Decentralized lending protocol Term Finance has fallen victim to a sophisticated security breach, suffering an estimated loss of $8.5 million after an attacker successfully exploited governance control mechanisms governing its strategy vaults. Leading blockchain security and analytics firms have confirmed the incident, which has severely impacted the protocol’s liquidity pools and prompted immediate emergency interventions from its development team.
According to initial reports released by blockchain security firm PeckShield on Sunday, the malicious actor managed to drain approximately 2,843 Ether, an amount valued at roughly $6.87 million at the time of the transaction. In addition to the Ethereum drain, the attacker made off with 1.68 million USDC, which was subsequently swapped for approximately 1.68 million Dai. Concurrently, fellow blockchain security organization CertiK published a similar assessment of the incident, placing the aggregate financial damage at approximately $8.5 million.
The substantial capital outflow dealt a severe blow to the protocol’s asset reserves. The reported losses accounted for roughly 68 percent of the total $12.45 million held within Term’s vault product line prior to the exploit. Furthermore, on-chain data provided by DefiLlama indicates that the attack wiped out nearly all of the protocol’s approximately $8.8 million in Ethereum deposits, leaving the vault infrastructure severely depleted.
In response to the emergency, Term Labs announced through official communication channels that it had taken the drastic step of irreversibly shutting down all Term Meta Vaults. As part of this containment strategy, the development team revoked the associated decentralized autonomous organization governance roles to prevent any further deposits from being made. However, the protocol maintained that user withdrawals remained open to allow participants to retrieve remaining assets where possible. Preliminary investigations conducted by the team indicated that the underlying Term protocol, along with its direct borrowing and lending markets, remained unaffected by the exploit, though developers noted that they were still in the process of verifying the full scope of the security breach. Cointelegraph attempted to reach Term Labs for further comment regarding the incident, but representatives were unavailable at the time of publication.
Attacker Allegedly Took Control Through Governance Mechanisms
As security analysts continued dissecting the on-chain activity, specialized monitoring service Defimon shed light on the mechanics of the exploit. According to Defimon’s assessment, the attacker acquired a majority stake in a sparsely held governance token at a relatively low cost. Armed with this newly established voting power, the malicious actor successfully pushed through malicious proposals that ultimately granted them absolute control over Term’s strategy vaults. Despite these detailed findings from monitoring services, Term Finance has not yet officially confirmed the exact method by which the attacker managed to secure voting control, nor has it specified which exact governance functions were leveraged during the attack.
Technical analysts also scrutinized the infrastructure underlying the affected contracts. The vault contracts in question were built using Yearn V3 infrastructure, prompting questions regarding the security of the underlying framework. However, Yearn issued a public clarification stating that the attack vector relied upon a custom governance wrapper implemented by Term Finance. Yearn explicitly emphasized that the specific attack vector utilized in this exploit does not apply to standard, out-of-the-box Yearn vault setups.
In the wake of the breach, Term Finance stated that it is actively coordinating with external cybersecurity and intelligence teams to strategize on asset recovery and broader remediation efforts. The protocol added that it would explore various pathways to adequately address any remaining financial shortfall experienced by liquidity providers and users.
This security incident is not the first major hurdle faced by the protocol. The platform previously endured an oracle error in April 2025 that triggered approximately 918 ETH in unintended liquidations. During that prior event, Term successfully recovered about 556 ETH, which reduced its ultimate net loss to 362 ETH, an amount the protocol fully reimbursed to affected users according to its published postmortem report. In the aftermath of that 2025 oracle failure, Term had publicly pledged to implement mandatory third-party validation for critical protocol updates and promised greater transparency across its governance structures.
