Community Investigation

The $8.5M Term Finance Governance Exploit: What the Chain Proves — and What It Does Not

REPORT
REPORT

August 25, 2026

​TL;DR

On August 23, 2026, Term Finance reported an exploit affecting its Strategy Vaults. Public reporting described a governance attack in which an attacker accumulated voting power, disabled a seven-day delay, and withdrew roughly 2,843 ETH and 1.68 million USDC.

Our SentinelTX-assisted review confirms the post-exploit asset flows with transaction-level anchors: 2,841.237 ETH moved into the consolidation wallet 0xD5183d8BfC65a50863C62aF2538198A8288FFc13; 1,679,642.45 USDC was swapped through KyberSwap into 1,679,642.45 DAI; and 300 ETH was later split into three 100 ETH deposits to the sanctioned Tornado Cash router. At the investigation cutoff, the consolidation wallet still held approximately 2,543.15 ETH and 1,679,642.45 DAI.

The important caveat: this investigation did not independently identify the proposal, vote, timelock, or execute transactions. Those governance mechanics remain based on public reporting and require separate contract-event reconstruction. The asset movements described below are on-chain confirmed; the governance narrative is not presented as independently proven.

INCIDENT BACKGROUND

Term Finance is an Ethereum-based fixed-rate lending protocol. According to Term Labs' official incident acknowledgement (https://x.com/term_labs/status/2091428394130886740) and contemporary reporting by CoinDesk (https://www.coindesk.com/markets/2026/08/24/ethereum-lending-app-term-finance-loses-usd8-5-million-after-attacker-buys-voting-power), its Strategy Vaults were exploited on August 23.

Public accounts describe an attacker buying a small amount of tmvETH governance exposure, submitting a malicious proposal, and using the proposal's first instruction to remove a seven-day timelock before executing the remaining instructions. They also report that the LP veto mechanism did not stop the proposal. Those claims explain the suspected attack path, but the SentinelTX session did not recover the full proposal-to-execution event chain.

Visual 1 — Reported governance sequence and confirmed transfer timeline

WHAT THE ON-CHAIN EVIDENCE CONFIRMS

1. The ETH branch

The principal confirmed ETH transfer occurred at 06:31:47 UTC on August 23, in block 25,816,079. Transaction 0xb3971dcb761ff0044c7d3752e5856af253768a42c32659b857c36250e49fc479 (https://etherscan.io/tx/0xb3971dcb761ff0044c7d3752e5856af253768a42c32659b857c36250e49fc479) moved 2,841.237 ETH from the operational wallet 0xa908b3472d76e7744bab0a5911768a4a6300612b into the consolidation wallet.

SentinelTX also observed a preceding WETH path involving 0x64e477800051efb06ae4086f4b258b270668b4df, but the contract was not labeled and was not independently verified as a Term vault. It should be treated as an intermediate contract, not conclusively labeled as the victim contract.

2. The stablecoin branch

At 06:48:35 UTC, block 25,816,163, transaction 0x92b2aaf00e28ec2f25128e375fd5e3344e4f69e690b5a7262abab4935fef65ce (https://etherscan.io/tx/0x92b2aaf00e28ec2f25128e375fd5e3344e4f69e690b5a7262abab4935fef65ce) routed 1,679,642.45 USDC through KyberSwap's Meta Aggregation Router v2 at 0x6131b5fae19ea4f9d964eac0408e4408b66337b5, producing 1,679,642.45 DAI.

The DAI then moved from 0x686457a7468b9b31c5dba43b1b16077b48520691 to the consolidation wallet in transaction 0xf91371b001a15fb31bbad7090b0af6190b32b3cf1efe77efff4c8fd086436898 (https://etherscan.io/tx/0xf91371b001a15fb31bbad7090b0af6190b32b3cf1efe77efff4c8fd086436898). A separate confirmed transaction, 0x4465052fc702c08cd39cfdcc613bf41a93e3cb54a5c9b7975ce6feeeb338078e (https://etherscan.io/tx/0x4465052fc702c08cd39cfdcc613bf41a93e3cb54a5c9b7975ce6feeeb338078e), moved 0.965 ETH from the same operational wallet to the consolidation address at 06:50:47 UTC.

THE FIRST CASH-OUT: 300 ETH INTO TORNADO CASH

On August 24, the consolidation wallet sent 300.05 ETH to the relay address 0xc14007663a5bb9f13d4d2aee8c6fe9075ef1d83e. The relay then deposited 300 ETH into the Tornado Cash router 0xd90e2f925da726b50c4ed8d0fb90ad053324f31b in three equal 100 ETH tranches.

This is the clearest laundering endpoint recovered in the investigation. Once funds enter Tornado Cash, deterministic transaction-by-transaction tracing stops. Statistical timing and amount analysis may generate leads, but it cannot by itself establish ownership of any later withdrawal.

No bridge or centralized-exchange endpoint was confirmed during this session.

Visual 2 — Confirmed post-exploit fund flow

CURRENT STATUS OF FUNDS

At the investigation cutoff — Ethereum block 25,832,793 at 2026-08-25 14:24:47 UTC — SentinelTX reported the following balances and completed mixer deposit.

Table 1 — Confirmed balances and fund status at the investigation cutoff

The large residual balance makes the consolidation wallet the highest-priority monitoring target. Any transfer to a centralized exchange, bridge, OTC-linked cluster, or fresh intermediary could create a new intervention opportunity.

WHY THE TIMELOCK AND LP VETO REPORTEDLY FAILED

Public reports say the malicious proposal's first action disabled the seven-day timelock, allowing later actions to execute without the intended review window. They also say the attacker accumulated enough governance power to pass the proposal while the LP veto was not exercised in time.

This would represent a governance-design failure rather than a classic smart-contract reentrancy or oracle exploit: a privileged process performed exactly what an approved proposal instructed it to do. But this investigation did not recover the underlying propose, vote, or execute transactions. Until those logs are reconstructed and linked to the affected vault contracts, the exact failure mode should be described as reported, not independently proven.

WALLET AND ENTITY MAP

• 0xD5183d8BfC65a50863C62aF2538198A8288FFc13 — primary consolidation wallet; highest-priority monitor.

• 0xa908b3472d76e7744bab0a5911768a4a6300612b — operational wallet associated with tmvETH acquisition and the main ETH transfer.

• 0x686457a7468b9b31c5dba43b1b16077b48520691 — operational wallet associated with the USDC-to-DAI swap and onward transfers.

• 0xc14007663a5bb9f13d4d2aee8c6fe9075ef1d83e — relay used before Tornado Cash deposits.

• 0xd90e2f925da726b50c4ed8d0fb90ad053324f31b — sanctioned Tornado Cash router; confirmed mixer endpoint.

• 0x6131b5fae19ea4f9d964eac0408e4408b66337b5 — KyberSwap Meta Aggregation Router v2.

• 0x64e477800051efb06ae4086f4b258b270668b4df — unlabeled WETH intermediate contract; victim-vault attribution not confirmed.

INVESTIGATOR ACTIONS

1. Place real-time alerts on the consolidation wallet, both operational wallets, and the relay address.

2. Pre-notify major exchanges, bridges, and stablecoin issuers with the confirmed transaction hashes and addresses.

3. Reconstruct Term Finance governance events from August 17–23 and identify the proposal ID, proposer, vote calls, timelock state change, and execution transaction.

4. Obtain the affected vault addresses and withdrawal-event logs directly from Term Labs, then match them against the confirmed recipient wallets.

5. Monitor Tornado Cash withdrawals using timing and denomination analysis, while treating any matches as leads rather than attribution.

Visual 3 — Priority monitoring and response points

UNKNOWNS AND ATTRIBUTION LIMITS

The session did not independently verify an inbound Tornado Cash funding link to the two operational wallets. It did not identify the affected vault contract, the governance proposal transaction, the vote transaction, or the timelock execution transaction. It also did not establish a real-world identity, threat group, CEX endpoint, bridge endpoint, or cross-chain continuation.

These gaps matter. The report establishes a post-exploit asset trail and a confirmed mixer deposit; it does not establish who controlled the wallets or fully prove the governance sequence.

CONCLUSION

The Term Finance incident illustrates why governance controls must be evaluated as part of the protocol's attack surface. A delay is only protective if a proposal cannot remove it before sensitive actions execute, and a veto is only protective if monitoring and participation are reliable during the entire review window.

The chain currently preserves a significant intervention window: most of the confirmed proceeds remained in one publicly identified wallet at the cutoff. That makes fast information sharing, exchange coordination, and precise event reconstruction more valuable than speculative attribution.

Analytical disclaimer: This report distinguishes transaction-level observations from public reporting and analytical inference. Wallet association does not by itself identify a person or organization. Balances and endpoints can change after the stated cutoff.

post_like_sub0
post_total_comment_sub0

38 조회

0/500 bytes