Term Labs 遭遇 850 万美元治理漏洞攻击

Term Labs 遭遇 850 万美元治理漏洞攻击

主要洞察:

  • 在发生针对 Term Labs.
  • Malicious actors drained ETH as its native asset.">Ethereum and USDC from impacted Term vaults.
  • Term Labs 已证实此次安全漏洞并展开了积极调查。

Term Labs issued a statement on X confirming that a governance exploit impacted its vaults on August 23, 2026. The security breach heightened awareness of crypto scams after analytics firms monitored roughly $8.5 million leaving the protocol. The attack compromised ETH as its native asset.">Ethereum holdings and USDC stored within the Term-linked vault framework.

加密骗局警报 | 来源:Coin Bureau (X)
加密骗局警报 | 来源:Coin Bureau (X)

The event drew attention because governance vulnerabilities can compromise pooled funds without breaching the underlying ETH as its native asset.">Ethereum network.

Term Finance had previously cautioned users that vault smart contracts might harbor weaknesses capable of triggering financial losses. Legal disclaimers from the project noted that Term Vaults depend on external smart contracts instead of banks and brokers.">decentralized finance protocols and Yearn v3 contracts.

加密骗局焦点转向 Term Labs 治理漏洞利用

According to PeckShield, the perpetrator extracted roughly 2,843 ETH, estimated at $6.87 million, during its initial assessment. The blockchain monitoring firm also detected 1.68 million USDC moving out of the compromised vaults before being swapped into approximately 1.6 million DAI.

PeckShield 追溯发现,黑客的初始资金来自通过 Tornado Cash 获取的两笔 ETH。这条交易路径并未暴露作案者的身份,也未表明存在更广泛的洗钱行为;它仅仅指出了攻击前所使用资金的声明来源。

Term Labs 通过其官方 X 频道确认了此次治理漏洞事件。代表们表示,该事件针对的是 Term 金库,目前仍在审查中,不过在本文编写时尚未发布技术复盘报告。

CertiK 对此次治理攻击进行了独立评估,估计总损失约为 850 万美元。其追踪锁定了黑客的钱包地址为 0xD5183d8BfC65a50863C62aF2538198A8288FFc13,该钱包随后持有 2,843 枚 ETH 以及约 160 万枚 DAI。

加密骗局讨论聚焦于金库治理风险

Official documentation outlines Term Finance as a non-custodial, fixed-rate lending protocol built on Ethereum. Its Term Repos utilize smart contracts to secure collateral for both lenders and borrowers, with isolated lockers designed to minimize risk compared to a single collective collateral pool.

来源:X

协议指南进一步将金库风险与主借贷框架隔离开来,解释称 repo 抵押品保留在指定的智能锁定器内,而金库操作则与外部协议进行交互。

尽管这种设置减轻了共享池漏洞的影响,但它未能消除合约或治理威胁。该协议的服务条款明确警告参与者,存入的资金可能会部分或全部丢失。

此次漏洞影响的是 Term Vaults(Term 金库),而非协议的基本 repo 机制。法律披露信息明确指出,这些金库运行在 Yearn v3 基础设施之上,并警告称漏洞、外部协议崩溃、策略故障或安全隐患可能会导致财务损失。

这一区别对于监控以下内容的观察者至关重要: 加密骗局 and security breaches. A governance exploit targets administrative privileges or authorization workflows rather than the Ethereum consensus mechanism. Term Labs has not yet revealed the specific governance vector, permission sequence, or contract path utilized.

A disclosure statement from Kraken characterizes Term Finance as an Ethereum-based, non-custodial lending platform developed by Terminal 0 Ltd., which operates as Term Labs. The document also noted that TERM governance management was slated for transition following the rollout of a Governor contract.

由于该文件发布于攻击之前,因此并未提及 8 月 23 日的漏洞利用事件,但它提供了有关该平台预期治理框架的背景信息。Term Labs 尚未说明即将推出的 Governor 架构是否促成了此次事件。

加密黑客事件留下以太坊和 USDC 追踪线索,目前正接受审查

尽管技术细节寥寥无几,但资金流向为调查人员提供了具体的验证点。PeckShield 观察到了 ETH 和 USDC 的转账,而 CertiK 则在攻击者钱包中识别出了 ETH 和 DAI 余额,这证实了 PeckShield 关于提取后代币兑换的调查结果。

现有数据显示,以太坊或 USDC 系统并未遭到破坏。相反,Term Labs 将该事件归类为其金库受影响的治理事件,将责任归咎于协议管理,而不是底层基础网络或资产。

Term Finance 此前已概述了其各项服务中潜在的网络安全风险,并建议用户智能合约故障、治理纠纷、安全漏洞以及第三方协议问题可能会对其资金造成影响。这些警告并未具体说明本次攻击中所利用的具体漏洞。

Term Labs 承诺发布的下一个进展报告将是下一个可验证的里程碑。存单持有人和交易员正在等待有关受影响金库标识符、目标合约地址、恢复计划以及潜在治理更新的详细信息。预计详细的复盘报告将确定是否能够追回任何被盗资金。

常见问题

  • 是什么导致了 Term Labs 的漏洞利用? Term Labs confirmed a governance exploit affected its vaults on August 23, 2026.
  • 此次攻击窃取了多少资金? PeckShield 和 CertiK 等安全公司追踪到的总流出资金约为 850 万美元。
  • 哪些资产从金库中被抽干? 攻击者盗取了以太坊资产和 USDC,随后被兑换为 DAI。
  • 底层的以太坊和 USDC 网络是否受到攻击? 没有,调查人员未发现底层以太坊或 USDC 基础设施遭到攻击的证据。
本文不构成投资建议 此处发布的分析仅供参考。数字资产具有波动性,您可能会损失仓位的全部价值。在采取行动前,请自行做好调研。

Glory Kaburu

发表回复

电子邮件地址不会被公开。 必填项已用 *