Two ETH From Tornado Cash Captured Term Finance's Vaults

An attacker seeded a wallet with two ether from Tornado Cash, bought a thin governance token, and voted Term Finance's vaults empty for $8.5 million.

Jan Whitfield News

Term Finance lost about $8.5 million on Saturday, and the attacker began with two ether. Everything else followed from that. The attacker drained the fixed-rate lending protocol built by Term Labs on August 23 at 06:25 UTC, and no contract bug played any part. Someone won a governance vote, then voted the vaults empty.

The two ether, worth under $5,000 at the day's price, came out of Tornado Cash, the same mixer where reports say 1,010 ETH vanished days earlier. That small stake was enough to buy a majority of a thinly held governance token. With it, the attacker took full voting control of four of the five USDC strategy vaults and roughly 91 percent of the Ethereum Meta Vault. Then the proposals passed. Assets moved to a wallet beginning 0xD5183, and the attacker swapped about 1.68 million USDC into 1.68 million DAI on the way out, alongside 2,843 ETH worth close to $6.87 million.

A coin nobody was watching controlled $12 million

Term Finance carried $12.2 million in total value locked, $8.6 million of it on Ethereum. Governance sat on top of that money, and governance was the soft spot. Reports of the incident describe no timelock and no meaningful delay between a proposal passing and the funds leaving, so whoever held the token held the money. Buy the votes cheaply enough and the vault opens itself. It is the same shape as a funded team steering an airdrop-heavy DAO vote, except this buyer was hostile and needed only a few thousand dollars to reach a majority.

Term Labs has been here before, though the last time was cleaner.

IncidentMay 2025August 2026
CauseOracle mismatchGovernance takeover
Reported loss$1.5 million$8.5 million
Attacker fundingNot applicable2 ETH via Tornado Cash
Funds returnedYesUnclear

Why the money may not come back

Term Labs returned the 2025 loss in full. This one looks harder to unwind. The attacker routed the funding through a mixer built to sever the on-chain link between sender and receiver, and Term Labs has said only that it is aware of a governance issue and is investigating further. No compensation plan exists yet. For Term Finance, whose whole pitch is fixed and predictable lending, the variable it never priced was who owns the vote, and the holders diluted out of their own vaults now wait to hear whether anything is left for them. Protocols that keep their spending limits in a document rather than in code keep meeting the same problem, and the next thing to watch is whether Term Finance rebuilds with a timelock before it reopens.

Disclaimer The information provided on Coinliva is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency investments are highly volatile and involve risk. While we strive to provide accurate and up-to-date information, some details may change over time. Always conduct your own research before making any financial decisions.
Jan Whitfield
Author

Jan Whitfield

Jan Whitfield is the founder and Editor-in-Chief of Coinliva. His coverage focuses on the macro crypto landscape, including regulatory developments, institutional adoption, and structural shifts shaping the digital asset industry. He tracks how policy decisions, ETF flows, and corporate treasury moves connect to broader market dynamics, drawing on primary regulatory filings, official statements, and on-chain data.