• 4 mins read
  • Published

Term Finance Hit by $8.5M Exploit After Governance Takeover

Guido Molinari Blockchain economics and tokenomics writer EgonCoin

Post by Guido Molinari

Term Finance Hit by $8.5M Exploit After Governance Takeover EgonCoin © egoncoin.com
Term Finance Hit by $8.5M Exploit After Governance Takeover © egoncoin.com

Term Finance suffered an $8.5 million loss after an attacker gained control of its Meta Vaults through a governance exploit, draining nearly all ETH deposits and forcing the protocol to shut down affected products

Term Finance has shut down its Meta Vaults after an attacker exploited the protocol's governance system, resulting in the loss of approximately $8.5 million in user assets. The incident, which occurred on August 23, was identified by blockchain security firms PeckShield and CertiK, both of which reported that the attacker drained nearly all Ethereum (ETH) and stablecoin deposits from the affected vaults.

Governance Exploit Drains Vaults

According to on-chain monitoring services, the attacker was able to acquire a majority of Term Finance's governance tokens at a low cost due to their sparse distribution. With this controlling stake, the attacker passed proposals that granted them direct control over the vault contracts. PeckShield estimated that 2,843 ETH-worth about $6.87 million at the time-was removed, along with 1.68 million USD Coin (USDC), which was quickly swapped for Dai (DAI). CertiK's analysis placed the total loss at roughly $8.5 million. Prior to the exploit, DefiLlama data showed the vaults held $12.45 million, meaning about 68% of user funds were affected, including nearly all of the $8.8 million in ETH deposits.

Protocol Response and User Impact

Term Labs, the company behind Term Finance, responded by permanently shutting down all Meta Vaults and revoking their decentralized autonomous organization (DAO) governance roles. Withdrawals remain open for existing users, but new deposits are no longer accepted. The company stated that its core borrowing and lending markets were not impacted by the exploit, though a full assessment of the incident's scope is ongoing. Term Labs is working with external security teams to pursue asset recovery and is evaluating options to address any remaining user shortfall.

Technical Details and Security Risks

The exploited vaults were built on Yearn V3 infrastructure, but Yearn clarified that the attack vector was specific to a custom governance wrapper implemented by Term Finance. Standard Yearn vaults are not exposed to the same risk, according to Yearn's team. The precise governance functions used in the exploit have not been publicly confirmed by Term Labs. This event highlights the risks associated with low-liquidity governance tokens, where a determined attacker can cheaply accumulate enough voting power to seize protocol control.

History of Security Incidents

This is not the first time Term Finance has faced a major security event. In April 2025, the protocol suffered unintended liquidations due to an oracle error, resulting in the loss of 918 ETH. Term was able to recover 556 ETH and reimbursed users for the remaining 362 ETH loss. Following that incident, the protocol committed to third-party validation for critical updates and increased transparency around governance. The latest exploit raises new questions about the effectiveness of those measures and the broader risks facing DeFi protocols with on-chain governance.

Security incidents continue to impact crypto companies and protocols across the industry. For example, Greenlane Holdings recently reported a $53.8 million unrealized loss after the value of its BERA token holdings plunged, as detailed in EgonCoin's coverage of Greenlane's crypto treasury losses.

Based on DefiLlama data, Term Finance's Meta Vaults held $12.45 million in assets before the attack, with $8.8 million in ETH and the remainder in stablecoins. The $8.5 million loss represents one of the largest DeFi governance exploits of 2026 to date, underscoring the ongoing vulnerability of protocols with thinly traded governance tokens and limited voting participation.

On-chain governance is a core feature of many decentralized finance protocols, allowing token holders to propose and vote on changes to smart contracts and protocol parameters. While this structure is intended to distribute control and reduce single points of failure, it can also introduce new attack vectors-especially when governance tokens are thinly traded or concentrated in a small number of wallets. Protocols that rely on on-chain voting must carefully consider token distribution, quorum requirements, and safeguards against hostile takeovers to mitigate the risk of governance-based exploits.

Related articles