Decentralized Lending Protocol Term Finance Suffers $8.5 Million Loss After Governance Exploit

Decentralized lending protocol Term Finance has suffered an estimated $8.5 million loss following a malicious exploit targeting the governance control mechanisms of its strategy vaults, according to multiple prominent blockchain security firms.

The security breach, which unfolded over the weekend, severely impacted the platform’s liquidity pools and prompted an immediate emergency response from the protocol’s development team. Leading blockchain security and auditing firm PeckShield reported on Sunday that the attacker successfully drained approximately 2,843 Ether (ETH), which was valued at roughly $6.87 million at the time of the transaction, alongside 1.68 million USDC. The stolen stablecoins were subsequently swapped for approximately 1.68 million Dai (DAI). Another leading security organization, CertiK, issued a closely aligned estimate, placing the aggregate losses for the protocol and its depositors at approximately $8.5 million.

According to analytics data compiled by DefiLlama, the reported losses wiped out roughly 68 percent of the total $12.45 million held within Term’s specialized vault product prior to the attack. The breach drained nearly all of the approximately $8.8 million in Ethereum deposits that users had locked into the system, dealing a substantial blow to the protocol’s total value locked (TVL) and casting a shadow over its structured yield offerings.

In response to the exploit, Term Labs announced through official channels that it had irreversibly shut down all Term Meta Vaults. Furthermore, the development team revoked their associated decentralized autonomous organization (DAO) governance roles. This drastic emergency measure was designed to prevent any further deposits from being made into the compromised architecture while simultaneously keeping user withdrawals open to allow individuals to pull out whatever remaining funds were untouched by the exploit. In its initial preliminary assessments, Term Labs noted that the core underlying Term protocol, along with its direct borrowing and lending markets, appeared to remain unaffected by the attack, though engineers were still actively verifying the full operational scope and safety of those contracts. Cointelegraph was unable to reach representatives from Term Labs for immediate comment regarding the incident.

Attacker Allegedly Took Control Through Governance Mechanisms

As forensic investigators and blockchain sleuths began dissecting the on-chain footprint of the attack, further details regarding the vector emerged. Onchain monitoring and alert service Defimon reported that the attacker managed to cheaply acquire a majority stake in a sparsely held governance token associated with the vault infrastructure. Armed with this voting power, the malicious actor passed unauthorized proposals that effectively granted them administrative control over Term’s strategy vaults, allowing them to systematically drain the funds. As of press time, Term has not officially confirmed the exact mechanics of how the attacker managed to secure voting control, nor has it detailed which specific governance functions were manipulated to execute the drain.

The vault contracts in question were built using Yearn V3 infrastructure. However, Yearn quickly moved to clarify its position, stating that the exploit involved a custom governance wrapper implemented by Term rather than a vulnerability in the underlying architecture. Yearn emphasized that the specific attack vector utilized in this exploit does not apply to standard, unmodified Yearn vault setups.

In the wake of the breach, Term stated that it is actively coordinating with external security teams, forensic analysts, and white-hat organizations to investigate asset recovery avenues and broader remediation strategies. The protocol added that it would "explore paths to address" any remaining financial shortfall experienced by depositors who lost funds in the vaults.

This security incident follows a previous operational hiccup in April 2025, when an oracle error triggered approximately 918 ETH in unintended liquidations across the platform. During that previous event, Term successfully recovered about 556 ETH, ultimately reducing its final net loss to 362 ETH and reimbursing the affected users out of pocket, according to its published postmortem report. In the aftermath of that oracle failure, Term had publicly pledged to implement third-party validation protocols for critical system updates and promised greater transparency across its governance operations.

Leave a Reply

Your email address will not be published. Required fields are marked *