Term Finance Loses $8.5M in Governance Attack on Ethereum Vaults

iconBlockchainreporter
Share
AI summary iconSummary
Ethereum news: Term Finance lost $8.5 million in a governance attack on its Ethereum ecosystem news-linked Meta Vaults. The attacker drained 2,843 ETH and 1.68 million USDC, nearly 68% of the assets. By acquiring a majority of the governance token, the attacker passed proposals to take control. Term has paused the product, blocked deposits, and revoked governance access. Yearn clarified the exploit did not impact its standard vaults.
ethereum68

Ethereum lending platform Term Finance has lost an estimated $8.5 million after an attacker seemingly acquired enough governance voting power to take control of some of its lending vaults, CoinDesk reported.

How the exploit unfolded

The attacker removed roughly 2,843 ether, worth about $6.9 million at the time, and 1.68 million USDC, draining around 68% of the assets held in Term’s Meta Vaults. The vaults held about $12.45 million before the attack, according to DefiLlama data, and nearly all of the ether deposited in the product was taken. The Meta Vaults sat on top of Term’s broader lending platform, which the company said was not affected by the incident.

A governance weak point

The unusual element is how access was gained. Onchain monitoring service Defimon said the attacker cheaply acquired a majority of the project’s sparsely held governance token, then allegedly used that voting power to pass proposals giving it control of the vaults. Term has not confirmed how majority control was obtained or exactly which governance functions were used. The incident sits in a grey area: while the transactions were valid under the protocol’s code, authorities could still treat the conduct as an exploit or misappropriation rather than ordinary governance.

Term’s response and outlook

Term has permanently shut the product, blocked new deposits and removed the governance permissions that allowed changes to the vaults. The team said its broader borrowing and lending markets were unaffected and that it is working with outside security firms on recovering assets, and will explore ways to cover any remaining losses.

Yearn, whose V3 infrastructure underpinned the vaults, said the exploit involved a custom governance layer added around its technology and did not apply to standard Yearn vaults. The episode also follows an April 2025 oracle error that triggered roughly 918 ETH of unintended liquidations, which Term later largely recovered after reimbursing affected users. A little over a year on, governance itself has become the weak point, where assets controlled by a vote can be worth far more than the tokens needed to win that vote.

For context on how DeFi yield strategies work, see our earlier explainer.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.