Term Finance Loses $8.5M as Attacker Drains 68% of Vault Deposits
A governance takeover let an attacker empty Term Finance's Meta Vaults of nearly $8.8M in ETH and swap 1.68M USDC for DAI.

Decentralized lending protocol Term Finance lost an estimated $8.5 million on Sunday after an attacker seized governance control of its Meta Vault strategy contracts and drained most of the funds inside. Blockchain security firm PeckShield tracked the theft of roughly 2,843 ETH, worth about $6.87 million at the time, along with 1.68 million USDC that was immediately swapped for around 1.68 million DAI. CertiK put the total loss at a similar $8.5 million.
The numbers show how concentrated the damage was. Term’s vault product held $12.45 million before the attack, according to DefiLlama, meaning the exploit wiped out roughly 68% of that total. Nearly all of the vaults’ approximately $8.8 million in ETH deposits was taken.
Governance token, cheaply bought
Onchain monitoring service Defimon said the attacker acquired a majority stake in a thinly held governance token at low cost, then used that voting power to push through proposals that handed control of the vaults to the attacker’s address. Term has not disclosed exactly how voting control was obtained or which specific governance functions were exploited.
The Block reported that Term’s vault proposals are normally subject to a seven-day delay and can be vetoed by liquidity providers before taking effect. Those safeguards apparently failed to stop this attack from executing.
Vaults shut down, core protocol says it’s untouched
Term Labs said it has irreversibly shut down every Term Meta Vault and revoked their DAO governance roles, blocking any further deposits. Withdrawals remain open for users still holding vault positions. The company said its investigation so far indicates the underlying Term protocol, including its direct borrowing and lending markets, was not affected, though it cautioned it is still verifying the full scope of the incident.
Term is coordinating with external security teams on possible asset recovery. Cointelegraph reported it was unable to reach Term Labs for comment, noting the company has no public press contact and had closed its direct messages on X.
Yearn distances its vault infrastructure
Term’s vault contracts run on Yearn V3 infrastructure, which initially raised questions about whether other Yearn-based vaults could face the same risk. Yearn responded that the attack relied on a custom governance wrapper built specifically for Term, and said the attack vector does not apply to standard Yearn vault deployments.
For depositors, the episode is a reminder that governance weight in DeFi vaults can be worth more than the price of the token that carries it. A sparsely distributed voting token let an attacker buy control cheaply and turn it directly into $8.5 million of user funds within a single weekend.
Sources
Related articles
Ethena Foundation Buys Back Locked ENA, Proposes Buyback Fee Switch as Token Jumps
Two outlets confirm Ethena's buyout of early-investor ENA and a fee-switch proposal, but neither reports exact size, price or rally percentage.
Moonwell Lending Loses $8.7M on Base as MAMO Collateral Price Manipulated
CertiK and PeckShield independently put the loss at $8.7M after an attacker inflated MAMO's price to borrow cbBTC and USDC from Moonwell.
Hyperliquid Policy Center Asks SEC and CFTC to Align Rules on Perpetual Contracts
Hyperliquid's policy arm filed comments urging U.S. regulators to unify perpetuals classification as the platform's derivatives volume grows.