Decentralized Lending Protocol Term Finance Suffers $8.5 Million Loss After Governance Exploit

Decentralized lending protocol Term Finance has suffered an estimated $8.5 million loss following a sophisticated security incident in which an attacker successfully exploited governance controls governing its strategy vaults, according to leading blockchain security firms.

The security breach, which unfolded over the weekend, severely impacted the platform’s liquidity pools and triggered immediate emergency containment measures from the project’s development team. Prominent blockchain security and threat intelligence analytics firms quickly mobilized to trace the stolen funds and assess the total financial impact on the protocol and its user base.

On Sunday, prominent blockchain security firm PeckShield reported via social media that the malicious actor successfully drained approximately 2,843 Ether (ETH), which was valued at roughly $6.87 million at the time of the exploit. In addition to the Ether drainage, the attacker made off with 1.68 million USDC, a widely used stablecoin, which was subsequently swapped for approximately 1.68 million Dai (DAI). Another leading security and auditing firm, CertiK, published a very similar estimate regarding the scale of the exploit, placing the aggregate financial damage at around $8.5 million.

The substantial capital loss represented a devastating blow to the protocol’s liquidity metrics, wiping out about 68% of the total $12.45 million held within Term’s specialized vault product prior to the attack. According to comprehensive data aggregated by DefiLlama, this catastrophic drain wiped out nearly all of the protocol’s approximately $8.8 million in Ethereum deposits, leaving users scrambling to assess the safety of their remaining funds and understand how the security perimeter was breached.

In response to the emergency, Term Labs acted swiftly to contain the damage. The organization announced that it had irreversibly shut down all Term Meta Vaults and successfully revoked their decentralized autonomous organization (DAO) governance roles. This drastic measure was designed to block any further unauthorized deposits into the affected contracts while deliberately keeping user withdrawals open to allow individuals to pull out whatever assets remained unscathed.

In its preliminary status updates, Term Labs noted that its ongoing internal investigation found that the underlying Term protocol and its direct borrowing and lending markets remained completely unaffected by the exploit. However, the team emphasized that engineers and security consultants were still working diligently to verify the full scope of the incident. Meanwhile, efforts by media outlets to obtain direct comments from Term Labs proved unsuccessful, as representatives were unavailable for immediate inquiries.

Attacker Allegedly Took Control Through Governance Mechanisms

As security analysts and onchain detectives dug deeper into the mechanics of the exploit, onchain monitoring service Defimon shed light on the potential vector used by the malicious actor. According to Defimon’s public assessments, the attacker managed to cheaply acquire a majority stake in a sparsely held governance token associated with the protocol. Armed with this voting power, the perpetrator was able to push through malicious proposals that effectively granted them administrative control over Term’s strategy vaults.

Despite these insights from onchain tracking services, Term Finance has not yet officially confirmed the exact method by which the attacker obtained voting control, nor has the team explicitly detailed which specific governance functions were manipulated during the attack.

The underlying architecture of the compromised vault contracts relies upon Yearn V3 infrastructure. However, the Yearn team quickly stepped forward to clarify its own position and disclaim responsibility for the design choices that allowed the exploit to occur. Yearn stated publicly that the attack specifically involved a custom governance wrapper implemented by Term Finance, noting firmly that the vulnerability and attack vector do not apply to standard, out-of-the-box Yearn vault setups.

Amid the fallout, Term Finance management emphasized that the protocol is actively coordinating with multiple external blockchain security teams and forensic specialists to pursue asset recovery strategies and comprehensive remediation plans. The project also stated that it would actively explore various administrative and financial paths to address any remaining shortfall faced by users who suffered losses during the exploit.

This recent security crisis follows a previous operational hiccup in April 2025, when an unexpected oracle error triggered roughly 918 ETH in unintended liquidations across the platform. During that earlier incident, Term managed to recover about 556 ETH, successfully reducing its final net loss to 362 ETH and fully reimbursing all affected users, as documented in its official postmortem report. In the wake of that oracle failure, Term had publicly pledged to implement rigorous third-party validation procedures for all critical protocol updates and committed itself to achieving greater governance transparency.

Leave a Reply

Your email address will not be published. Required fields are marked *