Blockchain security firm PeckShield says the attacker behind the Term Labs governance exploit has started moving stolen funds through Tornado Cash. On July 14, the hacker deposited 300 ETH, worth around $741,000, into the privacy protocol. The deposits were split into three separate 100 ETH transactions.
What happened at Term Labs
The initial breach took place on July 13, 2025. According to PeckShield, the attacker manipulated Term Labs’ governance mechanism and drained about $8.5 million in cryptocurrency. Splitting the deposits into smaller amounts is a common tactic. It helps avoid detection and makes it harder for tracking tools to follow the money.
Tornado Cash is a well-known mixing service. It breaks the on-chain link between source and destination addresses. This makes it difficult for investigators to trace where the funds end up. The service has been used in many high-profile crypto heists since 2019. The U.S. Treasury Department sanctioned it in August 2022, citing its role in laundering over $7 billion, including funds linked to North Korean hacking groups.
Governance exploits remain a weak spot
The Term Labs incident points to a recurring problem in decentralized finance. Governance systems that rely on token holder votes are often targeted. Attackers look for weak proposal execution mechanisms or missing checks and balances. Unlike smart contract bugs, governance exploits involve human decision-making. That makes them harder to prevent with audits alone.
There is now more pressure on protocols to add timelocks and multi-signature requirements. These measures can slow down malicious proposals and give the community time to react. Whether that will be enough is still unclear. Some protocols have already adopted such safeguards, but others remain exposed.
Privacy tools vs. regulation
The use of Tornado Cash in this case also highlights an ongoing tension. Privacy tools serve legitimate purposes, but they are frequently abused by criminals. Regulators have been watching this space closely. The successful laundering attempt could encourage other attackers. We might see more similar exploits in the coming months.
For law enforcement, tracing funds becomes much harder once they enter a mixer. Blockchain analytics firms like PeckShield continue to develop new methods, but it remains a cat-and-mouse game. Some stolen funds have been frozen by exchanges in the past. In other cases, negotiations led to partial returns. There are no guarantees.
Term Labs has not released a public statement about the exploit or the fund movements. The team is likely working with security experts and law enforcement. Recovery efforts have had mixed results across the industry. For now, the incident serves as another reminder that DeFi still has serious security gaps, especially in governance. Stronger safeguards and clearer anti-money laundering measures will likely be needed, but the path forward is not simple.
![]()

