Attacker Buys Governance Control, Drains $8.5M From Term Finance

  • The Term Finance incident underscores a major DeFi governance vulnerability: when a governance token is thinly traded, an attacker may be able to buy controlling voting power for far less than the value of the assets that power can influence.
  • Ethereum lending platform Term Finance has reportedly suffered an $8.5 million loss after an attacker appears to have gained enough voting control to take over several lending vaults.
  • Blockchain records show roughly 2,843 ETH, worth about $6.9 million at the time, was removed along with 1.68 million USDC. The withdrawals amounted to approximately 68% of the assets held in Term’s vaults.
  • Before the attack, Term’s Meta Vaults held around $12.45 million, according to DefiLlama. Nearly the entire ETH balance of approximately $8.8 million was drained.

How the Attacker Allegedly Gained Control

  • The most notable aspect of the incident is the apparent governance takeover behind the withdrawals.
  • Defimon said the attacker appears to have acquired a majority of Term’s lightly traded governance token at a relatively low price. That voting stake allegedly enabled the attacker to approve proposals that transferred control of the lending vaults.
  • The incident highlights a complicated issue within DeFi governance. Buying governance tokens on the open market can be a legitimate activity, but using that voting power to take control of deposited customer funds could cross the line into an exploit or misappropriation.
  • Even if the attacker’s transactions followed the protocol’s programmed rules, the conduct could still attract scrutiny from authorities.
  • Term has not yet explained how the attacker secured majority control or identified all of the governance functions involved. The company has permanently shut down the affected product, halted new deposits and removed the governance permissions that allowed vault parameters to be changed.

Term Says Core Lending Markets Were Not Affected

  • Term said its investigation has so far found no impact on the broader protocol or its direct lending and borrowing markets.
  • The team is working with external security firms to trace and recover the missing funds. It also plans to explore options for covering losses that cannot be recovered.
  • The affected vaults relied on Yearn V3 infrastructure, which automatically shifts deposits between lending markets in search of better returns. Yearn said the attack targeted a custom governance layer built around its technology and did not affect standard Yearn vaults.

Term Had Faced an Earlier Incident

  • The latest attack follows a previous problem at Term. In April 2025, an oracle malfunction triggered about 918 ETH in unintended liquidations.
  • Term subsequently recovered most of the affected assets, reimbursed users and promised stronger governance transparency and independent checks for important protocol changes.
  • The latest incident, however, points to a different weakness: governance itself. It demonstrates how protocols can become vulnerable when the assets controlled by governance decisions are worth substantially more than the tokens required to gain voting control.