Ethereum lending platform Term Finance loses $8.5 million in governance attack
Term Finance suffers $8.5 million loss after attacker exploits governance system
Ethereum-based lending platform Term Finance lost approximately $8.5 million after an attacker gained control of its Meta Vaults by acquiring majority voting power. The attacker drained about 68% of the vaults' assets, which included 2,843 ether (a cryptocurrency like digital money) and 1.68 million USDC (a stablecoin pegged to the U.S. dollar).
The Meta Vaults, which automatically move deposits to earn the best returns, held around $12.45 million before the attack. Term Finance stated that its broader lending markets were not affected.
How the attack unfolded
The attacker allegedly bought enough of Term Finance's governance tokens—digital tokens that give holders voting rights over how the platform operates—on the open market to gain majority control. With this control, the attacker passed proposals that allowed them to withdraw funds from the vaults. While the transactions were technically valid under the platform's rules, the method used is considered an exploit rather than normal governance activity.
On-chain monitoring service Defimon reported that the attacker acquired the voting power cheaply, taking advantage of the fact that the tokens were not widely held. This allowed the attacker to control the platform's operations without needing to hack the system directly.
Key details of the incident
- Approximately $8.5 million was drained from Term Finance's Meta Vaults.
- The attacker withdrew 2,843 ether (worth about $6.9 million at the time) and 1.68 million USDC.
- The vaults held $12.45 million before the attack, with nearly all ether deposits taken.
- Term Finance permanently closed the affected product and removed governance permissions.
- The attack did not impact the platform's direct borrowing and lending markets.
Term Finance's response and next steps
Term Finance has shut down the Meta Vaults product, blocked new deposits, and removed the governance permissions that allowed changes to the vaults. The company is working with outside security teams to recover the stolen assets and explore ways to cover any remaining losses for users.
The vaults were built using Yearn V3 infrastructure, a widely used system for automatically managing crypto deposits. Yearn stated that the exploit involved a custom governance layer added by Term Finance and did not affect standard Yearn vaults.
What is confirmed
- Term Finance lost $8.5 million in a governance-related attack.
- The attacker drained 2,843 ether and 1.68 million USDC from Meta Vaults.
- The Meta Vaults product has been permanently closed.
- Term Finance's broader lending markets were not affected.
- Yearn confirmed the exploit involved Term's custom governance layer, not its standard vaults.
What remains unclear
- How exactly the attacker gained majority voting power is not confirmed by Term Finance.
- Whether authorities will treat this as a legitimate governance action or an exploit.
- The full extent of asset recovery efforts and potential reimbursements for affected users.
Why this matters for crypto users
This incident highlights a risk in decentralized finance (DeFi), where platforms are governed by voting tokens. If these tokens are not widely held, attackers can buy enough to gain control and drain funds. It also shows the importance of strong governance protections and transparency in DeFi platforms.
Term Finance had previously faced issues in April 2025 when an error led to unintended liquidations, but it recovered most funds and pledged greater transparency. This latest attack suggests governance systems remain a potential weak point in DeFi.