How $900 Bought Control of an $8.5M DeFi Vault

Term Finance lost about $8.5M after an attacker reportedly spent just $900 to gain governance control. Here is what passive DeFi governance exposes and how protocols can respond.

How $900 Bought Control of an $8.5M DeFi Vault
How $900 Bought Control of an $8.5M DeFi Vault

The Term Finance exploit shows how the structure of DeFi, which is intended to enable financial systems to function without central control, can result in a different form of risk. According to reports, an attacker paid roughly $900 to get sufficient governance authority to seize control of vaults containing approximately $8.5 million.

Through governance, the attacker discovered a far less expensive path. A small quantity of staked voting power became sufficient to control the decision-making process with virtually no active participation from other stakeholders.

How the $900 Governance Takeover Happened

The incident is especially concerning because of the numbers behind the Term Finance attack. According to some onchain assessments, the cost of the governance takeover was about $951; however, the attacker apparently only paid about $900. The attacker gained control over governance related to vaults containing roughly $8.53 million with that very cheap purchase.

Voting power was based on staked vault shares; however, nearly none of the available shares were staked, making the attack feasible. Just 0.5352 of the 2,838.95 shares, or roughly 0.019% of the total, were staked, according to BlockWatchdog.

That completely transformed the attack's economics. The attacker didn't need to take over the whole supply. All they had to do was obtain enough of the little portion that was genuinely involved in governance.

Voting power became remarkably concentrated as a result. According to reports, the attacker effectively controlled the governance process because they held approximately 90.66% of the active voting power.

The attacker then took control of the impacted vaults by passing malicious proposals from that position. The next transactions took about 2,843 ETH and 1.68 million USDC out of the vaults, according to onchain security research. After that, the USDC was changed to DAI.

The crucial point is that the attacker didn't need to take over the entire economy. All they needed to do was overturn the governing body that was in charge of it.

This distinction explains the attack's low cost of purchasing. Only a small portion of the underlying economic value was represented by the active governance layer, whereas the value safeguarded by the vaults was measured in millions.

Governance becomes a possible attack surface as a result. An attacker has a strong financial incentive to target governance first when the cost of obtaining decision-making power is significantly lower than the assets under its control.

Why Low Participation Made the Exploit Possible

The main flaw wasn't only that too few people cast votes. The reason was that, in comparison to the assets underlying it, the quantity of active voting power had shrunk to the point where controlling it was economically insignificant.

This is evident from the numbers around the incident. The attacker was able to obtain around 90.66% of the active voting power even though only 0.019% of the available vault shares were staked for governance.

As a result, the governing structure may theoretically remain decentralised while in practice becoming quite consolidated. Even if thousands of users may be exposed to the protocol, their ownership does not offer any real security if a hostile proposal emerges if nearly all of them are inactive in governance.

There was a defence system in place at Term Finance intended to allow time for intervention. Liquidity providers had the power to veto transactions that were in line, and its governance procedure included a 7 day delay for vault proposals.

The issue was that the protection was contingent upon someone identifying the attack and exercising the veto.

An attacker cannot be deterred by a delay alone. It gives the participants in the protocol a chance to react. That chance may vanish without anybody taking action if governance participants are mainly inactive and no one is keeping a careful eye on the queue.

Passive governance becomes a security concern at this point. A malicious plan does not require everyone's approval. While legitimate players stay silent, they merely require enough voting power to comply with the regulations.

As a result, the incident highlights a risky presumption in governance design. Even though only a tiny portion of the eligible voters may be available at the time of an attack, a protocol may treat all of them as part of its security model.

What This Exposes About DeFi Governance

The Term Finance incident demonstrates that protocol security and governance cannot be viewed as separate layers. The governance mechanism itself is a component of the protocol's security perimeter if it is authorised to manage vaults and transfer user assets.

This modifies how one should see a governance token. Gaining the ability to approve transactions worth millions of dollars can give one some administrative influence over the protocol.

This results in an attack technique that differs greatly from taking advantage of a coding fault. An attacker can seek for governance systems with a small active voting base and a significant value managed by that governance, as opposed to looking for a vulnerable function.

That disparity was precisely what the Term Finance case offered. The value exposed to the ensuing governance decisions was around $8.5 million, yet the reported cost of gaining power was less than $1,000.

The event also highlights a crucial distinction regarding Term Finance's technology. Although the Yearn V3 architecture was used in the construction of its Strategy Vaults, a proprietary governance wrapper surrounding those vaults was the source of the alleged attack.

This distinction is important because the assault was more than just proof of the vulnerability of the underlying Yearn V3 vault design. The additional governance layer that Term Finance introduced was linked to the particular attack path.

For protocols that expand upon pre-existing infrastructure, this is a crucial lesson. Permissions, wrappers, and governance systems designed on a secure underlying architecture are not always secure.

The attack also demonstrates the necessity of monitoring governance concentration in a manner similar to how protocols keep an eye on anomalous contract activity. When that governance can control millions of dollars, a wallet suddenly gaining an overwhelming percentage of active voting power shouldn't appear to be a typical governance event.

Therefore, whether governance exists onchain is not the main concern. In order to make that governance resistant to capture, sufficient independent economic weight must be involved.

How Protocols Can Prevent the Next Attack

Making governance capture more costly and challenging when participation is abnormally low should be the top priority. Because the remaining eligible voters are inactive, a protocol shouldn't permit a little number of active voting power to become adequate for controlling millions of dollars.

One solution to this issue is quorum requirements. Before having an impact on vault ownership or other high-value permissions, critical suggestions should necessitate significant input. The concept is simple, but the precise threshold must match the protocol. When practically no one is involved, governance shouldn't be able to make significant changes.

Additionally, protocols can strengthen the safeguards surrounding recently obtained voting power. The protocol becomes considerably simpler to capture if an attacker can buy governance influence and use it right away. This danger can be decreased by using snapshots, delays, and other measures that stop newly obtained voting power from being used immediately.

The need for an additional layer is demonstrated by the current seven-day delay in Term Finance. A timelock offers useful reaction time, but it requires oversight. Proposals for high-risk governance should immediately notify participants and the protocol team so they can take appropriate action.

Proposal design is subject to the same principle. Governance frameworks must make it evident what a proposal can truly accomplish. If a proposal has the potential to transfer assets or alter vault control, it should be made clear before the vote rather than hidden in technical transaction data.

Protocols ought to keep an eye on governance capture's financial costs. Knowing how many wallets are eligible to vote is insufficient. Teams should keep a close eye on the amount of active voting power, its concentration, and the amount of money an adversary would need to spend to secure a majority.

The most important lesson is that when governance manages real assets, passive governance is not benign. An attacker may be able to gain control if only a small portion of voting power is in use.

As a result, Term Finance raises a much more general security concern for DeFi. Protocols should consider whether their governance can be inexpensively captured in addition to whether their contracts are secure.

If you find any issues in this article or notice missing information, please feel free to reach out at team@etherworld.co for clarifications or updates.

To promote your Web3 articles, events, and projects, you may reach out anytime via EtherWorld PR for submissions and collaboration.

Related Articles

  1. Grayscale Research Head Bets on Blockchain for AI
  2. NYSE Builds Onchain Platform for Tokenized Securities
  3. Bitcoin ETFs See $145M Outflows Led by BlackRock
  4. MetaMask Agent Wallet Launches AI Agents On-Chain
  5. Cloudflare Wallets Bring Stablecoin Payments to AI

To follow blockchain news, track Ethereum protocol progress, and read our latest stories, subscribe to our weekly today.

Join the EtherWorld & Avarch Internship Program and build your career in blockchain, content, social media, video, podcast editing, or operations. Send your resume and brief introduction to contact@etherworld.co.


Disclaimer: The information contained in this website is for general informational purposes only. The content provided on this website, including articles, blog posts, opinions, & analysis related to blockchain technology & cryptocurrencies, is not intended as financial or investment advice. The website & its content should not be relied upon for making financial decisions. Read full disclaimer & privacy policy.

To stay updated on blockchain news, Ethereum protocol progress, and our latest stories, subscribe to our weekly digest and YouTube channel for ELI5 content.

To promote your Web3 articles, events, project updates, and Press Releases, reach out anytime via EtherWorld PR for submissions and collaboration. For other queries, email contact@etherworld.co.

If you’d like to support our work, share the content and consider donating at avarch.eth.

Join our community on Discord and follow us on Twitter, Facebook, LinkedIn & Instagram.

Subscribe to join the discussion.

Please create an account to become a member and join the discussion.

Already have an account? Sign in

Sign up for EtherWorld.co newsletters.

Stay up to date with curated collection of our top stories.

Please check your inbox and confirm. Something went wrong. Please try again.
0/5 free articles read this week
Sign up free