Community Investigation

The $8.5M Term Finance Governance Exploit: What the Chain Proves — and What It Does Not

REPORT
REPORT

August 25, 2026

TL;DR

On August 23, 2026, Term Finance reported an exploit affecting its Strategy Vaults. Public reporting described a governance attack in which an attacker accumulated voting power, disabled a seven-day delay, and withdrew roughly 2,843 ETH and 1.68 million USDC.

Our SentinelTX-assisted review confirms the post-exploit asset flows with transaction-level anchors: 2,841.237 ETH moved into the consolidation wallet `0xD5183d8BfC65a50863C62aF2538198A8288FFc13`; 1,679,642.45 USDC was swapped through KyberSwap into 1,679,642.45 DAI; and 300 ETH was later split into three 100 ETH deposits to the sanctioned Tornado Cash router. At the investigation cutoff, the consolidation wallet still held approximately 2,543.15 ETH and 1,679,642.45 DAI.

The important caveat: this investigation did not independently identify the proposal, vote, timelock, or execute transactions. Those governance mechanics remain based on public reporting and require separate contract-event reconstruction. The asset movements described below are on-chain confirmed; the governance narrative is not presented as independently proven.

Incident Background

Term Finance is an Ethereum-based fixed-rate lending protocol. According to Term Labs' official incident acknowledgement (https://x.com/term_labs/status/2091428394130886740) and contemporary reporting by CoinDesk (https://www.coindesk.com/markets/2026/08/24/ethereum-lending-app-term-finance-loses-usd8-5-million-after-attacker-buys-voting-power), its Strategy Vaults were exploited on August 23.

Public accounts describe an attacker buying a small amount of tmvETH governance exposure, submitting a malicious proposal, and using the proposal's first instruction to remove a seven-day timelock before executing the remaining instructions. They also report that the LP veto mechanism did not stop the proposal. Those claims explain the suspected attack path, but the SentinelTX session did not recover the full proposal-to-execution event chain. We therefore separate the public narrative from what the transfers themselves establish.

What the On-Chain Evidence Confirms

1. The ETH branch

The principal confirmed ETH transfer occurred at 06:31:47 UTC on August 23, in block 25,816,079. Transaction `0xb3971dcb761ff0044c7d3752e5856af253768a42c32659b857c36250e49fc479` (https://etherscan.io/tx/0xb3971dcb761ff0044c7d3752e5856af253768a42c32659b857c36250e49fc479) moved 2,841.237 ETH from the operational wallet `0xa908b3472d76e7744bab0a5911768a4a6300612b` into the consolidation wallet.

SentinelTX also observed a preceding WETH path involving `0x64e477800051efb06ae4086f4b258b270668b4df`, but the contract was not labeled and was not independently verified as a Term vault. It should be treated as an intermediate contract, not conclusively labeled as the victim contract.

2. The stablecoin branch

At 06:48:35 UTC, block 25,816,163, transaction `0x92b2aaf00e28ec2f25128e375fd5e3344e4f69e690b5a7262abab4935fef65ce` (https://etherscan.io/tx/0x92b2aaf00e28ec2f25128e375fd5e3344e4f69e690b5a7262abab4935fef65ce) routed 1,679,642.45 USDC through KyberSwap's Meta Aggregation Router v2 at `0x6131b5fae19ea4f9d964eac0408e4408b66337b5`, producing 1,679,642.45 DAI.

The DAI then moved from `0x686457a7468b9b31c5dba43b1b16077b48520691` to the consolidation wallet in transaction `0xf91371b001a15fb31bbad7090b0af6190b32b3cf1efe77efff4c8fd086436898` (https://etherscan.io/tx/0xf91371b001a15fb31bbad7090b0af6190b32b3cf1efe77efff4c8fd086436898). A separate confirmed transaction, `0x4465052fc702c08cd39cfdcc613bf41a93e3cb54a5c9b7975ce6feeeb338078e` (https://etherscan.io/tx/0x4465052fc702c08cd39cfdcc613bf41a93e3cb54a5c9b7975ce6feeeb338078e), moved 0.965 ETH from the same operational wallet to the consolidation address at 06:50:47 UTC.

The First Cash-Out: 300 ETH Into Tornado Cash

On August 24, the consolidation wallet sent 300.05 ETH to the relay address `0xc14007663a5bb9f13d4d2aee8c6fe9075ef1d83e`. The relay then deposited 300 ETH into the Tornado Cash router `0xd90e2f925da726b50c4ed8d0fb90ad053324f31b` in three equal 100 ETH tranches.

This is the clearest laundering endpoint recovered in the investigation. Once funds enter Tornado Cash, deterministic transaction-by-transaction tracing stops. Statistical timing and amount analysis may generate leads, but it cannot by itself establish ownership of any later withdrawal.

No bridge or centralized-exchange endpoint was confirmed during this session.

Current Status of Funds

At the investigation cutoff — Ethereum block 25,832,793 at 2026-08-25 14:24:47 UTC — SentinelTX reported approximately:

- 2,543.15 ETH remaining at `0xD5183d8BfC65a50863C62aF2538198A8288FFc13`

- 1,679,642.45 DAI remaining at the same address

- 300 ETH already deposited into Tornado Cash

- 0.035 ETH remaining at the relay address after the mixer deposits

The large residual balance makes the consolidation wallet the highest-priority monitoring target. Any transfer to a centralized exchange, bridge, OTC-linked cluster, or fresh intermediary could create a new intervention opportunity.

Why the Timelock and LP Veto Reportedly Failed

Public reports say the malicious proposal's first action disabled the seven-day timelock, allowing later actions to execute without the intended review window. They also say the attacker accumulated enough governance power to pass the proposal while the LP veto was not exercised in time.

This would represent a governance-design failure rather than a classic smart-contract reentrancy or oracle exploit: a privileged process performed exactly what an approved proposal instructed it to do. But this investigation did not recover the underlying `propose`, `vote`, or `execute` transactions. Until those logs are reconstructed and linked to the affected vault contracts, the exact failure mode should be described as reported, not independently proven.

Wallet and Entity Map

- `0xD5183d8BfC65a50863C62aF2538198A8288FFc13` — primary consolidation wallet; highest-priority monitor.

- `0xa908b3472d76e7744bab0a5911768a4a6300612b` — operational wallet associated with tmvETH acquisition and the main ETH transfer.

- `0x686457a7468b9b31c5dba43b1b16077b48520691` — operational wallet associated with the USDC-to-DAI swap and onward transfers.

- `0xc14007663a5bb9f13d4d2aee8c6fe9075ef1d83e` — relay used before Tornado Cash deposits.

- `0xd90e2f925da726b50c4ed8d0fb90ad053324f31b` — sanctioned Tornado Cash router; confirmed mixer endpoint.

- `0x6131b5fae19ea4f9d964eac0408e4408b66337b5` — KyberSwap Meta Aggregation Router v2.

- `0x64e477800051efb06ae4086f4b258b270668b4df` — unlabeled WETH intermediate contract; victim-vault attribution not confirmed.

Investigator Actions

1. Place real-time alerts on the consolidation wallet, both operational wallets, and the relay address.

2. Pre-notify major exchanges, bridges, and stablecoin issuers with the confirmed transaction hashes and addresses.

3. Reconstruct Term Finance governance events from August 17–23 and identify the proposal ID, proposer, vote calls, timelock state change, and execution transaction.

4. Obtain the affected vault addresses and withdrawal-event logs directly from Term Labs, then match them against the confirmed recipient wallets.

5. Monitor Tornado Cash withdrawals using timing and denomination analysis, while treating any matches as leads rather than attribution.

Unknowns and Attribution Limits

The session did not independently verify an inbound Tornado Cash funding link to the two operational wallets. It did not identify the affected vault contract, the governance proposal transaction, the vote transaction, or the timelock execution transaction. It also did not establish a real-world identity, threat group, CEX endpoint, bridge endpoint, or cross-chain continuation.

These gaps matter. The report establishes a post-exploit asset trail and a confirmed mixer deposit; it does not establish who controlled the wallets or fully prove the governance sequence.

Conclusion

The Term Finance incident illustrates why governance controls must be evaluated as part of the protocol's attack surface. A delay is only protective if a proposal cannot remove it before sensitive actions execute, and a veto is only protective if monitoring and participation are reliable during the entire review window.

The chain currently preserves a significant intervention window: most of the confirmed proceeds remained in one publicly identified wallet at the cutoff. That makes fast information sharing, exchange coordination, and precise event reconstruction more valuable than speculative attribution.

*Analytical disclaimer: This report distinguishes transaction-level observations from public reporting and analytical inference. Wallet association does not by itself identify a person or organization. Balances and endpoints can change after the stated cutoff.*

post_like_sub0
post_total_comment_sub0

3 reads

0/500 bytes