Decentralized Lending Protocol Term Finance Suffers $8.5M Exploit Via Strategy Vaults Governance Control

Decentralized lending protocol Term Finance has fallen victim to a major security breach, suffering an estimated $8.5 million loss after an attacker successfully exploited governance control over its strategy vaults. The incident, which unfolded over the weekend, has drawn swift responses from blockchain security firms, protocol developers, and onchain monitoring platforms as the broader decentralized finance (DeFi) community assesses the damage and investigates the vector used to breach the system.

According to prominent blockchain security firm PeckShield, the malicious actor managed to drain approximately 2,843 Ether (ETH), which was valued at roughly $6.87 million at the time of the exploit. In addition to the stolen Ether, the attacker siphoned 1.68 million USDC. This stablecoin sum was subsequently swapped for approximately 1.68 million Dai (DAI). Another leading blockchain security and analytics firm, CertiK, made a similar assessment of the incident, placing the aggregate financial damage at around $8.5 million.

The severity of the exploit is starkly reflected in the protocol’s total value locked (TVL) metrics prior to the attack. According to data from DeFi analytics platform DefiLlama, the reported losses account for approximately 68% of the $12.45 million that was held within Term’s vault product before the breach occurred. More critically, the stolen funds included nearly the entirety of the protocol’s roughly $8.8 million in Ethereum deposits, leaving the vaults heavily depleted.

In response to the emergency, Term Labs took immediate steps to contain the breach. The development team announced via social media that it had irreversibly shut down all Term Meta Vaults and successfully revoked their decentralized autonomous organization (DAO) governance roles. This emergency action was designed to halt any further deposits into the compromised vaults while deliberately keeping user withdrawals open, allowing participants to retrieve whatever remaining assets were untouched by the exploit.

Initial investigations carried out by the development team suggested that the underlying Term protocol, along with its direct borrowing and lending markets, remained unaffected by the governance takeover. However, developers noted that they were still actively verifying the full scope of the incident to ensure no other areas of the ecosystem were quietly compromised. At the time of reporting, Cointelegraph had reached out to Term Labs for additional comment but was unable to secure a direct statement.

Attacker Allegedly Took Control Through Governance

As security analysts dug deeper into the mechanics of the exploit, onchain monitoring service Defimon shed light on how the breach was orchestrated. According to Defimon, the attacker managed to cheaply acquire a majority stake in a sparsely held governance token associated with the protocol. Armed with this voting power, the malicious actor successfully passed malicious proposals that ultimately granted them administrative control over Term’s strategy vaults. To date, Term Finance has not officially confirmed the exact method by which the attacker acquired this voting control, nor has it detailed which specific governance functions were manipulated to execute the drain.

The vulnerability also prompted scrutiny regarding the underlying infrastructure used by the protocol. The vault contracts in question were built using Yearn V3 infrastructure. However, representatives from Yearn quickly clarified the situation, stating that the attack involved a custom governance wrapper implemented by Term Finance. Yearn explicitly noted that the specific attack vector utilized in this exploit does not apply to standard Yearn vault setups, distancing their core codebase from the incident.

In the wake of the breach, Term Finance stated that it was actively coordinating with external cybersecurity and intelligence teams to pursue asset recovery and comprehensive remediation efforts. The protocol added that it would explore various paths to address any remaining financial shortfall experienced by users affected by the exploit.

This recent security failure compounds historical challenges faced by the protocol. The incident follows an earlier security scare in April 2025, when an oracle error triggered approximately 918 ETH in unintended liquidations across the platform. During that previous event, Term managed to recover about 556 ETH, successfully reducing its final loss to 362 ETH and fully reimbursing the affected users, as detailed in its published postmortem report. Following that oracle-related mishap, Term had publicly pledged to implement third-party validation for critical protocol updates and to increase overall governance transparency to prevent future failures.

Leave a Reply

Your email address will not be published. Required fields are marked *