Term Finance loses estimated $8.5M in vault governance exploit

On Sunday, prominent blockchain security and data analytics firm PeckShield reported that the malicious actor drained approximately 2,843 Ether (ETH)—which was valued at roughly $6.87 million at the time of the exploit—along with 1.68 million USDC. The stolen stablecoins were subsequently swapped for approximately 1.68 million Dai (DAI) to obfuscate their trail. Another leading blockchain intelligence and security firm, CertiK, published a very similar financial assessment of the incident, corroborating the total estimated losses at approximately $8.5 million.

The sudden drain dealt a devastating blow to the protocol’s liquidity pools. According to historical and real-time data tracked by DefiLlama, the reported losses represented roughly 68% of the total $12.45 million held within Term’s specialized vault product prior to the attack. More critically, the breach wiped out nearly all of the protocol’s Ethereum deposits, which stood at approximately $8.8 million before the exploit took place.

In response to the emergency, Term Labs moved swiftly to contain the damage. The team announced via social media channels that it had irreversibly shut down all Term Meta Vaults and successfully revoked their DAO governance roles. This emergency measure effectively blocked any further deposits from being made into the vulnerable vaults while deliberately keeping user withdrawal functions open to allow remaining assets to be secured. In its initial preliminary assessments, Term Labs reported that the underlying Term protocol and its direct borrowing and lending markets appeared to be completely unaffected by the exploit, though security engineers were still actively verifying the full scope of the breach. Cointelegraph attempted to reach out to Term Labs for further comment regarding the incident, but representatives were unavailable at the time of publication.

Attacker allegedly took control through governance

As blockchain forensic investigators dug deeper into the mechanics of the exploit, onchain monitoring service Defimon shed light on how the breach was executed. According to Defimon, the attacker managed to cheaply acquire a majority stake in a sparsely held governance token associated with the protocol. Armed with this sudden voting majority, the malicious actor successfully pushed and passed malicious governance proposals that ultimately granted them administrative control over Term’s strategy vaults. To date, Term Finance has not officially confirmed the exact mechanism by which the attacker managed to accumulate the necessary voting control, nor has it detailed which specific governance functions were manipulated to execute the heist.

The compromised vault contracts were built utilizing Yearn V3 infrastructure, prompting immediate questions across the broader decentralized finance community regarding the security of the underlying framework. However, Yearn developers quickly clarified the situation, stating that the attack vector relied upon a custom governance wrapper implemented by Term Finance. Yearn emphasized that the exploit mechanism does not apply to standard, out-of-the-box Yearn vault setups, insulating the broader Yearn ecosystem from the vulnerability.

Following the containment measures, Term Finance stated that it was actively coordinating with external cybersecurity and forensic teams to investigate asset recovery possibilities and formulate a comprehensive remediation plan. The protocol assured stakeholders that it would explore various viable paths to address any remaining financial shortfall left by the exploit.

This recent security failure compounds historical challenges faced by the protocol. The incident closely follows an earlier crisis in April 2025, when a severe oracle error triggered roughly 918 ETH in unintended user liquidations. During that previous event, Term managed to successfully recover about 556 ETH, ultimately reducing its final net loss to 362 ETH and fully reimbursing the affected users, according to its published postmortem report. In the wake of that oracle failure, Term Finance had publicly pledged to implement third-party validation processes for all critical protocol updates and committed itself to achieving greater governance transparency.

As the situation continues to develop, investigators and security analysts remain focused on tracking the stolen funds across various decentralized exchanges and cross-chain bridges, while the Term Finance team works alongside its partners to navigate the aftermath of the multi-million-dollar breach.

Leave a Reply

Your email address will not be published. Required fields are marked *