TL;DR
- Term Finance lost approximately $8.5M after an attack in which an external actor acquired majority control of its governance token.
- The attacker stole 2,843 ETH and 1.68 million USDC, equivalent to 68% of the assets deposited in the protocol’s Meta Vaults.
- The team permanently shut down the affected product, blocked new deposits, and removed the governance permissions that allowed vault modifications.
The Ethereum-based lending platform Term Finance suffered estimated losses of $8.5 million after an attacker acquired enough voting power to take control of its Meta Vaults and drain the funds deposited in them. The incident was reported by the protocol’s team.
According to on-chain data cited by the monitoring service Defimon, the attacker purchased on the open market a majority of the project’s governance token, which was widely dispersed and had little demand. That position granted the voting rights needed to approve proposals that transferred operational control of the vaults.
Update: All Term Meta Vaults were shut down and dao governance roles have been revoked. This shutdown is irreversible and permanently prevents further deposits. Withdrawals remain open.
Today's incident involved Term Vault governance. Based on our investigation so far, the… https://t.co/e1jstHfzWd
— Term Labs (@term_labs) August 23, 2026
The result was the withdrawal of approximately 2,843 ETH —valued at $6.9 million at the time of the attack— and 1.68 million USDC, representing the theft of 68% of the $12.45 million the product managed before the incident, according to DefiLlama.
Term Finance: How the Attack Vector Worked
The case raises a gray area within decentralized governance. The executed transactions were valid under the protocol’s code, as the attacker used voting rights acquired legitimately on the market. However, the use of those rights to seize depositors’ assets can hardly be considered ordinary governance. Authorities could treat the conduct as an exploit or misappropriation of funds.
Defimon detected an exploit on Term Finance @term_labs that drained ~$8.5M on Ethereum
Attacker cheaply acquired a majority of a sparsely-held DAO governance token, then passed malicious proposals to seize control of Term's vaults.
Tx #1: https://t.co/CeSu6OJxsP
Tx #2:…— Defimon Alerts (@DefimonAlerts) August 23, 2026
The team indicated that the Term Finance protocol and its direct lending and deposit markets were not affected according to the ongoing investigation. Following the attack, the project permanently shut down the Meta Vaults, blocked new deposits, and removed the governance permissions that allowed modifications to those structures. It also confirmed that it is working with external security teams on asset recovery and is evaluating mechanisms to cover the remaining losses.
Term Finance’s vaults operated on Yearn V3 infrastructure. Yearn clarified that the exploit involved a custom governance layer built around its technology and that the platform’s standard vaults were not compromised.
A Less Than Encouraging Track Record
This incident is not the first to affect the protocol. In April 2025, an oracle error triggered unintended liquidations of approximately 918 ETH. Term Finance recovered most of those funds, reimbursed affected users, and pledged greater transparency in governance and external validation for critical changes.
Just over a year later, governance itself became the weak point: the assets under the control of a single voter turned out to be worth considerably more than the tokens needed to win that vote.






