Term Finance Hit by Governance Takeover, $8.5M Drained from Ethereum Vaults
AI Market Summary
Term Finance suffered an estimated $8.5M loss after an attacker allegedly amassed majority governance power and used it to seize control of Ethereum-based Meta Vaults, draining ETH and USDC. While Term says core lending markets were unaffected and has shut the product and removed governance permissions, the incident highlights governance attack surface risk in DeFi vault wrappers, potentially weighing on near-term confidence in ETH-denominated yield strategies.
Impact level
● Medium
Affected assets
ETH/USDT+0.32%
AI Insight · ETH/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Ethereum lending platform Term Finance suffered an estimated $8.5 million loss after an attacker appears to have accumulated enough governance voting power to seize control of parts of its lending vault system, CoinDesk reported.
According to on-chain data, the attacker withdrew about 2,843 ETH—valued around $6.9 million at the time—along with 1.68 million USDC. The withdrawals drained roughly 68% of the assets held in Term's Meta Vaults. DefiLlama data shows the Meta Vaults held about $12.45 million prior to the incident, and nearly all ETH deposited into the product was taken.
Term said the broader lending platform sitting beneath the Meta Vaults was not impacted.
The incident stands out for how access was obtained. On-chain monitoring service Defimon said the attacker acquired a majority stake in the project's thinly distributed governance token at low cost, then allegedly used that voting power to pass proposals granting control over the vaults. Term has not confirmed how majority control was achieved or which specific governance mechanisms were used.
The episode also raises a legal and policy question: while the transactions were valid under the protocol's code, authorities may still view the activity as an exploit or misappropriation rather than legitimate governance.
Term has permanently shut down the product, halted new deposits, and removed the governance permissions that enabled vault changes. The team said it is working with external security firms to pursue asset recovery and will consider options to cover any remaining losses.
Yearn, whose V3 infrastructure underpinned the vaults, said the exploit stemmed from a custom governance layer built around its technology and does not affect standard Yearn vaults.
The attack comes after an April 2025 oracle error at Term that triggered about 918 ETH in unintended liquidations—losses the company later largely recovered after reimbursing affected users.
The broader takeaway is that governance itself can become the attack surface in DeFi: when vault-controlled assets are worth far more than the tokens required to win a vote, the incentive to capture governance rises sharply.