Decentralized finance (DeFi) protocol Term Finance has fallen victim to a sophisticated security exploit, resulting in an estimated loss of $8.5 million. According to reports from prominent blockchain security firms, the attack targeted and compromised the governance control mechanisms governing the protocol’s specialized strategy vaults, highlighting ongoing vulnerabilities in decentralized governance frameworks within the broader Web3 ecosystem.
The security breach unfolded over the weekend, drawing immediate attention from on-chain analysts and security researchers. Leading blockchain security and threat intelligence platform PeckShield reported on Sunday that an unidentified malicious actor successfully drained approximately 2,843 Ether (ETH) from the protocol. At the time of the exploit, this volume of Ethereum was valued at roughly $6.87 million. In addition to the native cryptocurrency, the attacker also absconded with 1.68 million USDC. According to on-chain data, these stablecoins were subsequently swapped for approximately 1.68 million Dai (DAI), likely to obscure the trail or consolidate the stolen funds into a more decentralized or easily manageable asset format.
Another prominent blockchain security and auditing firm, CertiK, made a comparable assessment of the financial damage, corroborating the total estimated loss at approximately $8.5 million. The severity of the incident becomes starker when looking at the protocol’s total value locked (TVL) prior to the attack. DefiLlama data indicates that the reported $8.5 million loss accounted for roughly 68 percent of the total $12.45 million held within Term’s vault products before the breach occurred. Crucially, the attack wiped out nearly all of the approximately $8.8 million in Ethereum deposits sitting inside these targeted vaults, leaving depositors facing a catastrophic impairment of their capital.
In response to the emergency, Term Labs—the development entity behind the protocol—took swift action to contain the bleeding. The team announced via social media that it had irreversibly shut down all Term Meta Vaults. Furthermore, developers successfully revoked the DAO governance roles associated with these vaults. This decisive administrative action effectively halted any further deposits from unsuspecting users, while intentionally keeping the withdrawal functions open to allow any remaining, uncompromised capital to be salvaged by rightful owners.
Preliminary investigations conducted by the Term Labs team indicated that the core underlying Term protocol, along with its direct borrowing and lending markets, remained unaffected by the exploit. However, developers noted that they were still actively verifying the full scope of the security incident and auditing related contracts to ensure no lingering vulnerabilities existed elsewhere in the ecosystem. At the time of reporting, Cointelegraph had attempted to reach Term Labs for further comment regarding the incident, but had not received a response.
Attacker Allegedly Took Control Through Governance
As security researchers dove deeper into the mechanics of the exploit, on-chain monitoring service Defimon shed light on how the attacker managed to bypass standard security assumptions. According to Defimon’s analysis, the malicious actor cheaply acquired a majority stake in a sparsely held governance token associated with the protocol’s management structure. Armed with this sudden, concentrated voting power, the attacker was able to successfully push and pass malicious governance proposals. These unauthorized proposals granted the attacker the administrative permissions necessary to seize direct control of Term’s strategy vaults, effectively weaponizing the protocol’s own governance system against it.
As of yet, Term Finance has not officially confirmed the exact mechanics of how the attacker managed to obtain voting control, nor has it publicly detailed precisely which governance functions were leveraged to execute the takeover.
The vault contracts in question were built utilizing Yearn V3 infrastructure, which naturally drew questions regarding the safety of the underlying Yearn framework. However, representatives from Yearn quickly clarified the situation, stating that the exploit did not stem from any inherent flaw in standard Yearn vault setups. Instead, Yearn confirmed that the attack specifically relied upon a custom governance wrapper implemented by Term Finance, meaning the vulnerability was isolated to Term’s unique architectural integration rather than a systemic failure across the wider Yearn ecosystem.
In the wake of the breach, Term Finance stated that it was actively coordinating with external cybersecurity and intelligence teams to strategize on asset recovery and comprehensive remediation. The protocol added that it would "explore paths to address" any remaining capital shortfall left behind by the exploit, though concrete reimbursement plans have not yet been finalized.
This recent security failure compounds an already challenging historical track record for the protocol. The incident follows an earlier crisis in April 2025, when an unexpected oracle error triggered roughly 918 ETH in unintended and erroneous liquidations across the platform. During that previous event, Term managed to successfully recover about 556 ETH, ultimately reducing its net final loss to 362 ETH and fully reimbursing the affected users, according to its published postmortem report. In the aftermath of that oracle failure, Term had publicly pledged to implement stringent third-party validation for all critical protocol updates and promised greater transparency in its governance operations.
As investigations continue, the Term Finance team remains under pressure from the community to provide a comprehensive account of the governance failure and a realistic roadmap for user compensation, while security analysts continue to monitor the movement of the stolen funds across decentralized and centralized mixing services.
