On August 23, the Term Labs team officially confirmed an incident involving unauthorized access to the storage management system of the DeFi protocol Term Finance. However, the details and scale of the damage initially remained undisclosed, sparking a wave of speculation in the crypto community.
My analysis of data obtained from independent blockchain detectives allows me to reconstruct the full picture of what happened. The attacker managed to withdraw 2,843 ETH from the protocol, equivalent to approximately $6.9 million, as well as 1.68 million USDC, which were subsequently converted into DAI. The total amount of losses, by my estimates, amounted to about $8.5 million.
Particularly alarming is the fact that this amount represents approximately 68% of all funds locked in Term Finance's vaults. According to data from the DefiLlama aggregator, this deals a serious blow to the liquidity and trust in a protocol that was positioned as a reliable tool for managing digital assets.
At this point, Term Labs has not disclosed details of the attack vector, but similar incidents in the DeFi sector are most often associated with vulnerabilities in smart contracts or errors in access control logic. Hackers are increasingly exploiting administrative functions, making code audits and the implementation of multi-layered protection mechanisms critically important.
This hack is yet another reminder of the systemic risks inherent in decentralized financial platforms. Even with formal security checks in place, incidents of this scale undermine the resilience of the entire sector and require teams to take a more proactive approach to monitoring and responding to threats.
In my practice, such cases highlight the need for investors to diversify risks and avoid concentrating significant amounts of funds in a single protocol, especially in the early stages of its development.