Incident case file
Sign in to watchTerm Finance Governance Takeover — $8.5M Stolen via Malicious Proposal, Fully Traced
0 views
Estimated loss
Affected users
Investigation
Facts and investigation
Ledger
Attacker
Funds moved to
Linked
Chronology
1 beatOn August 23, 2026, two coordinated attacker wallets — both funded via Tornado Cash — executed a governance takeover of Term Finance's ETH Meta Vault. Exploiter 2 (0x686457a7...) deployed helper contracts and submitted eight malicious governance proposals to contract 0x4F4B614d2A... between 06:25:35 and 06:47:47 UTC, disguised as routine parameter updates. Exploiter 1 (0xa908b347...) then transferred 2,841.74 WETH to the consolidation wallet 0xD5183d8B..., which also received 1,679,639 USDC from five separate vaults, bringing the total to roughly $8.5M. The consolidation wallet began systematically transferring the stolen funds — in tranches from 0.05 ETH up to 2,000 ETH — to a dedicated laundering hub, 0xC14007663A..., which converted a portion via SushiSwap and Across Protocol before depositing approximately 2,450+ ETH into Tornado Cash across roughly 22+ separate 100 ETH deposits within two weeks, representing 75-80% of the total stolen value. Both source wallets remain tagged as 'Term Finance Exploiter 1/2' on Etherscan with active alerts sourced to PeckShieldAlert. An address-poisoning wallet mimicking the consolidation address's first and last characters was also detected in the transaction history, a pattern also observed in the Tectonic, Moonwell, and Symbiosis incidents during the same period.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)