Decentralized lending protocol Term Finance has suffered an estimated $8.5 million loss following a malicious exploit targeting the governance control mechanisms of its strategy vaults, according to leading blockchain security firms. The security breach has severely impacted the platform’s liquidity pools, drawing renewed scrutiny toward governance vulnerabilities within the decentralized finance (DeFi) sector and prompting an immediate emergency response from the protocol’s development team.
On Sunday, blockchain security and threat intelligence platform PeckShield reported that the attacker successfully drained approximately 2,843 Ether (ETH)—which was valued at around $6.87 million at the time of the attack—alongside 1.68 million USDC. According to on-chain analytics, the stolen stablecoins were subsequently swapped for approximately 1.68 million Dai (DAI). Another prominent blockchain security firm, CertiK, released a similar assessment shortly after, placing the aggregate losses for the protocol and its users at roughly $8.5 million.
The scale of the financial impact is substantial when viewed against the protocol’s total value locked prior to the incident. DefiLlama data indicates that the reported losses represent roughly 68% of the $12.45 million that was held within Term’s vault products before the exploit occurred. Furthermore, the attack wiped out nearly all of the protocol’s approximately $8.8 million in Ethereum deposits, leaving users and developers scrambling to assess the damage and secure remaining assets.
In response to the security breach, Term Labs announced through its official communication channels that it had irreversibly shut down all Term Meta Vaults. The development team also revoked the associated decentralized autonomous organization (DAO) governance roles linked to these vaults. This emergency measure successfully prevented any further deposits from being made into the compromised infrastructure, while deliberately keeping user withdrawal functions open so that unaffected or remaining funds could be retrieved safely.
Initial internal investigations conducted by Term Labs suggested that the underlying Term protocol and its direct borrowing and lending markets remained completely unaffected by the exploit. However, the team noted that it was still actively verifying the full scope of the incident. Representatives from Cointelegraph attempted to reach Term Labs for further commentary regarding the exploit, but the protocol’s team was unavailable for comment at the time of publication.
Attacker Allegedly Took Control Through Governance
As security analysts and protocol developers dive deeper into the mechanics of the exploit, on-chain monitoring service Defimon shed light on how the attack was allegedly executed. According to Defimon, the attacker managed to cheaply acquire a majority stake in a sparsely held governance token. Armed with this voting power, the malicious actor successfully passed a series of unauthorized proposals that granted them direct control over Term’s strategy vaults. To date, Term Finance has not officially confirmed the precise method by which the attacker managed to obtain voting control, nor have they detailed which specific governance functions were manipulated during the attack.
The compromised vault contracts were built using infrastructure provided by Yearn V3. Following speculation regarding the underlying framework, Yearn issued a statement clarifying that the exploit actually involved a custom governance wrapper implemented by the Term team. Yearn emphasized that the specific attack vector utilized in the incident does not apply to standard, out-of-the-box Yearn vault setups.
In the wake of the breach, Term Finance stated that it is actively coordinating with external cybersecurity and blockchain forensics teams to pursue asset recovery and comprehensive system remediation. The protocol added that it would explore various viable paths to address any remaining financial shortfall experienced by depositors.
This security incident is not the first major hurdle faced by Term Finance. In April 2025, the protocol suffered an oracle error that inadvertently triggered approximately 918 ETH in unintended liquidations. During that previous event, Term successfully recovered about 556 ETH, which significantly reduced its final net loss to 362 ETH and allowed the protocol to fully reimburse affected users, according to its official postmortem report. Following that oracle-related incident, Term had publicly pledged to implement third-party validation checks for critical protocol updates and to increase overall governance transparency to prevent future failures.
As the situation develops, Term Finance continues to work alongside security partners to manage remediation efforts, while the broader DeFi community evaluates the ongoing risks associated with sparsely distributed governance tokens and custom wrapper implementations.
