Term Finance Loses Estimated $8.5M in Vault Governance Exploit
Key Takeaways
- •Blockchain security firms PeckShield and CertiK estimate that Term Finance lost approximately $8.5 million, including about 2,843 ETH valued at $6.87 million and 1.68 million USDC exchanged for Dai.
- •The reported loss represented roughly 68% of the $12.45 million held in Term's vault product before the attack, including nearly all of its approximately $8.8 million in Ethereum deposits.
- •Term Labs has irreversibly shut down all Term Meta Vaults and revoked their DAO governance roles, preventing further deposits while keeping withdrawals open, and reports that the underlying protocol and its direct borrowing and lending markets were unaffected.
- •Onchain monitoring service Defimon said the attacker cheaply acquired majority control of a sparsely held governance token and passed proposals enabling the seizure, a method Term has not confirmed.
- •Yearn stated the attack involved a custom governance wrapper rather than a flaw in its standard vault infrastructure, and the incident follows a prior April 2025 oracle error at Term that caused unintended liquidations which the firm reimbursed.

Decentralized lending protocol Term Finance lost an estimated $8.5 million after an attacker seized governance control of its strategy vaults, according to blockchain security firms.
On Sunday, PeckShield reported that the attacker drained roughly 2,843 Ether (ETH), valued at $6.87 million at the time, along with 1.68 million USDC, which was exchanged for approximately 1.68 million Dai (DAI). CertiK reached a similar estimate, putting the total loss at around $8.5 million.
The reported loss represented about 68% of the $12.45 million held in Term's vault product before the attack, including nearly all of its approximately $8.8 million in Ethereum deposits, according to DefiLlama data.
Term Labs said it had irreversibly shut down all Term Meta Vaults and revoked their DAO governance roles, a step that prevents further deposits while keeping withdrawals open. The firm added that its investigation so far found the underlying Term protocol and its direct borrowing and lending markets were unaffected, although it was still verifying the scope.
Cointelegraph was unable to reach Term Labs for comment.
Attacker allegedly took control through governance
Onchain monitoring service Defimon said the attacker cheaply acquired a majority of a sparsely held governance token and passed proposals that allowed the vaults to be seized. Term has not confirmed how the attacker obtained voting control or which governance functions were used.
If confirmed, the method would place the incident in a known class of DeFi attacks that target voting power rather than smart contract code. The best-known precedent is Beanstalk, which lost roughly $182 million in April 2022 when an attacker used a flash loan to obtain majority voting power and passed a proposal that drained its reserves. Sparsely held governance tokens are especially exposed to such takeovers, because majority voting power can be acquired cheaply when few tokens are widely distributed.
The vault contracts are built on Yearn V3 infrastructure. However, Yearn said the attack involved a custom governance wrapper and that the attack vector does not apply to standard Yearn vault setups.
Term said it is coordinating with external security teams on asset recovery and remediation, and that it would "explore paths to address" any remaining shortfall.
The incident follows an April 2025 oracle error that triggered about 918 ETH in unintended liquidations. At the time, Term recovered roughly 556 ETH, reduced its final loss to 362 ETH, and reimbursed affected users, according to its postmortem. Following that earlier incident, Term pledged third-party validation for critical updates and greater governance transparency. Term has not detailed whether those pledged measures covered the vault governance layer seized on Sunday, or whether vault depositors will be made whole as users were after the earlier incident.