DeFi lending protocol Term Finance suffered an estimated $8.5 million loss after an attacker gained control of governance mechanisms governing several strategy vaults and used that authority to withdraw assets. Security firms PeckShield and CertiK independently estimated the losses at roughly $8.5 million.
PeckShield reported that approximately 2,843 ETH, worth about $6.9 million at the time, and $1.68 million in USDC were removed. The USDC was subsequently converted into DAI.
The incident affected a significant portion of the assets held in Term’s vault products. DefiLlama data cited by The Block put vault TVL at roughly $12.45 million before the attack, meaning the reported loss represented around two-thirds of the vault assets.
Governance, rather than a conventional code exploit
Early evidence indicates that the incident was primarily a governance takeover, rather than a traditional smart-contract vulnerability.
Reports indicate that the attacker accumulated enough voting power in Term’s relatively thinly distributed governance system to approve proposals affecting the vaults. Those governance actions ultimately enabled the movement of funds. Term Labs has not yet provided a complete technical explanation of how voting control was obtained or which specific governance functions were exploited.
The incident highlights a broader DeFi risk: governance itself can become an attack surface when voting power is concentrated among a small number of participants.
Term’s vault infrastructure incorporates Yearn V3 components, but Yearn has said the incident involved Term’s customized governance layer, rather than a vulnerability in standard Yearn vault deployments.
Term shuts down Meta Vaults
Following the attack, Term Labs said it had permanently shut down its Meta Vaults and revoked their DAO governance roles. The move prevents additional deposits while allowing users to withdraw remaining assets.
The company said its investigation so far indicates that Term’s core lending and borrowing markets were not directly affected, although it was still assessing the full impact.
Term Labs is also working with external security teams on recovery efforts and remediation. The company has not yet confirmed whether the entire reported shortfall can be recovered.
Previous security incident raised governance concerns
The latest attack comes after another significant incident involving Term in April 2025.
An oracle configuration problem triggered approximately 918 ETH in unintended liquidations. Term subsequently recovered around 556 ETH, leaving a final shortfall of roughly 362 ETH, while affected users were reimbursed. Following that incident, the protocol said it would strengthen third-party validation of critical updates and improve governance transparency.
The latest exploit demonstrates why those safeguards extend beyond smart-contract code. A protocol can have functioning contracts yet remain vulnerable if its governance system allows an attacker to acquire effective control over valuable assets.
A warning for DeFi governance
The Term incident underscores a growing challenge for decentralized finance: security is no longer limited to code vulnerabilities.
Smart contracts, oracle systems, administrative permissions and governance structures all form part of a protocol’s security perimeter. When voting power is thinly distributed or poorly monitored, an attacker may not need to break the code at all. They can simply obtain enough authority to make the protocol execute an otherwise valid transaction.
For Term Finance, the immediate priorities are asset recovery, determining exactly how governance control was compromised and strengthening safeguards before any affected vault infrastructure is reconsidered.
The incident is another reminder that decentralization is only as strong as the governance architecture protecting it. (

