OKX Banner
BTC $77,395.00 (+1.77%)
ETH $2,457.05 (+2.90%)
BNB $699.42 (+1.98%)
XRP $1.48 (+1.90%)
SOL $94.22 (+1.96%)
TRX $0.34 (+0.47%)
HYPE $79.65 (+1.27%)
DOGE $0.09 (+1.74%)
ZEC $837.73 (+4.54%)
RAIN $0.01 (+1.03%)
LINK $11.53 (+2.30%)
LEO $9.31 (-1.79%)
ADA $0.22 (+1.25%)
XMR $424.60 (-0.89%)
XLM $0.20 (+2.90%)
BCH $266.86 (+0.15%)
CC $0.12 (+8.98%)
GRAM $1.47 (-0.04%)
LTC $52.16 (+1.81%)
HBAR $0.08 (+5.09%)

Term Finance Loses $8.5M as Attacker Hijacks Vault Governance

Share on X icon · Published 1時間前 on August 24, 2026 · Hassan Maishera

Term Finance loses approximately $8.5 million after an attacker exploits vault governance, prompting the permanent shutdown of its Meta Vaults.

Term Finance Loses $8.5M as Attacker Hijacks Vault Governance

TL;DR

  • Term Finance suffered an estimated $8.5 million exploit after an attacker allegedly gained control of governance functions associated with its strategy vaults.

  • The attacker drained approximately 2,843 ETH and 1.68 million USDC, with the USDC subsequently exchanged for roughly 1.68 million DAI.

  • The stolen funds represented approximately 68% of the $12.45 million held in Term’s vault product before the attack.

Term Finance Suffers $8.5 Million Governance Exploit

Decentralized lending protocol Term Finance has suffered an estimated $8.5 million loss after an attacker exploited governance controls connected to its strategy vaults, according to blockchain security firms.

PeckShield said Sunday that the attacker drained approximately 2,843 Ether, worth around $6.87 million at the time, along with 1.68 million USDC.

The stolen USDC was subsequently exchanged for approximately 1.68 million Dai.

Blockchain security company CertiK provided a similar assessment, estimating the total value of the stolen assets at approximately $8.5 million.

The incident underscores the risks associated with governance structures that allow control of decentralized finance products to become concentrated among a small number of tokenholders.

Before the exploit, Term’s vault product held approximately $12.45 million, according to DefiLlama data.

The estimated $8.5 million loss represented roughly 68% of those assets.

The attack also affected nearly all of the approximately $8.8 million in Ethereum deposits held within the vault product before the incident.

The scale of the exploit significantly reduced the assets available within the affected vaults, although Term Labs said withdrawals remain open.

Attacker Allegedly Used Governance Tokens to Seize Control

Onchain monitoring service Defimon alleged that the attacker acquired a majority position in a sparsely held governance token at a relatively low cost.

The attacker then reportedly passed governance proposals that enabled control over Term’s vaults and access to deposited assets.

However, Term Labs has not confirmed how the attacker obtained voting control or which governance mechanisms were used.

The precise sequence of events and the vulnerabilities involved remain under investigation.

If confirmed, the incident would highlight the potential security risks associated with thinly distributed governance tokens and insufficient safeguards around administrative proposals.

Term Labs Permanently Shuts Down Meta Vaults

Following the exploit, Term Labs said it had irreversibly shut down all Term Meta Vaults.

The company also revoked its DAO governance roles, permanently preventing further deposits while allowing users to withdraw remaining funds.

Term Labs said its initial investigation indicated that the underlying Term protocol and its direct borrowing and lending markets were unaffected.

However, the company emphasized that it was still verifying the full scope of the incident.

It added that it was working with external security teams on asset recovery and remediation and would explore potential options for addressing any remaining shortfall.

The affected vault contracts were built using Yearn V3 infrastructure. However, Yearn said the exploit involved a custom governance wrapper rather than a vulnerability in standard Yearn vault configurations.

According to Yearn, the attack vector does not apply to conventional implementations of its vault infrastructure.

The distinction suggests the incident was linked to the governance framework surrounding Term’s vaults rather than a broader flaw in Yearn’s underlying technology.

Incident Follows Previous Oracle-Related Loss

The governance exploit is not the first significant security incident involving Term Finance.

In April 2025, an oracle error triggered approximately 918 ETH in unintended liquidations.

Term later recovered around 556 ETH, reducing the final loss to approximately 362 ETH, and reimbursed affected users, according to its postmortem.

Following that incident, the company pledged to introduce third-party validation for critical updates and improve governance transparency.

The latest exploit renews scrutiny of the protocol’s governance protections and broader risk-management practices as investigators work to determine whether stolen assets can be recovered.

 

Bitcoin Tops $64K as Listed Miners Cut Power 21% for AI
Next article Bitcoin Tops $64K as Listed Miners Cut Power 21% for AI
Hassan Maishera
Hassan Maishera Senior Reporter

Hassan is a Nigeria-based financial content creator that has invested in many different blockchain projects, including Bitcoin, Ether, Stellar Lumens, Cardano, VeChain and Solana. He currently works as a financial markets and cryptocurrency writer and has contributed to a large number of the leading FX, stock and cryptocurrency blogs in the world.