2026-08-24 CoinTelegraph

Term Finance Loses $8.5M in Governance Exploit, Shuts Down Vaults

Decentralized lending protocol Term Finance lost an estimated $8.5 million after an attacker exploited governance control of its strategy vaults, according to blockchain security firms PeckShield and CertiK. On Sunday, PeckShield reported that the attacker drained roughly 2,843 Ether (ETH), valued at $6.87 million at the time, along with 1.68 million USDC, which was swapped for an equivalent amount of Dai (DAI). The loss represented approximately 68% of the $12.45 million held in Term's vault product before the attack, wiping out nearly all of its $8.8 million in Ethereum deposits, per Defillama data.

Onchain monitoring service Defimon reported that the attacker cheaply acquired a majority of a sparsely held governance token and passed proposals enabling it to seize control of Term's vaults. Term has not publicly confirmed how the attacker obtained voting power or which specific governance functions were exploited. The vault contracts rely on Yearn V3 infrastructure, though Yearn clarified that the attack involved a custom governance wrapper and that the vector does not apply to standard Yearn vault setups.

In response, Term Labs said it had irreversibly shut down all Term Meta Vaults and revoked their DAO governance roles, permanently preventing further deposits while keeping withdrawals open. The company stated that its core Term protocol and direct borrowing and lending markets were unaffected, though it was still verifying the full scope of the incident. Term added that it was coordinating with external security teams on asset recovery and pledged to "explore paths to address" any remaining shortfall. Cointelegraph was unable to reach Term Labs for comment, as the company lists no public press contact and has closed its direct messages on X.

The exploit follows an April 2025 oracle error that triggered approximately 918 ETH in unintended liquidations. Term recovered around 556 ETH from that incident, reducing its final loss to 362 ETH and reimbursing affected users, according to its postmortem. After that earlier event, the protocol committed to third-party validation for critical updates and increased governance transparency, measures that ultimately did not prevent Sunday's larger governance-layer compromise.

Read Full Article at CoinTelegraph →

Related Tool

Find Your ID

Try Now →
Check My ID