← Radar

Incident case file

Sign in to watch

Term Finance Governance Takeover — $8.5M Stolen via Malicious Proposal, Fully Traced

Incident date Aug 22, 2026Last updated Sep 24, 2026

0 views

ContainedEthereumGovernance takeover exploitCluster: TERMFI-ETH-2026-08

Estimated loss

$8.5M

Affected users

1
Group joining is coming soon.

Investigation

90%

Facts and investigation

Ledger

Attacker

Exploiter 1: 0xa908b3472d76e7744baB0A5911768a4a6300612B; Exploiter 2: 0x686457a7468B9B31c5dbA43b1b16077B48520691 (Etherscan-labeled 'Term Finance Exploiter')

Funds moved to

Consolidated at 0xD5183d8BfC65a50863C62aF2538198A8288FFc13, then laundered via a dedicated hub wallet 0xC14007663A5bb9F13d4d2AEE8c6FE9075eF1d83e which deposited roughly 2,450+ ETH (75-80% of the total) into Tornado Cash within two weeks of the exploit.

Linked

Exploiter 1: 0xa908b3472d76e7744baB0A5911768a4a6300612B. Exploiter 2: 0x686457a7468B9B31c5dbA43b1b16077B48520691. Targeted governance contract (8 malicious proposals submitted): 0x4F4B614d2Aa533E6e3B11a6A32295Bd147Eba17f. Consolidation wallet: 0xD5183d8BfC65a50863C62aF2538198A8288FFc13. Laundering hub (Tornado Cash deposits): 0xC14007663A5bb9F13d4d2AEE8c6FE9075eF1d83e. An address-poisoning lookalike (0xD506b9A335d82Ee0B568C86c9b82DcF8538FFc13) was also identified targeting the consolidation addr

Chronology

1 beat
  1. On August 23, 2026, two coordinated attacker wallets — both funded via Tornado Cash — executed a governance takeover of Term Finance's ETH Meta Vault. Exploiter 2 (0x686457a7...) deployed helper contracts and submitted eight malicious governance proposals to contract 0x4F4B614d2A... between 06:25:35 and 06:47:47 UTC, disguised as routine parameter updates. Exploiter 1 (0xa908b347...) then transferred 2,841.74 WETH to the consolidation wallet 0xD5183d8B..., which also received 1,679,639 USDC from five separate vaults, bringing the total to roughly $8.5M. The consolidation wallet began systematically transferring the stolen funds — in tranches from 0.05 ETH up to 2,000 ETH — to a dedicated laundering hub, 0xC14007663A..., which converted a portion via SushiSwap and Across Protocol before depositing approximately 2,450+ ETH into Tornado Cash across roughly 22+ separate 100 ETH deposits within two weeks, representing 75-80% of the total stolen value. Both source wallets remain tagged as 'Term Finance Exploiter 1/2' on Etherscan with active alerts sourced to PeckShieldAlert. An address-poisoning wallet mimicking the consolidation address's first and last characters was also detected in the transaction history, a pattern also observed in the Tectonic, Moonwell, and Symbiosis incidents during the same period.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)