The $8.5M DAO heist that cost $951 to pull off: how Term Labs got governance hijacked

An attacker bought a controlling stake in a DAO governance token for less than $1,000, passed malicious proposals, and drained $8.5 million from strategy vaults. The exploit exposes a vulnerability that most DeFi protocols have not patched. Summary An attacker spent approximately $951 to acquire a controlling share of Term Labs’ governance tokens, then passed proposals that drained roughly $8.5 million from the protocol’s strategy vaults on August 23, 2026. The stolen assets included 2,843 ETH (approximately $6.87 million) and 1.68 million USDC, later swapped for roughly 1.6 million DAI, with the attacker’s initial funding traced to just 2 ETH sourced through Tornado Cash. The exploit did not involve a smart contract bug or a coding flaw. Every transaction was a permitted governance action executed by the address the protocol recognized as its legitimate governor. Term Labs permanently shut down all Meta Vault deposits and revoked DAO governance roles in response, while keeping withdrawals open for existing depositors. The attack is the fifth governance exploit of 2026 according to DefiLlama, bringing the combined total for the year to $25.1 million, led by a $20 million BonkDAO treasury drain in July. The math is the story. An attacker spent $951 on governance tokens for a protocol that held $12.45 million in depositor funds. That $951 bought enough voting power to control four USDC strategy vaults and approximately 91% of the Ethereum Meta Vault. The attacker submitted proposals to move the funds, voted on those proposals with the tokens just purchased, and watched the vaults transfer $8.5 million to a wallet seeded with 2 ETH from Tornado Cash. Every step was legal from the protocol’s perspective. The governance contracts worked exactly as designed. The proposals were submitted correctly, the votes were counted accurately, and the vault transfers executed precisely as the governance system instructed. The problem was not that the code broke. The problem was that the code did what it was told by someone who spent less than $1,000 to become its highest authority. Term Labs confirmed the exploit on X on August 23, 2026. Security firms PeckShield and CertiK independently verified the incident and traced the stolen funds to attacker address 0xD5183d8BfC65a50863C62aF2538198A8288FFc13. The protocol’s on chain monitoring bot, Decurity’s Defimon, flagged the unusual transactions first. JUST IN: Ripple expands its presence in Washington, D.C. with a larger office. Move reflects long-term commitment to constructive engagement, clear rules of the road, and responsible financial innovation https://t.co/1K0bS8tXrfpic.twitter.com/0Ba2eb0Cvp — crypto.news (@cryptodotnews) June 3, 2026 This was not a novel attack. It was the fifth governance exploit of 2026 and the second in seven weeks. The pattern is repeating because the vulnerability is structural, and most DeFi protocols have not addressed it.
عنوان اصلی (انگلیسی): The $8.5M DAO heist that cost $951 to pull off: how Term Labs got governance hijacked
مشاهدهی خبر کامل در منبع ↗ بازگشت به یرن فایننساین خلاصه بهصورت خودکار از کوینمارکتکپ ترجمه شده و ممکن است خطای ماشینی داشته باشد؛ صرفاً جهت اطلاعرسانی است و توصیهی معاملاتی نیست.