AiCoin中文
AiCoin中文|8月 28, 2026 11:03
A few days ago, Term Finance lost about $8.5M, but the most ridiculous part this time wasn’t how complex the attack was—it was the malicious Governance Proposal that was publicly visible on-chain for 6 days. When the voting window ended, there was no veto. 12 seconds later, the proposal was executed, and 2,841.74 WETH was transferred out. Another transaction took away approximately 1.68M USDC. No leaked keys, no oracle manipulation, no reentrancy, and no flash loans. The attacker simply exploited Term’s own Governance Module: submitted a parameter modification, waited through the delay period, no one opposed it, and finally executed it according to the rules. This incident actually highlights a pretty overlooked issue in DeFi. Over the years, people have been adding Timelocks, Governance, DAOs, and Veto mechanisms—all essentially aimed at making rules more transparent and reducing reliance on any single individual. But just because the rules are public doesn’t mean someone is actually watching. Code can give you 6 days to act, but it won’t proactively remind you: “Hey, this proposal looks suspicious, go veto it.” So the next phase of DeFi security might not just be about whether Smart Contracts have vulnerabilities—it’s also about asking: Who’s actually monitoring Governance? Decentralization can reduce reliance on one person, but if it ends up with everyone assuming “someone else will handle it,” then that’s just another kind of risk.
+2
Mentioned
Share To

Timeline

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads