Ethereum lending protocol Term Finance lost an estimated $8.5 million over the weekend after an attacker acquired majority control of a sparsely held governance token and used it to drain the protocol's vault product.
The exploit is the latest example of a governance takeover attack — a class of exploit where buying voting power is cheaper than the assets that voting power controls.
How It Happened
Blockchain security firms PeckShield and CertiK traced roughly $8.5 million in losses: about 2,843 ETH, valued at $6.87 million at the time of the attack, plus 1.68 million USDC that was swapped into Dai.
Onchain monitoring service Defimon said the attacker cheaply accumulated a majority of a lightly held governance token and passed proposals that handed over control of Term's strategy vaults. Term has not confirmed exactly how voting control was obtained or which governance functions were exploited.
The loss represented about 68% of the $12.45 million held in Term's vault product before the attack, according to DefiLlama, including nearly all of its roughly $8.8 million in Ethereum deposits.
Term Shuts the Vaults
Term Labs said it irreversibly shut down all Term Meta Vaults and revoked their DAO governance roles, preventing further deposits while keeping withdrawals open. The team said its investigation found the underlying Term protocol and its direct borrowing and lending markets were unaffected, though it was still verifying the scope.
The vault contracts were built on Yearn V3 infrastructure, but Yearn said the attack involved a custom governance wrapper and does not apply to standard Yearn vault setups. Term said it is coordinating with external security teams on asset recovery and remediation, and will "explore paths to address" any remaining shortfall.
Second Incident for Term
The exploit is Term's second security event. In April 2025, an oracle error triggered about 918 ETH in unintended liquidations; Term recovered 556 ETH, cut the final loss to 362 ETH and reimbursed affected users. In the postmortem, the protocol pledged third-party validation for critical updates and greater governance transparency.
That pledge now reads as an indictment of the gap that remained. The attack pattern — cheap governance tokens, custom wrappers, low participation — is one the DeFi sector has seen repeatedly, and it argues for treating governance control itself as an attack surface, not just code.