Skip to content
  • BTC$75,403−3.13%
  • ETH$2,390−4.86%
  • SOL$96.38−5.55%
  • XRP$1.27−10.54%
  • BNB$708.84−1.80%
  • DOGE$0.0795−5.18%
  • ADA$0.1925−7.38%
  • LINK$10.78−6.91%
DeFi

Term Finance Loses $8.5M in Governance Attack on Vaults

An attacker who bought enough voting power drained about $8.5m from Term Finance's Meta Vaults on Aug 24, roughly 68% of the product's holdings.

Rare Dollar Newsroom 2 min read
A hooded figure at a keyboard with code on screen, representing a governance exploit of a DeFi protocol.
Pexels

In this story

  • ETH $2,390 −4.86%
  • USDC $0.9999 −0.02%
  • DAI $0.9997 −0.02%

Ethereum lending protocol Term Finance lost an estimated $8.5 million on August 24 after an attacker gained governance control of its Meta Vaults, according to blockchain security firms and CoinDesk.

Security firm PeckShield tracked the drain at roughly 2,843 ether, worth about $6.87 million at the time, plus 1.68 million USDC, which was swapped for approximately 1.68 million DAI. CertiK corroborated the total loss estimate at around $8.5 million. DeFiLlama data cited by Cointelegraph put the vaults’ pre-attack holdings at $12.45 million, meaning the attacker removed about 68% of the product’s assets — including nearly all of its roughly $8.8 million in ether deposits.

A governance attack, not a code exploit

Term Finance is a fixed-rate lending protocol where token holders can propose and vote on upgrades through an on-chain governance module. Investigators described the incident as governance-based: the attacker accumulated enough voting power to take control of the vaults’ strategy, then used it to extract funds — in effect buying the keys rather than breaking the code. Reports describe the attacker zeroing out a seven-day timelock that normally delays governance changes.

Yearn distance itself

The Meta Vaults run on Yearn V3 infrastructure, but Yearn said the attack involved a custom governance wrapper and that the vector does not apply to standard Yearn vault setups. Term said it was coordinating with external security teams on asset recovery and remediation, and would “explore paths to address” any remaining shortfall.

A costly month for DeFi

DeFiLlama had already logged 17 separate security incidents in August 2026, totalling roughly $18.8 million, before the Term Finance loss — which pushes the month’s running total past $27 million.

What the incident does not tell you

Loss figures measure what left the vaults, not the damage to a protocol’s reputation, TVL or lending book — which for a fixed-rate lender can outlive the stolen balance. Governance attacks are also the hardest class of incident to insure against, because they exploit the legitimacy of the process rather than a bug.

The takeaway

Term Finance’s exploit is a reminder that in DeFi, the most trusted mechanism — governance — is also an attack surface. Until protocols price voting power as carefully as they audit code, the cheapest way to drain a vault may keep being the most democratic one.

Sources

  1. CoinDesk: Ethereum lending app Term Finance loses $8.5 million after attacker buys voting power
  2. Cointelegraph: Term Finance loses estimated $8.5M in vault governance exploit
  3. DeFiLlama: protocol data
Entities Ethereum