DeFi lending protocol Term Finance suffered an estimated $8.5 million loss after an attacker exploited governance controls tied to its strategy vaults, according to blockchain security firms PeckShield and CertiK.
The attacker reportedly withdrew about 2,843 ETH, valued at roughly $6.9 million at the time, along with 1.68 million USDC. The USDC was later exchanged for approximately 1.68 million DAI.
The incident affected Term’s Meta Vaults rather than its core fixed rate borrowing and lending markets. Term Labs has since permanently shut down the Meta Vaults, revoked their DAO governance roles and stopped new deposits while keeping withdrawals open.
Key Takeaways
Term Finance suffered an estimated $8.5 million loss through a governance-related exploit affecting its Meta Vaults.
The attacker reportedly drained about 2,843 ETH and 1.68 million USDC.
The loss represented roughly 68% of the $12.45 million held in Term’s vault product before the attack.
Term’s vault governance included a seven-day timelock and liquidity provider veto mechanism, but those protections did not prevent the exploit.
Term Labs has permanently shut down the Meta Vaults and said its core borrowing and lending markets were not affected.
Governance Controls Failed to Stop the Attack
Term’s strategy vaults used a governance system designed to separate operational control from depositor oversight. The vaults included a seven day delay before queued governance actions could be executed. During that period, liquidity providers acting as DAO participants could vote to veto proposals they considered harmful.
Despite those protections, the attacker was able to gain enough control to execute governance actions that resulted in funds being removed from the vaults. Onchain monitoring service Defimon alleged that the attacker obtained a majority position in a thinly distributed governance token at relatively low cost and then used that voting power to approve proposals giving control over the vaults.
Term Labs has not yet confirmed the exact method used to gain governance control or explained why the timelock and LP veto system failed to stop the transaction sequence. That unanswered question is central to the incident. If the protections functioned as designed but were not used in time, the failure may have been operational. If the attacker found a way around the intended controls, the issue could point to a deeper governance design weakness.
Term Meta Vaults Permanently Shut Down
Following the exploit, Term Labs said it had irreversibly shut down all Term Meta Vaults and removed the DAO governance roles associated with them. New deposits have been disabled, while users can still withdraw remaining funds.
The protocol also said its initial investigation found that the underlying Term Finance markets for direct borrowing and lending were not affected, although it continued to verify the full scope of the incident.
Before the attack, Term’s vault product held about $12.45 million in total value locked, according to DefiLlama. The estimated $8.5 million loss represented approximately 68% of those assets. The exploit also removed nearly all of the roughly $8.8 million in Ethereum deposits held in the vault product before the incident.
Yearn Says Core Vault Infrastructure Was Not Affected
Term’s strategy vaults were built using Yearn V3 infrastructure, but Yearn said the attack did not involve a vulnerability in its standard vault architecture.
According to Yearn, the exploit occurred through a custom governance wrapper added around the vaults.
“While their contracts are built on Yearn’s V3 architecture, the exploit occurred via a custom governance wrapper around the vaults and this attack vector is not applicable to standard Yearn vault setups.”
Yearn also said funds deposited in standard Yearn vaults were unaffected. That distinction narrows the issue to the governance layer Term built around the underlying vault infrastructure rather than a broader flaw affecting Yearn V3.
Term Finance Begins Recovery and Remediation Efforts
Term Labs said it is working with external security teams on asset recovery and remediation. The protocol has not yet disclosed whether it has identified the attacker, opened negotiations for a return of funds or determined how much of the loss may ultimately be recoverable. It said it would explore options for addressing any remaining shortfall.
The incident comes after a separate Term Finance loss in April 2025, when an oracle configuration problem caused approximately 918 ETH in unintended liquidations. Term later recovered around 556 ETH, reducing the final loss to roughly 362 ETH and reimbursing affected users. Following that earlier incident, the protocol said it would improve governance transparency and introduce third-party validation for critical updates.
Conclusion
The Term Finance exploit highlights how governance can become a direct security risk even when a protocol includes familiar safeguards such as timelocks and veto rights.
The reported $8.5 million loss, equal to about two-thirds of the vault product’s pre-attack assets, shows that governance security depends not only on smart contract code but also on token distribution, proposal controls and the ability of participants to react during critical windows.
Term’s decision to permanently close its Meta Vaults limits further exposure, but several questions remain unresolved, particularly how the attacker gained control and why the seven-day delay and LP veto mechanism failed to stop the exploit. Those details will be important for determining whether the incident was mainly a governance-design flaw, an operational failure or a combination of both.
Disclaimer: This article is intended solely for informational purposes and should not be considered trading or investment advice. Nothing herein should be construed as financial, legal, or tax advice. Trading or investing in cryptocurrencies carries a considerable risk of financial loss. Always conduct due diligence before making any trading or investment decisions.