The $8.5M DAO heist that cost $951 to pull off: how Term Labs got governance hijacked

56 minutes ago 2



An attacker bought a controlling stake in a DAO governance token for less than $1,000, passed malicious proposals, and drained $8.5 million from strategy vaults. The exploit exposes a vulnerability that most DeFi protocols have not patched. Summary An attacker spent approximately $951 to acquire a controlling share of Term Labs’ governance tokens, then passed proposals that drained roughly $8.5 million from the protocol’s strategy vaults on August 23, 2026. The stolen assets included 2,843 ETH (approximately $6.87 million) and 1.68 million USDC, later swapped for roughly 1.6 million DAI, with the attacker’s initial funding traced to just 2 ETH sourced through Tornado Cash. The exploit did not involve a smart contract bug or a coding flaw. Every transaction was a permitted governance action executed by the address the protocol recognized as its legitimate governor. Term Labs permanently shut down all Meta Vault deposits and revoked DAO governance roles in response, while keeping withdrawals open for existing depositors. The attack is the fifth governance exploit of 2026 according to DefiLlama, bringing the combined total for the year to $25.1 million, led by a $20 million BonkDAO tr...

Read Entire Article