Ethereum lending protocol Term Finance suffered an estimated $8.5 million loss after an attacker apparently gained enough governance voting power to seize control of several lending vaults.
Blockchain data shows the attacker withdrew approximately 2,843 Ether (ETH), valued at around $6.9 million at the time, along with 1.68 million USDC. The exploit drained roughly 68% of the assets stored in Term Finance’s Meta Vaults.
Before the attack, the vaults held approximately $12.45 million in assets, according to DefiLlama data. Nearly all of the roughly $8.8 million worth of ETH deposited in the product was removed.
Unlike a typical smart contract exploit, the Term Finance attack appears to have targeted the protocol’s governance system. Onchain monitoring service Defimon said the attacker may have cheaply accumulated a majority of Term Finance’s thinly distributed governance token, giving them substantial voting power.
The attacker allegedly used that influence to approve governance proposals that provided control over the affected vaults. Term Finance has not yet confirmed exactly how majority control was obtained or which governance functions enabled the withdrawals.
Following the incident, Term Finance permanently shut down its Meta Vaults, disabled new deposits and removed governance permissions that previously allowed modifications to the vaults. The company said its broader protocol, including direct borrowing and lending markets, was unaffected based on its investigation so far.
Term Finance is working with external security specialists to recover stolen assets and said it will consider options for covering any remaining user losses.
The Meta Vaults were built using Yearn V3 infrastructure, which automatically allocates deposits across lending markets to seek higher yields. Yearn said the exploit involved a customized governance layer surrounding its technology and does not affect standard Yearn vaults.
The incident follows an April 2025 oracle error at Term Finance that caused around 918 ETH in unintended liquidations. Most funds were later recovered and affected users reimbursed.
The latest attack highlights a broader DeFi governance risk: when assets controlled through voting are worth significantly more than the cost of acquiring enough governance tokens to control those votes.
Comment 0