be made whole, and given how the May 2025 incident played out versus this one, that's not a given. An internal bug is one thing to unwind. Money that's already been swapped to DAI and sitting behind Tornado Cash withdrawals is another. The next real update will be Term's post-mortem, and depositors will be watching for which vaults were exposed, whether the governance parameters get rewritten, and whether any of the $8.5 million comes back at all.

Espor haberlerini ve güncellemelerini kaçırmayın! Kaydolun ve haftalık makale özetini alın!
Kaydolun

For now, the lesson going around DeFi Twitter is the same one nobody seems to act on until it's too late: audited code doesn't protect you from a vote you lost.

Canlı bir yorum
Makaleyi beğiniz mi?
0
0

Yorum

FREE SUBSCRIPTION ON EXCLUSIVE CONTENT
Receive a selection of the most important and up-to-date news in the industry.
*
*Only important news, no spam.
SUBSCRIBE
LATER