An attacker drained an estimated $8.5 million from Term Finance vaults on Sunday. The method: exploiting the protocol’s governance system. It is the latest in a string of on-chain governance attacks to hit DeFi lending markets.
Term Labs confirmed the incident on X. “We are aware of a governance exploit impacting Term vaults,” the team wrote, adding it would release more detail after investigating. Term did not confirm the loss figure. It did not name the affected vaults or say how the attacker reached the governance controls.
Blockchain security firms PeckShield and CertiK traced the outflow. PeckShield said the attacker withdrew roughly 2,843 ether (about $6.9 million) plus 1.68 million USDC, which was then swapped for DAI. CertiK separately put the loss at approximately $8.5 million. The funds sit in a single address that first received 2 ETH from Tornado Cash.
The scale is hard to overstate. Term’s vaults held about $12.45 million in total value locked before the exploit. Of that, $8.8 million sat on Ethereum, per DefiLlama. The reported $8.55 million loss equals roughly 68% of vault TVL across all chains and nearly all of the Ethereum side.
Term’s Strategy Vaults are ERC-4626 tokenized vaults built on Yearn V3 infrastructure. They allocate capital between Term’s fixed-rate lending markets and variable-rate protocols. Yearn moved quickly to distance itself. “While their contracts are built on Yearn’s V3 architecture, the exploit occurred via a custom governance wrapper around the vaults and this attack vector is not applicable to standard Yearn vault setups,” Yearn wrote. “Funds deposited to standard Yearn vaults are safe and those vaults are unaffected.”
The governance design was meant to be a backstop. Not a vector. Term separates control into a “manager” role, which handles auction operations, and a “governor” role, which sets risk parameters, the protocol controller, price oracles, and emergency pauses. Vault liquidity providers sit as DAO members. They can vote to veto queued governance transactions during a seven-day timelock. A successful LP veto invalidates the transaction before it executes.
Those controls apparently did not hold. Term has not said which role the attacker used. It has not said whether a governor key was compromised, whether a proposal was pushed through the timelock over LP objection, or why the veto mechanism did not stop the transactions. The seven-day delay and LP veto were billed as safeguards against exactly this kind of attack. That they failed, or were bypassed, is the open question for every DeFi protocol that relies on a timelock as a security boundary.
This is not Term’s first incident. In April 2025, a misconfigured oracle triggered faulty liquidations in the protocol’s tETH market. The loss: $1.6 million. Term recovered more than $1 million and covered the rest from treasury, The Block reported. “This was not a hack. No smart contracts were exploited, and user funds were not directly targeted,” Term said at the time. This time, smart contracts appear to be exactly the point of failure.
Governance attacks have become a recurring pressure point. In March, an attacker spent roughly $1,800 on tokens to push a proposal that threatened $1.08 million at Moonwell. The archetype is older still. Beanstalk lost about $182 million to a flash-loan governance exploit in 2022.
The Block said it could not immediately reach Term Labs for comment.