Term Finance Exploit: $951 Bought 90% Control, Drained $8.5M

A crypto attacker needed less than a thousand dollars to walk away with millions in digital assets this past weekend, and the Term Finance exploit is now being held up as a case study in how thin governance participation can turn a lending protocol into an easy target. No smart contract bug was involved. No months of reconnaissance. Just a small token purchase, a stake, and a vote nobody was watching closely enough to stop in time.
Key takeaways
- Term Finance’s vaults were drained of approximately $8.5 million in a governance exploit confirmed by blockchain security firms PeckShield and CertiK.
- The attacker spent roughly $951 to buy and stake 0.4852 tmvETH, which alone secured 90.66% of all existing voting power in the pool.
- The exploiter withdrew about 2,843 ETH and 1.68 million USDC, converting the stablecoin haul into DAI.
- The wallet’s initial funding traced back to just 2 ETH sourced through Tornado Cash.
- Users holding trUSD, strUSD, or Ecosystem Vault positions were confirmed unaffected, according to the Tori project.
Details of the Term Finance Governance Exploit
The core fact of this story is simple: an attacker turned a $951 purchase into control over $8.5 million in user funds. Blockchain security firm PeckShield confirmed the breach directly, reporting that Term Labs was hit for approximately $8.5 million after a governance exploit impacted Term’s vault products. CertiK separately corroborated the same figure, putting the total loss at roughly $8.5 million as well.
… Continue reading the full article at the original source below.

