Term Finance, an Ethereum-based fixed-rate lending protocol, has suffered an estimated $8.5 million loss after an attacker exploited its governance system to take control of several strategy vaults. The incident, which occurred on August 23, is notable because the attacker did not need to exploit a conventional smart-contract vulnerability. Instead, governance itself became the attack surface.
Security firms PeckShield and CertiK independently estimated the losses at roughly $8.5 million. On-chain data indicates that approximately 2,843 ETH, worth around $6.9 million at the time, and 1.68 million USDC were removed from the affected vaults. The USDC was subsequently exchanged for roughly the same amount of DAI.
The episode raises an uncomfortable question for DeFi developers: how secure is a protocol if its governance system can be captured without breaking the underlying code?
Governance Became the Weak Point
Term Finance’s Strategy Vaults use a governance structure that gives designated roles control over operational and risk-related settings, while liquidity providers can participate in voting and veto queued proposals. The system also included a seven-day delay intended to give participants time to identify and block potentially harmful changes.
Those safeguards were not enough to prevent this incident.
According to reports, the attacker accumulated enough voting power to gain control over four of the protocol’s five USDC strategy vaults and roughly 91% control of its Ethereum Meta Vault. That voting position was then used to approve actions that redirected vault assets.
This distinction matters. A smart-contract exploit typically involves finding a way to make code behave differently from its intended rules. A governance attack can be much more subtle: the attacker manipulates the decision-making process until the protocol itself authorizes an otherwise legitimate transaction.
The Scale of the Loss Makes the Attack More Significant
The financial impact was substantial relative to the assets held in the affected vaults. The Block reported that Term’s vaults held approximately $12.45 million before the attack, meaning the estimated $8.55 million loss represented about 68% of that vault product’s total value locked.
That concentration is important when assessing the incident. The entire Term Finance protocol was not wiped out, and its broader lending markets were reported as unaffected. The attack was concentrated in the strategy vault infrastructure rather than representing a complete compromise of the underlying lending platform.
Term Labs has since moved to shut down the affected Meta Vaults and revoke their governance roles. The company is also working with external security teams to investigate the incident and explore asset recovery options.
The Yearn Connection Also Matters
The affected vaults were built using Yearn V3 infrastructure, but the incident should not be interpreted as a compromise of standard Yearn vaults. Reports indicate that the vulnerable component was Term’s custom governance layer built around the vault infrastructure. Yearn has said its standard vaults were not affected.
For the wider DeFi sector, that distinction reinforces a recurring security lesson: composability can extend both functionality and risk. A protocol may rely on established infrastructure while adding its own governance, permission and control mechanisms on top.
Term Finance had already experienced a separate incident in 2025 involving an oracle configuration problem that caused unintended liquidations. The latest attack puts governance design under scrutiny for a second time.
The broader lesson is difficult to ignore. Audited smart contracts and established infrastructure do not automatically make a DeFi protocol safe if governance rights are poorly distributed or economically cheap to capture. As decentralized finance continues to manage larger pools of capital, governance needs to be treated as a security boundary—not simply as a mechanism for community decision-making.
















Comments