The decentralized lending protocol Term Finance has faced a serious security incident. On August 23, the Term Labs team officially confirmed an attack on the vault management system, but initially refrained from disclosing the exact scale of the damage. My analysis shows that this event has become yet another warning sign for the DeFi sector, where vulnerabilities in smart contracts continue to lead to multi-million-dollar losses.
According to my assessment, based on blockchain analytics data, the attacker managed to withdraw significant assets from the protocol. In particular, the hacker stole 2,843 ETH, equivalent to approximately $6.9 million, as well as 1.68 million USDC. Notably, the stolen stablecoins were quickly converted into DAI, indicating an attempt to obscure the trail and hinder fund tracking.
Independent security experts, including the CertiK team, estimate the total damage at $8.5 million. This figure is especially telling: it amounts to about 68% of all funds locked in the protocol's vaults, according to data from the DefiLlama aggregator. Such a high percentage of losses suggests that the attack targeted the most liquid pools, making fund recovery particularly challenging.
As for the attack vector, judging by the nature of the transactions, the vulnerability was likely related to the vault management logic, which allowed the attacker to bypass verification and authorization mechanisms. To date, there have been no official statements regarding compensation for affected users, adding uncertainty to the situation.
This incident underscores the critical importance of regular audits and stress testing of smart contracts, especially for protocols dealing with collateral assets. In my practice, such attacks often occur due to insufficient validation of external calls or improper handling of edge cases. DeFi users should diversify risks and avoid storing significant amounts in a single protocol without a thorough analysis of its security.