Term Finance Loses $8.5M in Ethereum Governance Exploit
Term Finance lost $8.5M in a governance exploit. Attacker seized 100% voting on four USDC vaults and 91% on Ethereum Meta Vault. Vaults shut down.
AI SummaryAI
- Term Finance lost an estimated $8.5 million in a governance exploit of its strategy vaults.
- The attacker drained approximately 2,843 ETH and 1.68 million USDC, later converted to DAI.
- Stolen assets represented about 68% of the $12.45 million TVL in the vault product.
- Term Labs shut down all Term Meta Vaults and revoked DAO governance roles.
Term Finance Vaults Hit by Governance Exploit
Decentralized lending protocol Term Finance lost an estimated $8.5 million after an attacker took control of its strategy vaults through a governance exploit. Two independent security firms, PeckShield and CertiK, estimated the theft at roughly $8.5 million. PeckShield detailed the drain as 2,843 ETH and 1.68 million USDC, the latter later exchanged for approximately 1.68 million DAI. The vault product's total value locked had been $12.45 million before the attack, so the stolen assets accounted for about 68% of it, including nearly all of the ~$8.8 million in Ethereum deposits. On-chain data shows the attacker's address had received 2 ETH from Tornado Cash prior to the exploit. Term Labs responded on X by irreversibly shutting down all Term Meta Vaults and revoking their DAO governance roles, permanently preventing further deposits while keeping withdrawals open. The company said its core lending protocol and direct markets were unaffected, though it continued to verify the full scope. Yearn Finance, which provides the V3 vault infrastructure, clarified that the attack involved a custom governance wrapper specific to Term and does not affect standard Yearn vaults. This incident follows an April 2025 oracle error that caused about 918 ETH in unintended liquidations; Term recovered 556 ETH, reducing the final loss to 362 ETH, per its postmortem. Term Labs also mentioned it would explore paths to address any remaining shortfall and was coordinating with external security teams on asset recovery. The recurring nature of such challenges highlights the risks inherent in DeFi governance design, where a sparsely held governance token can become a vector for attacks. Such vulnerabilities are particularly concerning for altcoin projects that rely on community-based decision-making.
Attacker Seized 100% Voting on Four Vaults
According to on-chain monitoring, the attacker achieved near-total voting control in four of the five USDC strategy vaults, holding 100% of the voting power in each, and approximately 91% in the Ethereum Meta Vault. This was accomplished by acquiring a majority of a sparsely traded governance token, which may have been initially distributed via an airdrop to bootstrap community participation. The attacker then passed proposals that authorized the transfer of funds to an external address. The attacker's address was pre-funded with 2 ETH from Tornado Cash, and the stolen funds were consolidated into a single address, indicating a deliberate plan. Despite the vaults being built on Yearn V3 infrastructure, the exploit did not rely on a code bug but on a governance flaw. Term Labs has not yet disclosed which specific governance role was abused, nor why the liquidity providers' veto and timelock mechanisms failed to prevent the withdrawal. The lack of transparency around these details leaves users uncertain about the robustness of the protocol's governance safeguards. This incident serves as a stark reminder that decentralized governance systems can be manipulated if token distribution is not adequately decentralized or if voting power is concentrated in a few hands. The move into DAI brings attention to the algorithmic stablecoin sector, where code-based peg mechanisms are still debated. The single-address consolidation of funds also suggests a coordinated theft rather than a random exploit.
Full Incident Report Pending as Vaults Stay Shut
The exploit underscores a shifting threat landscape in DeFi, where governance manipulation is now as dangerous as smart contract bugs. The fact that the attacker gained control through a sparsely held token, rather than exploiting code, points to a systemic weakness in many DAO structures. Term Labs' decision to revoke all governance roles and shut down the vaults is a blunt but necessary response, yet the lack of a detailed post-mortem leaves users guessing about the exact vulnerability. On-chain data confirms the theft of 2,843 ETH and 1.68 million USDC, and the attacker's address remains identifiable. Until protocols implement stronger safeguards, such as minimum quorum requirements or veto mechanisms that cannot be overridden, the altcoin ecosystem will remain exposed to similar attacks. While established lending protocols like Aave have navigated governance challenges, the custom wrapper on Yearn infrastructure created a blind spot that standard audits may not catch. This incident should serve as a wake-up call for DeFi projects that rely on governance tokens without adequate distribution decentralization.
Related Tags
AI-generated, AI-reviewed, under COINOTAG editorial oversight.

