Ethereum Lending Platform Term Finance Loses $8.5 Million in Governance Takeover Attack
Key Takeaways
- •The attacker reportedly bought enough of Term Finance’s governance token supply to gain control over the Meta Vaults.
- •About 2,843 ETH and 1.68 million USDC were withdrawn, representing roughly 68% of the vaults’ assets.
- •Term Finance said its broader lending and borrowing markets were not affected by the incident.
- •The company has permanently shut down the vault product, blocked new deposits, and removed the governance permissions used in the attack.
- •Yearn said the exploit involved Term’s custom governance layer and did not affect standard Yearn vaults.

Ethereum-based lending platform Term Finance lost an estimated $8.5 million after an attacker apparently acquired enough governance voting power to take control of its Meta Vaults. Term Finance focuses on fixed-rate, fixed-term lending and borrowing on Ethereum, with rates set through auction-based markets rather than the variable-rate model common across DeFi.
The attacker withdrew approximately 2,843 ETH — worth roughly $6.9 million at the time — together with 1.68 million USDC, draining about 68% of the vaults' assets. ETH is the native asset of the Ethereum network, while USDC is a widely used U.S. dollar-pegged stablecoin.
Unlike many DeFi exploits, the attack did not stem from a conventional smart-contract vulnerability. Instead, it exploited a weakness in governance. The attacker reportedly bought a majority of the protocol's sparsely held governance token and then used that voting power to approve proposals granting control over the vaults.
Term said its broader lending and borrowing markets were not affected by the incident. The company has permanently shut down the vault product, blocked new deposits, and removed the governance permissions that had enabled changes to the vaults. Term is also working with external security teams on asset recovery and potential compensation for losses, with the extent of any reimbursement still undetermined.
The Meta Vaults were built on Yearn V3 infrastructure, but Yearn said the exploit involved Term's custom governance layer and did not affect standard Yearn vaults. Yearn Finance is a long-established DeFi protocol known for its yield-aggregating vault products.
The incident highlights a growing risk in decentralized finance: when the cost of buying governance control is lower than the value of the assets controlled by that governance, voting mechanisms themselves can become an attack vector. The pattern has precedent — in April 2022, the DeFi protocol Beanstalk lost roughly $180 million after an attacker used a flash loan to amass voting power and push through emergency proposals. Many protocols blunt this exposure with safeguards such as timelock delays, elevated proposal thresholds, and guardian multisignature approvals, which slow or block sudden changes to fund-handling logic.
Source: BitcoinKE