Term Finance loses estimated $8.5M in vault governance exploit

According to blockchain security firm PeckShield, the malicious actor managed to drain approximately 2,843 Ether (ETH)—which carried a valuation of roughly $6.87 million at the time of the exploit—alongside 1.68 million USDC. The attacker subsequently swapped the stablecoins for approximately 1.68 million Dai (DAI). Another leading security and auditing firm, CertiK, corroborated these findings with a nearly identical assessment, pegging the total aggregate loss at approximately $8.5 million.

The devastating scale of the exploit significantly impacted the protocol’s overall liquidity reserves. DefiLlama data indicates that the reported losses wiped out roughly 68% of the $12.45 million total value locked (TVL) held within Term’s vault product prior to the attack. Furthermore, the breach decimated nearly all of the protocol’s approximately $8.8 million in Ethereum deposits, leaving users and developers scrambling to assess the damage and secure remaining assets.

In response to the emergency, Term Labs—the development entity behind the protocol—announced that it had taken swift, irreversible action. The team permanently shut down all Term Meta Vaults and successfully revoked their respective DAO governance roles. These measures were implemented to immediately halt any further incoming deposits while intentionally keeping user withdrawal channels open to allow individuals to pull out whatever unaffected funds remained. In its preliminary post-incident updates, Term Labs noted that its ongoing internal investigation found the core underlying Term protocol, as well as its direct borrowing and lending markets, entirely unaffected by the exploit, though engineers continue to verify the full scope of the vulnerability. Attempts by Cointelegraph to reach Term Labs for direct comments regarding the incident were unsuccessful at the time of publication.

Attacker allegedly took control through governance

Initial onchain investigations into how the exploit unfolded point toward a sophisticated manipulation of the protocol’s administrative voting apparatus. According to alerts issued by onchain monitoring service Defimon, the attacker managed to quietly and cheaply acquire a majority stake in a sparsely held governance token associated with the platform’s management structure. Utilizing this newly minted voting weight, the perpetrator allegedly pushed through malicious proposals that granted them direct, administrative control over Term’s vulnerable strategy vaults. Despite these detailed onchain observations, Term Finance has not yet officially confirmed the precise method by which the attacker managed to secure voting control, nor has it detailed which specific governance functions were manipulated to execute the drain.

The compromised vault contracts were built utilizing underlying Yearn V3 infrastructure, which immediately raised questions across the broader decentralized finance community regarding the security of the foundational framework. However, Yearn officials quickly clarified the situation through social media channels, stating unequivocally that the exploit involved a custom governance wrapper implemented specifically by Term Finance. Yearn emphasized that the unique attack vector exploited in this incident does not apply to standard, out-of-the-box Yearn vault setups or its native implementations.

As the situation developed, Term Finance management confirmed that they are actively coordinating with external cybersecurity specialists and blockchain forensics teams to strategize on asset recovery operations and long-term protocol remediation. The development team stated that they intend to "explore paths to address" any residual financial shortfalls left by the exploit, though specific reimbursement plans have not yet been finalized.

This latest security setback follows a previous operational crisis for the protocol earlier in the year. Back in April 2025, an unexpected oracle error rippled through the platform, triggering approximately 918 ETH worth of unintended and erroneous liquidations. During that incident, Term managed to successfully recover about 556 ETH, ultimately reducing its final net loss to 362 ETH and fully reimbursing all affected platform users, according to its published postmortem report. In the wake of that spring incident, Term publicly pledged to implement rigorous third-party validation processes for all critical protocol updates and committed to fostering greater transparency within its governance structure.

Leave a Reply

Your email address will not be published. Required fields are marked *