Once again, the world of crypto security has been shaken by another incident. On August 23rd, Term Finance, a DeFi lending and borrowing protocol on Ethereum [ETH], fell victim to an attack.
Instead of exploiting a smart contract bug directly, the attacker exploited a vulnerability in Term Finance’s DAO governance system.


How did the attacker siphon off millions in ETH?
With only a small amount of Term’s governance token available on the market, the hacker seized the opportunity to purchase a significant portion of the tokens at a low price, giving them majority voting power.
Once the attacker had enough votes for approval, they proceeded to submit and approve malicious governance proposals. This granted them control over Term Finance’s vaults, where users’ assets are stored.
Before executing the attack, the attacker allegedly funded the operation with 2 ETH obtained through Tornado Cash. This led to a loss of around $8.5 million from Ethereum, with 2,843 ETH (approximately $6.87 million) and 1.68 million USDC being compromised. The attacker exchanged these tokens for roughly 1.68 million DAI.
2026: A challenging year for Ethereum
A recent report from Blockaid revealed that in the first half of 2026, losses from crypto theft and fraud surpassed $1 billion, with Ethereum accounting for the largest portion at around $332 million.


Ethereum’s losses were primarily driven by exploits in smart contracts and applications, including vulnerabilities in bridges, privileged accounts, and protocol logic.
ETH under siege
This aligns with AMBCrypto’s recent coverage of the Verus-Ethereum Bridge hack, which suffered a second attack in July resulting in a loss of around $7.54 million.
In a similar attack in May, nearly $11.58 million was compromised. The recurrence of these attacks raises concerns about the adequacy of the earlier fixes to vulnerabilities.
These incidents occurred while Ethereum’s price, which was hovering around $4k in January, had dropped to $2412 at the time of reporting.
Over the year, ETH has declined by 48.9% according to CoinGecko’s annual data, attributed to attacks, regulatory uncertainties, geopolitical tensions, Fed rate adjustments, and more.
Key Takeaways
- The attacker acquired a significant portion of governance tokens cheaply to gain majority voting power.
- In the first half of 2026, Ethereum accounted for the largest share of funds lost in crypto fraud, amounting to $332 million.
