Security

Term Finance vaults drained in apparent governance exploit, losses put near $8.5 million

4 min read
Term Finance vaults drained in apparent governance exploit, losses put near $8.5 million

Term Finance lost an estimated $8.5 million to a governance exploit on Sunday. The Ethereum fixed-rate lending protocol was designed with governance safeguards meant to block exactly this kind of attack. They did not hold. Vaults sit behind a seven-day timelock and a liquidity-provider veto, according to blockchain security firms tracking the incident, yet the funds walked out anyway.

PeckShield said the attacker withdrew roughly 2,843 ether, worth about $6.9 million at the time, along with 1.68 million USDC that was then swapped for roughly 1.68 million DAI. CertiK separately put the loss at about $8.5 million. Term itself did not confirm either figure.

“We are aware of a governance exploit impacting Term vaults,” Term Labs wrote on X, adding that it would share more once it had investigated. The Block said it could not immediately reach the team for comment.

The hit fell on a small pool. DefiLlama data cited by The Block placed Term’s vault product at roughly $12.45 million in total value locked across all chains before the attack. About $8.8 million of that sat on Ethereum. An $8.5 million loss takes close to 70% of vault TVL by that measure. Term’s broader protocol TVL stood around $25.8 million, with $3.79 million in active loans.

Safeguards that didn’t stop it

Term’s Strategy Vaults are ERC-4626 tokenized vaults built on Yearn V3 infrastructure. They allocate capital between Term’s fixed-rate lending markets and variable-rate lending protocols. Governance splits in two: a “manager” role handles auction operations, while a “governor” role oversees risk parameters, protocol configuration and emergency functions, according to Term’s developer documentation.

Liquidity providers get a vote. They can move to veto queued governance transactions during a seven-day timelock. A successful veto is supposed to kill a transaction before execution. Governors, meanwhile, carry broad authority: changing the protocol controller, the price oracle, risk limits, or pausing deposits and strategy activity outright.

None of it worked. Term has not said which role the attacker used. It has not explained why the timelock failed to slow transactions enough for a veto to form, or whether any LPs tried. That silence is the story. A protocol built around a seven-day delay was drained regardless. The mechanism meant to give LPs the final word either did not function as advertised or did not function fast enough.

A custom wrapper, not Yearn’s code

Yearn, whose V3 architecture underpins the vaults, moved quickly to put distance between itself and the failure. “While their contracts are built on Yearn’s V3 architecture, the exploit occurred via a custom governance wrapper around the vaults and this attack vector is not applicable to standard Yearn vault setups,” Yearn wrote on X. “Funds deposited to standard Yearn vaults are unaffected.”

That places the fault squarely at Term’s own governance layer, not the vault contracts beneath it.

PeckShield traced the funds to a single Ethereum address that first received 2 ETH from Tornado Cash, a mixing protocol, before the attack. The pattern is common in pre-funded exploit setups. It does not, on its own, identify the attacker.

Not the first time

This is Term’s second public incident in under 18 months. In April 2025, a misconfigured oracle triggered faulty liquidations in its tETH market. Term said it recovered more than $1 million of a $1.6 million loss and covered the remainder from its treasury. “This was not a hack,” the team said at the time. “No smart contracts were exploited, and user funds were not directly targeted.”

This time, the team is calling it an exploit.

Governance attacks carry a longer history in DeFi. In March 2026, an attacker spent roughly $1,800 on tokens to push a Moonwell governance proposal that threatened $1.08 million. In 2022, a flash-loan governance attack on Beanstalk stablecoin protocol cost roughly $182 million. Term’s loss is far smaller. The shape is the same. Governance mechanisms built to let token holders steer a protocol become the door through which it is robbed.

What remains unknown: whether any drained funds have been frozen or recovered, which specific vaults were hit, and whether the attacker exploited the governor role, the manager role, or some custom path not fully described in Term’s documentation. Term has promised more detail. It has not yet delivered.

Avatar of Mara Velasquez

Mara Velasquez

Mara Velasquez covers markets and DeFi for NFT Signals, reporting on price action, liquidity and the listed companies with crypto on their balance sheets. She also tracks exploits and stolen-funds recovery.