Decentralized Lending Protocol Term Finance Suffers $8.5 Million Exploit Following Governance Takeover

Decentralized lending protocol Term Finance has suffered a major security breach resulting in the loss of an estimated $8.5 million after an attacker exploited governance controls governing its strategy vaults. Prominent blockchain security and analytics firms first flagged the unauthorized activity over the weekend, revealing a sophisticated maneuver that drained a significant portion of the platform’s total value locked in its vault products.

On Sunday, blockchain security firm PeckShield reported that the malicious actor successfully drained approximately 2,843 Ether (ETH), which was valued at roughly $6.87 million at the time of the incident. Additionally, the attacker made off with 1.68 million USDC, which was subsequently swapped for approximately 1.68 million Dai (DAI). Another leading security organization, CertiK, published a comparable assessment of the breach, placing the total financial damage at approximately $8.5 million.

The sudden loss dealt a severe blow to the protocol’s liquidity reserves, wiping out roughly 68% of the $12.45 million that had been held within Term’s vault products prior to the attack. According to data compiled by DefiLlama, the stolen funds accounted for nearly all of the approximately $8.8 million in Ethereum deposits that users had entrusted to the platform.

In response to the emergency, Term Labs announced through social media that it had taken swift, irreversible action to shut down all Term Meta Vaults. The team revoked the associated decentralized autonomous organization (DAO) governance roles for these vaults, a move designed to block any further user deposits while keeping user withdrawals open so that individuals could pull out whatever funds remained. Preliminary findings from the team’s ongoing internal investigation indicated that the underlying Term protocol and its direct borrowing and lending markets remained unaffected by the exploit, though developers and security partners were still working to fully verify the complete scope of the breach. Cointelegraph was unable to reach Term Labs for immediate additional comment regarding the incident.

Attacker Allegedly Took Control Through Governance

As blockchain forensics teams dug into the mechanics of the exploit, onchain monitoring service Defimon shed light on how the breach was executed. According to Defimon, the attacker managed to cheaply acquire a majority stake in a sparsely held governance token associated with the protocol’s management structure. By securing this voting power, the actor was able to push through malicious proposals that granted them direct control over Term’s strategy vaults. To date, Term Finance has not officially confirmed the exact mechanism by which the attacker obtained voting control, nor has it detailed which specific governance functions were manipulated to execute the drain.

The compromised vault contracts were built using Yearn V3 infrastructure, prompting immediate questions across the decentralized finance community regarding the safety of the underlying framework. However, Yearn quickly clarified the situation, stating publicly that the exploit relied on a custom governance wrapper implemented by Term Finance. Yearn emphasized that the specific attack vector utilized in the incident does not apply to standard, out-of-the-box Yearn vault setups.

Term Finance has confirmed that it is actively coordinating with external security teams, blockchain forensic experts, and investigators to pursue asset recovery strategies and long-term remediation. The protocol stated that it would explore various pathways to address any remaining shortfalls left behind by the exploit, though a comprehensive recovery plan has not yet been finalized.

This latest security setback follows a previous incident in April 2025, when an unexpected oracle error triggered roughly 918 ETH in unintended liquidations across the platform. During that prior event, Term successfully recovered approximately 556 ETH, reducing its ultimate net loss to 362 ETH and fully reimbursing the affected users, according to its published postmortem report. In the wake of that oracle failure, Term had publicly pledged to implement stricter third-party validation for critical protocol updates and to increase overall governance transparency to prevent future operational vulnerabilities.

Leave a Reply

Your email address will not be published. Required fields are marked *