When Governance Gets Exploited: Where Term Finance’s $8.5M Went The… — BitOK — TG.ME

🧠 When Governance Gets Exploited: Where Term Finance’s $8.5M Went

The attacker didn’t need to find a smart contract vulnerability to drain millions from Term Finance. A small stake in the vault was enough to propose the changes they needed and wait for no one to say “no.”

The weak point wasn’t the code. It was the protocol’s governance.

⚙️ Six days to stop the withdrawal

The attacker swapped 0.5 ETH for a stake in the ETH Meta Vault, received governance tokens, and submitted a proposal containing 17 actions.

Those actions included removing the protective delay, pulling WETH back from four strategies, and adding an attacker-controlled exit strategy.

The proposal remained open for around six days. No one vetoed it. Once the window closed, the protocol executed the actions and transferred 2,841.74 WETH to the attacker.

A similar setup targeted five USDC vaults. Separate proposals changed key roles and risk controls, allowing another 1.68M USDC to be withdrawn.

🔍 Where did the funds go? BitOK analysts traced the full flow:

➤ WETH was converted to ETH;
➤ USDC was swapped for DAI via KyberSwap and Maker PSM;
➤ the ETH and DAI were consolidated into a single wallet.

The attacker didn’t need to break the code. They used Term Finance’s own rules: propose the right changes, wait for no one to stop them, then let the protocol execute the rest.

❤️ Want to break down similar cases and trace on-chain fund flows yourself? Use BitOK Graph for your own investigations.

Website | Telegram | BitOK bot
🔥7❤5👏3✍1
August 26, 2026 46