
Term Finance’s decentralized lending protocol suffered an estimated $8.5 million loss after an attacker allegedly exploited governance control over its strategy vaults, according to multiple blockchain security monitoring firms. The incident highlights a recurring risk in DeFi: even when a lending protocol’s core markets continue to operate, weaknesses around vault governance and upgrade paths can still lead to large, fast-moving drains.
PeckShield said the attacker drained approximately 2,843 ETH (worth about $6.87 million at the time) and 1.68 million USDC, which was converted into roughly 1.68 million DAI. CertiK reported a similar total, placing the combined losses at around $8.5 million. Term’s vault product held about $12.45 million before the exploit, according to DefiLlama data.
Key takeaways
Security firms attribute the drain to governance control over Term Finance’s strategy vaults rather than a break of the core protocol markets. About 68% of vault assets were reportedly lost, with the attacker converting USDC into DAI after taking funds. Term Labs says it has shut down the affected vaults and revoked their DAO governance roles to stop further deposits. Yearn V3 infrastructure was involved, but Yearn says the attack used a custom governance wrapper, limiting how much the finding applies to standard Yearn setups.Loss estimates and what was taken
According to PeckShield, the attacker executed withdrawals that totaled 2,843 ETH and 1.68 million USDC, later swapping the stablecoin into about 1.68 million DAI. CertiK’s assessment aligned with PeckShield’s, suggesting the total loss across the drained assets reached roughly $8.5 million.
These figures matter because they contextualize the scale relative to what was actually exposed. Before the exploit, Term’s vault product reportedly held about $12.45 million (DefiLlama). The security firms’ estimates imply the attacker removed around 68% of that value—during a period in which the vaults included nearly all of Term’s approximately $8.8 million in Ethereum deposits, based on the same DefiLlama data.
Term Labs shuts vaults and changes governance
In a post on X, Term Labs said it had taken emergency steps to limit further damage. The company stated it had irreversibly shut down all Term Meta Vaults and revoked their DAO governance roles, which it said would permanently prevent additional deposits while leaving withdrawals open.
Term Labs also indicated that, based on its investigation so far, the underlying Term protocol and its direct borrowing and lending markets were not affected. Even so, it said it was still verifying the full scope of what was impacted.
Cointelegraph reported it could not reach Term Labs for further comment. The company does not appear to list a public press contact, and its X direct messages were closed at the time of reporting.
How governance may have been compromised
Defimon, an on-chain monitoring service, suggested the attacker likely took control in a governance-related maneuver rather than via a direct exploit of the vault strategies themselves. Defimon claimed the attacker acquired a majority of a sparsely held governance token “cheaply” and then passed proposals that enabled it to seize control of Term’s vaults.
Crucially, Defimon’s statement did not specify the precise mechanism by which the attacker obtained voting control, nor did it clarify which governance functions were used. Term has also not publicly confirmed the path to voting control in the reports summarized by PeckShield, CertiK, or Defimon.
The vault contracts reportedly use Yearn V3 infrastructure, which raised questions about whether a weakness in Yearn itself could have been responsible. Yearn responded that the attack involved a custom governance wrapper and said the vector does not apply to standard Yearn vault setups.
For investors and users, this distinction is significant. It suggests the failure mode may be less about the underlying Yearn components and more about the protocol-specific governance layer built on top of them. That’s a useful takeaway for other teams auditing their own vault governance: even established infrastructure can be rendered vulnerable if the wrapper logic or permissioning is poorly defended.
An incident that echoes earlier governance risk
This exploit arrives against a backdrop of prior Term-related security issues. The incident follows an April 2025 oracle error that reportedly triggered unintended liquidations totaling about 918 ETH. In that earlier event, Term said it recovered about 556 ETH, reducing the final loss to about 362 ETH, and reimbursed affected users, as described in its postmortem at term.finance.
After the oracle incident, Term pledged third-party validation for critical updates and greater governance transparency. The latest reported attack again centers on governance—this time not on oracles, but on the decision-making controls around vault access and management—suggesting that governance hardening remains a core area for DeFi risk management.
Term said it was coordinating with external security teams on asset recovery and remediation, and it stated it would “explore paths to address” any remaining shortfall. While the exact recovery outcome was not detailed in the reports summarized here, the company’s approach indicates it views the event as partially reversible or at least seeks to minimize lasting damage where possible.
Yearn’s clarification also offers a broader lesson for the sector: protocols borrowing widely used components still need to scrutinize the surrounding governance and upgrade wrappers. Standard integrations may be safe, but custom permissioning layers can introduce new attack surfaces—especially when governance token distribution is thin or proposals can be approved by an unexpectedly small voting bloc.
Readers should watch whether Term provides a more complete explanation of how voting control was obtained, whether any portion of the drained assets can be recovered, and what governance safeguards are added or modified before vault functionality is restored in any form.
This article was originally published as Term Finance Estimates $8.5M Loss After Vault Governance Exploit on Crypto Breaking News – your trusted source for crypto news, Bitcoin news, and blockchain updates.

5 hours ago
8

Bengali (Bangladesh) ·
English (United States) ·