Crypto news

24.08.2026
05:40

Attack on Term Finance: hackers withdrew $8.5 million from DeFi vaults

hack

On August 23, the Term Labs team officially confirmed an unauthorized intrusion into the storage management system of the DeFi protocol Term Finance. However, the details of the incident were not disclosed—the company chose not to comment on the scale of the damage. My analysis of the situation, based on data from independent monitoring platforms, allows me to reconstruct the full picture of what happened.

According to data from the analytical service PeckShield, the attacker managed to withdraw 2,843 ETH from the protocol, equivalent to approximately $6.9 million, as well as 1.68 million USDC, which were subsequently converted into DAI. In turn, CertiK experts estimate the total losses at $8.5 million. This figure looks more realistic given the volatility of the exchange rate at the time of the attack and additional transactions.

It is critically important to emphasize: according to DefiLlama, the stolen amount constitutes about 68% of all funds locked in the protocol's vaults. This means the attack was not targeted in nature but was aimed at maximally draining liquidity. Such a level of losses calls into question the continued viability of Term Finance as a platform—restoring user trust after such a blow will require significant effort and, likely, compensatory measures.

At this point, it remains unclear whether a vulnerability in smart contracts was exploited or whether the attack was carried out through the compromise of administrative keys. In any case, the incident once again highlights the systemic risks of the DeFi sector, where even audited protocols are not immune to exploits. I recommend that holders of funds in such vaults reconsider their risk management strategies and pay attention to protocols with more mature security systems and insurance funds.