Term Finance Exploited for $8.5M After Voting Power Is Manipulated

  • The $8.5 million Term Finance attack highlights a key weakness in DeFi governance: when voting tokens have limited liquidity, an attacker can potentially buy enough control to influence assets worth far more than the cost of acquiring that voting power.
  • Ethereum lending protocol Term Finance has reportedly lost about $8.5 million after an attacker apparently accumulated enough governance power to take control of several lending vaults.
  • Onchain data shows that around 2,843 ETH, worth roughly $6.9 million at the time, and 1.68 million USDC were withdrawn. The exploit drained approximately 68% of the assets held in Term’s vaults.
  • DefiLlama data shows the affected Meta Vaults contained about $12.45 million before the incident. Nearly all of the roughly $8.8 million worth of ETH deposited in the product was removed.

Governance Token Became the Attack Vector

  • The unusual part of the incident is how the attacker allegedly obtained control of the vaults.
  • Blockchain monitoring firm Defimon said the attacker appears to have purchased a majority of Term’s thinly traded governance token at a low cost. That gave the wallet enough voting power to approve proposals that allegedly transferred control of the vaults.
  • The incident exposes a gray area in decentralized governance. Although purchasing governance tokens and voting with them can be legitimate, using that voting power to gain control of user deposits could potentially be considered an exploit or misappropriation.
  • The fact that the transactions may have followed the protocol’s code does not necessarily eliminate legal concerns, meaning authorities could still scrutinize the attacker’s actions.
  • Term has not confirmed exactly how the attacker obtained majority control or which governance functions were used. The platform has permanently closed the affected product, blocked new deposits and removed the governance permissions that allowed changes to the vaults.

Broader Term Protocol Reportedly Unaffected

  • Term said its investigation so far has found no evidence that its broader protocol or direct lending and borrowing markets were affected.
  • The team is working with external security specialists to trace and recover the stolen assets and will consider options for addressing any losses that remain unrecovered.
  • The affected vaults were built on Yearn V3 infrastructure, which automatically reallocates deposits among lending markets in search of better yields. Yearn said the incident involved a custom governance layer added to its technology and did not affect standard Yearn vaults.

Term Had Already Faced a Security Incident

  • The latest exploit follows an earlier incident at Term in April 2025, when an oracle error triggered about 918 ETH in unintended liquidations.
  • Term later recovered most of the funds, compensated affected users and pledged to improve governance transparency while adding external validation for critical changes.
  • More than a year later, governance appears to have become the protocol’s latest weak point, showing how dangerous it can be when the value controlled by a governance vote is vastly greater than the cost of acquiring enough tokens to control that vote.
  • Related Posts

    Crypto Pauses After Breakout: Bitcoin Near $78K, Gold Rallies, Altcoins Consolidate

    Derivatives Positioning Token Talk

    Continue reading