NewsCryptoTerm Finance Loses $8.5M as Attacker Seizes Control of Vault Governance

Term Finance Loses $8.5M as Attacker Seizes Control of Vault Governance

Author: Coincentral·

Key Takeaways

  • The attacker drained 2,843 ETH and approximately $1.68 million in stablecoins, representing about 68% of the roughly $12.45 million held in the affected Meta Vault product.
  • The attacker reportedly acquired TERM governance tokens using 2 ETH traced to Tornado Cash, gaining voting power sufficient to pass malicious proposals controlling vault withdrawals.
  • Term Labs permanently halted Meta Vault deposits and revoked DAO governance roles, while keeping withdrawals open as the investigation continues with outside security teams.
  • Yearn said the exploit involved a custom governance wrapper built by Term Finance and that the same attack path does not apply to standard Yearn vault deployments.
  • The incident follows an April 2025 oracle error at Term that caused about 918 ETH in unintended liquidations, with a final loss of 362 ETH after partial recovery and user reimbursement.
Term Finance Loses $8.5M as Attacker Seizes Control of Vault Governance

Decentralized lending protocol Term Finance has lost an estimated $8.5 million after an attacker gained control of governance tied to its strategy vaults. The Term Finance hack affected the Meta Vault product, the company said, while its borrowing and lending markets remained operational.

The attacker reportedly drained 2,843 ETH and about $1.68 million in stablecoins from the affected vaults after allegedly obtaining majority governance control and using malicious proposals to authorize the withdrawals. DefiLlama data showed the vault product held about $12.45 million before the attack, so the reported losses represented roughly 68% of its assets. The vaults had also held nearly $8.8 million in Ether before the attacker drained most of the deposits.

Security firms PeckShield and CertiK both tracked the attacker's holdings as the incident unfolded. PeckShield reported 2,843 Ether worth $6.87 million alongside 1.68 million USDC, and observed that the attacker exchanged the USDC for 1.68 million DAI (PeckShieldAlert on X).

Term Finance Hack Targets Vault Governance

Term Labs confirmed on August 23, 2026, that a governance exploit had affected Term Vaults. The company said the attack focused on the vault layer built above its fixed-rate lending protocol, and that its review had not found damage to the core lending markets.

Onchain monitor Defimon said the attacker bought a majority share of a lightly held governance token. Reports said the attacker used 2 ETH traced to Tornado Cash—a crypto mixer sanctioned by the U.S. Treasury in 2022 over money-laundering allegations and a recurring feature in past exploit fund trails—to acquire TERM tokens, and that the resulting voting power allowed malicious proposals to pass. Those proposals reportedly gave the attacker control over withdrawals from the strategy vaults.

Buying majority voting power in a thinly held governance token is a recurring failure mode in DeFi rather than a novel one. In April 2022, credit protocol Beanstalk lost roughly $182 million after an attacker used a flash loan to accumulate enough governance tokens to pass a proposal that drained its reserves. Term's reported mechanics are far smaller in scale but follow the same pattern: a modest amount of capital converted into decisive voting power.

The method is said to have bypassed a seven-day timelock and an LP veto process through custom governance logic, although Term Labs has not confirmed this path. Timelocks and similar delays are standard DeFi governance safeguards designed to give users time to react and withdraw before approved changes take effect; if the reported bypass is confirmed, depositors would have had no such exit window.

Yearn Clarifies Its Role

The affected vaults use Yearn V3 infrastructure. Yearn, one of DeFi's longest-running yield-vault protocols, said the attack involved a custom governance wrapper used by Term Finance, and added that the same attack path does not apply to standard Yearn vault deployments.

Term Labs Permanently Closes Meta Vault Deposits

After confirming the incident, Term Labs permanently stopped new deposits into all Meta Vaults and revoked the DAO governance roles linked to the vaults. The company described the shutdown as irreversible, saying it permanently prevents further deposits. Withdrawals remain open for users while the review continues.

Update: All Term Meta Vaults were shut down and dao governance roles have been revoked. This shutdown is irreversible and permanently prevents further deposits. Withdrawals are open.

Today's incident involved Term Vault governance. Based on our investigation so far, the…

— Term Labs (@term_labs) August 23, 2026

Recovery Review Continues After Previous Oracle Loss

Term Labs said it is working with outside security teams on recovery and remediation. The company advised users to temporarily revoke contract approvals and to rely only on official updates while the investigation continues.

The loss adds to a stretch of high-value crypto exploits: blockchain-analytics firms tracked more than $2 billion stolen from crypto platforms in 2024, and the February 2025 theft of roughly $1.5 billion from the Bybit exchange remains the largest on record.

The incident follows an April 2025 oracle error that caused about 918 ETH in unintended liquidations. Term later recovered about 556 ETH, recorded a final loss of 362 ETH, and reimbursed affected users. For vault depositors, the open questions now are whether any of the drained ETH and stablecoins can be traced and recovered, whether the review sustains the initial finding that the core lending markets were untouched, and what replaces the revoked DAO roles for whatever vault operations continue.

Source: CoinCentral