Term Finance Suffers $8.5 Million Loss Following Governance Exploit on Strategy Vaults

Decentralized lending protocol Term Finance has fallen victim to a major security exploit, suffering an estimated loss of $8.5 million after an attacker gained unauthorized governance control over its strategy vaults. Prominent blockchain security and onchain analytics firms quickly flagged the unauthorized transactions, detailing how the protocol’s automated vaults were systematically drained over the weekend.

According to blockchain security firm PeckShield, the malicious actor successfully drained approximately 2,843 Ether (ETH), which was valued at roughly $6.87 million at the time of the exploit. In addition to the stolen Ether, the attacker made off with 1.68 million USDC, which was swiftly swapped for approximately 1.68 million Dai (DAI) to obscure or consolidate the funds onchain. Another leading security firm, CertiK, published a comparable assessment of the incident, corroborating the total estimated losses at approximately $8.5 million.

The financial impact of the breach represents a devastating blow to the platform’s liquidity pools. According to data provided by DefiLlama, the reported losses account for roughly 68% of the total $12.45 million held within Term Finance’s specialized vault products immediately prior to the attack. More critically, the breach wiped out nearly all of the protocol’s Ethereum deposits, which stood at approximately $8.8 million before the security lapse occurred.

In response to the unfolding emergency, Term Labs issued a public statement via social media confirming that it had taken swift, albeit drastic, measures to contain the breach. The development team announced that it had irreversibly shut down all Term Meta Vaults and successfully revoked their associated decentralized autonomous organization (DAO) governance roles. While these emergency actions effectively halted any further deposits into the vulnerable vaults, the protocol kept user withdrawals open to allow participants to retrieve whatever unaffected assets remained.

Term Labs noted in its preliminary incident report that its ongoing investigation found the underlying Term protocol, along with its direct borrowing and lending markets, remained entirely unaffected by the exploit. However, developers emphasized that they were still actively verifying the full scope of the breach and auditing the affected smart contracts. Representatives from Cointelegraph attempted to reach Term Labs for further commentary regarding the incident, but were unable to secure a statement prior to publication.

Attacker allegedly took control through governance

As blockchain forensics teams dissected the mechanics of the attack, onchain monitoring service Defimon shed light on the vector used to compromise the protocol. According to Defimon’s findings, the attacker managed to cheaply acquire a majority stake in a sparsely held governance token associated with the platform. Armed with this sudden voting majority, the perpetrator successfully pushed through malicious proposals that granted them complete control over Term’s strategy vaults, bypassing traditional security checkpoints. As of yet, Term Finance has not officially confirmed the exact mechanism by which the attacker managed to secure voting control, nor has it detailed which specific governance functions were exploited to execute the asset drain.

Further complicating the technical analysis, the vault contracts in question were built using Yearn V3 infrastructure. However, representatives from Yearn were quick to clarify the situation and distance their core infrastructure from the vulnerability. Yearn stated publicly that the exploit specifically involved a custom governance wrapper implemented by Term Finance, emphasizing that the attack vector does not apply to standard, out-of-the-box Yearn vault setups.

Term Finance stated that it is actively coordinating with external cybersecurity experts and leading forensic teams to pursue asset recovery and comprehensive remediation. The protocol added that it will formally "explore paths to address" any remaining financial shortfall left by the exploit once recovery efforts have run their course.

The latest security breach comes as a significant setback for the protocol, which has faced operational hurdles in the past. In April 2025, an unexpected oracle error triggered roughly 918 ETH in unintended liquidations across the platform. During that previous incident, Term successfully recovered about 556 ETH, ultimately reducing its final net loss to 362 ETH and fully reimbursing the affected users, according to its published postmortem report. In the wake of that oracle failure, Term had explicitly pledged to implement third-party validation for all critical system updates and promised greater transparency in its governance procedures.

Leave a Reply

Your email address will not be published. Required fields are marked *