Term Finance: Hostile Governance Takeover Sparks Significant $8.5M Loss

Term Finance: Hostile Governance Takeover Sparks Significant $8.5M Loss
Table of Contents

TL;DR

  • Term Finance lost approximately $8.5M after an attack in which an external actor acquired majority control of its governance token.
  • The attacker stole 2,843 ETH and 1.68 million USDC, equivalent to 68% of the assets deposited in the protocol’s Meta Vaults.
  • The team permanently shut down the affected product, blocked new deposits, and removed the governance permissions that allowed vault modifications.

The Ethereum-based lending platform Term Finance suffered estimated losses of $8.5 million after an attacker acquired enough voting power to take control of its Meta Vaults and drain the funds deposited in them. The incident was reported by the protocol’s team.

According to on-chain data cited by the monitoring service Defimon, the attacker purchased on the open market a majority of the project’s governance token, which was widely dispersed and had little demand. That position granted the voting rights needed to approve proposals that transferred operational control of the vaults.

The result was the withdrawal of approximately 2,843 ETH —valued at $6.9 million at the time of the attack— and 1.68 million USDC, representing the theft of 68% of the $12.45 million the product managed before the incident, according to DefiLlama.

Term Finance: How the Attack Vector Worked

The case raises a gray area within decentralized governance. The executed transactions were valid under the protocol’s code, as the attacker used voting rights acquired legitimately on the market. However, the use of those rights to seize depositors’ assets can hardly be considered ordinary governance. Authorities could treat the conduct as an exploit or misappropriation of funds.

The team indicated that the Term Finance protocol and its direct lending and deposit markets were not affected according to the ongoing investigation. Following the attack, the project permanently shut down the Meta Vaults, blocked new deposits, and removed the governance permissions that allowed modifications to those structures. It also confirmed that it is working with external security teams on asset recovery and is evaluating mechanisms to cover the remaining losses.

Term Finance’s vaults operated on Yearn V3 infrastructure. Yearn clarified that the exploit involved a custom governance layer built around its technology and that the platform’s standard vaults were not compromised.

A Less Than Encouraging Track Record

This incident is not the first to affect the protocol. In April 2025, an oracle error triggered unintended liquidations of approximately 918 ETH. Term Finance recovered most of those funds, reimbursed affected users, and pledged greater transparency in governance and external validation for critical changes.

Term finance exploit

Just over a year later, governance itself became the weak point: the assets under the control of a single voter turned out to be worth considerably more than the tokens needed to win that vote.

RELATED POSTS

Ads

Follow us on Social Networks

Crypto Tutorials

Crypto Reviews