Term Finance loses estimated $8.5M in vault governance exploit
Reported by Cointelegraph · AI-assisted summary by ChikoCorp AI News Desk

AI-generated summary based on the linked source; not independently verified. This is not investment advice. Verify market-moving details at the original publisher before acting. See our editorial policy, AI content policy, and financial disclaimer.
Summary
Decentralized lending protocol Term Finance suffered an estimated $8.5 million loss after an attacker exploited governance control of its strategy vaults. The attacker drained about 2,843 Ether (ETH) worth $6.87 million and 1.68 million USDC, subsequently exchanged for Dai (DAI). Term Labs has shut down all Term Meta Vaults, revoked their governance roles, and stated that the core borrowing and lending markets are unaffected so far.
Why it matters
The exploit resulted in a loss of approximately 68% of the $12.45 million held in Term’s vault product, which highlights vulnerabilities in decentralized governance mechanisms. The source does not elaborate on broader market or industry impacts but notes ongoing efforts for asset recovery and remediation.
Key context
The attacker gained majority control by cheaply acquiring sparse governance tokens and passed proposals to seize vault control. Yearn V3 infrastructure was used for the vault contracts, but Yearn clarified the attack involved a custom governance wrapper not affecting standard Yearn vaults. Term Labs previously experienced an oracle error in April 2025 leading to unintended liquidations and reimbursed users afterward.
Key numbers and entities
Term Finance lost an estimated $8.5 million. The attacker drained about 2,843 ETH (valued at $6.87 million) and 1.68 million USDC. Term’s vault product held around $12.45 million before the exploit. Defillama provided vault data; PeckShield and CertiK estimated the losses. Yearn and Term Labs are key protocol entities mentioned.
What remains unclear
Term Labs has not confirmed how the attacker precisely obtained voting control or which governance functions were exploited. The full scope of the impact on Term’s protocols and the final outcome of asset recovery efforts remain unverified. Term Labs has not provided public comments or detailed investigation results.