
An attacker seized control of Term Finance vaults via governance voting, draining $8.5M in ETH and USDC. The protocol has frozen the affected product and is working on recovery.
Ethereum lending protocol Term Finance lost an estimated $8.5 million after an attacker gained enough governance voting power to seize control of several lending vaults.
Blockchain data shows the attacker withdrew roughly 2,843 Ether, valued at about $6.9 million at the time, along with 1.68 million USDC. The exploit drained approximately 68% of the assets held in Term Finance's Meta Vaults.
Before the attack, the vaults held about $12.45 million, per DefiLlama. Nearly all of the roughly $8.8 million in ETH deposited in the product was removed.
Unlike a typical smart contract exploit, this one targeted the protocol's governance system. Onchain monitoring service Defimon said the attacker may have cheaply accumulated a majority of Term Finance's thinly distributed governance token, giving them substantial voting power.
The attacker allegedly used that influence to approve governance proposals that provided control over the affected vaults. Term Finance has not confirmed exactly how majority control was obtained or which governance functions enabled the withdrawals.
Following the incident, Term Finance permanently shut down its Meta Vaults, disabled new deposits, and removed governance permissions that allowed modifications to the vaults. The company said its broader protocol, including direct borrowing and lending markets, was unaffected based on its investigation so far.
Term Finance is working with external security specialists to recover stolen assets and said it will consider options for covering any remaining user losses.
The Meta Vaults were built using Yearn V3 infrastructure, which automatically allocates deposits across lending markets to seek higher yields. Yearn said the exploit involved a customized governance layer surrounding its technology and does not affect standard Yearn vaults.
The incident follows an April 2025 oracle error at Term Finance that caused roughly 918 ETH in unintended liquidations. Most funds were later recovered and affected users reimbursed.
The latest attack illustrates a broader DeFi governance risk: when assets controlled through voting are worth significantly more than the cost of acquiring enough governance tokens to control those votes.
Prepared with AlphaScala editorial tooling from the source reporting linked above. Indexable analysis may include a cited Alpha Score value. Publishing checks screen each story before release. Educational coverage, not personalized advice.