According to reports from prominent blockchain security firms, the attacker systematically drained a substantial amount of digital assets from the protocol. Leading security firm PeckShield was among the first to alert the crypto community on Sunday, revealing that the malicious actor had managed to siphon approximately 2,843 Ether (ETH). At the time of the exploit, this volume of Ethereum was valued at roughly $6.87 million. In addition to the stolen Ether, the attacker also made off with 1.68 million USDC, which was swiftly swapped for approximately 1.68 million Dai (DAI) to obfuscate or consolidate the funds.
Another major blockchain intelligence and security organization, CertiK, published a very similar assessment shortly after the attack came to light. CertiK pegged the aggregate financial damage at approximately $8.5 million, aligning closely with the figures calculated by onchain investigators.
The scale of the losses dealt a severe blow to Term Finance’s liquidity pools and vault products. Before the security breach occurred, DefiLlama data indicated that Term’s vault products held roughly $12.45 million in total assets. The $8.5 million drained by the attacker represents an alarming 68% of the platform’s total vault holdings prior to the incident. Furthermore, the exploit consumed nearly the entirety of the protocol’s Ethereum deposits, which had hovered around $8.8 million.
In the wake of the exploit, the team behind the protocol took immediate emergency measures to contain the damage. Term Labs announced through official social media channels that it had irreversibly shut down all Term Meta Vaults. As part of this emergency shutdown, the development team revoked the associated DAO governance roles. By cutting off these governance pathways, the protocol effectively prevented any further deposits from being made into the vulnerable vaults, while consciously keeping withdrawal channels open to allow remaining users a pathway to salvage their uncompromised funds.
In its preliminary statements, Term Labs noted that its ongoing internal investigation suggested the underlying Term protocol, along with its direct borrowing and lending markets, remained unaffected by the exploit. However, the team emphasized that verification efforts were still ongoing to fully determine the complete scope of the security compromise. Coin-related media outlets, including Cointelegraph, attempted to reach out to Term Labs for additional comments and official statements, but representatives were unavailable at the time of publication.
Attacker allegedly took control through governance
As blockchain sleuths and security analysts dug deeper into the mechanics of the exploit, more details began to emerge regarding how the attacker managed to breach the protocol’s defenses. Onchain monitoring service Defimon provided insight into the attack vector, suggesting that the malicious actor executed a low-cost takeover of the platform’s administrative structures. According to Defimon, the attacker cheaply acquired a majority stake in a sparsely held governance token associated with the protocol. Once holding dominant voting power, the actor successfully passed malicious proposals that granted them administrative control over Term’s strategy vaults.
It is worth noting that while Term Finance has not yet officially confirmed the precise method by which the attacker obtained voting control or explicitly detailed which governance functions were leveraged in the attack, the theory of a governance token accumulation aligns with the nature of the breach.
The underlying architecture of the vault contracts relies on Yearn V3 infrastructure, which naturally led to questions regarding the security of the broader Yearn ecosystem. However, Yearn representatives quickly clarified the situation, stating via social media that the exploit involved a custom governance wrapper implemented by Term. Yearn explicitly assured the community that the specific attack vector utilized in this incident does not apply to standard, out-of-the-box Yearn vault setups.
Despite the severity of the incident, Term Finance has signaled its commitment to addressing the crisis and supporting its user base. The protocol stated that it is actively coordinating with external cybersecurity teams and blockchain forensic experts to pursue asset recovery and comprehensive remediation. Furthermore, the platform noted that it would explore various pathways to address any remaining financial shortfall left by the exploit.
This unfortunate security breach follows a previous operational hurdle experienced by the protocol in April 2025. At that time, an oracle error triggered approximately 918 ETH in unintended liquidations across the platform. In the aftermath of that earlier incident, Term successfully recovered roughly 556 ETH, which reduced its final net loss to 362 ETH. The protocol subsequently reimbursed all affected users, detailing the event in an official postmortem report. Following that oracle malfunction, Term had publicly pledged to implement third-party validation for critical protocol updates and to increase overall governance transparency.
As the situation continues to develop, industry observers and affected liquidity providers await further updates from the Term Labs team regarding potential recovery efforts, forensic tracking of the stolen funds, and future remediation plans for the protocol.
