Term Finance Hit by $8.5M Exploit After Attacker Seizes Voting Power
3 hours ago
The incident highlights a key weakness in decentralized governance: when governance tokens are thinly traded, an attacker may be able to buy enough voting power to control assets worth far more than the cost of obtaining that influence.
Ethereum lending platform Term Finance has reportedly lost about $8.5 million after an attacker appears to have accumulated enough voting power to seize control of several lending vaults.
Blockchain data shows that approximately 2,843 ETH, valued at around $6.9 million at the time, along with 1.68 million USDC, was withdrawn from the vaults. The attack drained roughly 68% of the assets held by Term’s vault products.
DefiLlama data indicates that Term’s Meta Vaults contained approximately $12.45 million before the incident. Almost the entire $8.8 million ETH balance deposited in the product was reportedly removed.
What makes the attack particularly unusual is the suspected method used to gain control.
Blockchain monitoring firm Defimon said the attacker appears to have purchased a majority stake in Term’s lightly traded governance token at a relatively low cost. Holding enough of the token provided voting rights over protocol decisions, which the attacker allegedly used to approve proposals granting control of the vaults.
The incident raises difficult questions around DeFi governance. Although the attacker may have acquired the voting tokens through legitimate market transactions, using that voting power to gain control over customer deposits goes beyond what would normally be considered routine governance. The transactions may have followed the protocol’s code, but authorities could still potentially view the actions as an exploit or misappropriation.
Term has not yet confirmed how the attacker obtained majority voting control or precisely which governance mechanisms were exploited. The company has since permanently shut down the affected product, disabled new deposits and revoked the governance permissions that allowed changes to the vaults.
Based on its investigation so far, Term said the broader protocol and its direct lending and borrowing markets were not impacted.
The company said it is working with external security specialists to recover the stolen assets and will consider options for making users whole if losses remain.
The affected vaults relied on Yearn V3 infrastructure, software designed to automatically shift deposited funds between lending markets in search of higher yields. Yearn said the incident involved a custom governance system built around its technology and did not affect standard Yearn vaults.
The latest attack also follows an earlier security incident.
In April 2025, an oracle malfunction at Term triggered roughly 918 ETH in unintended liquidations. The protocol later recovered most of the affected funds, compensated users and promised stronger governance transparency and external reviews for critical protocol changes.
Just over a year later, governance appears to have emerged as the protocol’s biggest vulnerability, demonstrating how voting-controlled assets can be worth substantially more than the governance tokens required to gain control of them.
More Stories
Strategy Secures $2B From MSTR Sales, Builds New USD Cash Reserve
Bitcoin Holds Near $78K as Gold Climbs and Altcoins Pause After Huge Rally
Fed Experiment Reveals How Bitcoin Rallies Pull New Buyers Into Crypto