Term Finance, an Ethereum-based fixed-rate lending protocol, suffered an estimated $8.5 million exploit on Sunday after an attacker used its vault governance system to transfer ether and stablecoins, according to blockchain security firms PeckShield and CertiK. The incident appears to have struck the protocol’s strategy vaults, where governance permissions can alter core settings governing assets and risk controls.
Term Labs said it was aware of a governance exploit affecting Term vaults and would provide more information once its investigation was complete. The company did not confirm the value of funds removed, identify the affected vaults, or explain how the attacker gained the authority needed to execute the transactions.
PeckShield estimated that the attacker withdrew 2,843 ETH, valued at roughly $6.9 million at the time of its assessment, alongside 1.68 million USDC. The USDC was subsequently exchanged for about 1.68 million DAI, the security firm said. PeckShield traced the assets to one address that had initially received 2 ETH through Tornado Cash, an Ethereum mixing protocol.
CertiK placed the total loss at around $8.5 million. The difference between the firms’ estimates may reflect fluctuating ETH prices or the valuation of assets moved after the initial withdrawals.
Vault losses could erase most Ethereum deposits
The reported loss represents a severe hit to the strategy vault product relative to the capital held there before the breach. DefiLlama showed approximately $12.45 million in total value locked in the vaults before the attack, including about $8.8 million deployed on Ethereum.
An $8.55 million loss would equal roughly 68% of the vault product’s cross-chain deposits and nearly all of the capital listed on Ethereum. Term Finance’s broader protocol had about $25.8 million in total value locked before the incident, according to DefiLlama, while active loans stood at $3.79 million.
That gap illustrates the concentrated exposure created by vault products. Term’s strategy vaults are designed to deploy deposited capital across fixed-rate lending markets and variable-rate lending protocols, aiming to give users managed yield exposure. A breach of the layer responsible for allocation and vault controls can therefore affect funds that may be spread across several underlying defi venues.
Custom governance wrapper is under scrutiny
Term’s strategy vaults use the ERC-4626 tokenized vault standard and are built on Yearn V3 infrastructure, according to Term’s developer documentation. ERC-4626 is a common Ethereum standard that governs how tokenized vault deposits and withdrawals are handled.
Yearn said the exploit involved a custom governance wrapper deployed around the Term vaults, rather than the standard Yearn V3 vault configuration. The statement narrows the immediate technical focus to Term’s added governance design, though it does not establish precisely how the exploit was executed.
Term’s documentation divides authority between two roles. A manager handles auction operations, while a governor controls broader risk settings, configuration decisions and emergency functions. Governors can change the protocol controller, alter the price oracle used by the system, modify risk limits, and pause deposits or strategy activity.
Those powers are intended to let the protocol respond to market stress or operational issues. In the wrong hands, they can also provide a route to redirect funds or change the conditions under which a vault operates.
Liquidity providers are described as DAO members with the ability to veto queued governance actions. The documentation says such transactions face a seven-day timelock and that a successful veto invalidates an action before it can be executed.
Term Labs has not said which governance role the attacker controlled, whether a malicious proposal passed through the normal queue, or why the timelock and veto mechanism did not prevent the transfers. Those details will determine whether the breach stemmed from compromised permissions, a flaw in the custom governance wrapper, an implementation error in the delay mechanism, or another weakness in the vault’s control structure.
A repeat problem for protocol risk controls
The exploit is Term Finance’s second known loss event. In April 2025, a misconfigured oracle — software that supplies external price information to blockchain applications — caused faulty liquidations in Term’s tETH market. The protocol said it recovered more than $1 million from a loss initially estimated at $1.6 million.
The two incidents involve different mechanisms, but both place attention on the systems surrounding a lending market’s core smart contracts. Oracle configuration determines whether collateral is valued correctly. Governance configuration determines who can modify the parameters that shape those valuations, strategies and emergency responses.
defi protocols often use governance to distribute administrative power rather than placing it with a single company-controlled account. The model can give depositors and token holders a formal role in major decisions, yet the protections depend on voting rules, permission boundaries and the practical ability of participants to monitor and challenge pending actions.
Previous attacks show how governance systems can become a direct route to protocol funds. In March, an attacker spent roughly $1,800 acquiring governance tokens in an incident involving Moonwell, according to reports on the event, and passed a proposal that threatened $1.08 million. In 2022, Beanstalk lost about $182 million after an attacker used a flash loan to obtain sufficient voting power for a malicious governance proposal.
The Term breach differs from those cases in one critical respect: available information does not yet show that the attacker accumulated voting tokens or used a flash loan. Term’s own documentation instead points to specialized governor and manager roles within its vault architecture. Treating the incident as a conventional token-voting takeover would go beyond the facts currently disclosed.
Recovery prospects depend on asset movement and controls
The conversion of USDC into DAI may make the stolen assets easier to move across Ethereum’s decentralized finance ecosystem, though both are traceable on public blockchains. Whether any funds can be frozen, recovered through negotiations, or intercepted at later exit points will depend on the attacker’s subsequent transactions and the legal or technical options available to affected parties.
Term Labs has not announced a compensation plan for vault depositors. Its response will likely face close scrutiny given the scale of the estimated loss relative to the vaults’ pre-exploit deposits and the unanswered questions around the seven-day governance delay.
For Term users, the immediate issue is less the protocol’s fixed-rate lending model than the governance layer that sat above its vaults. The incident has turned a set of administrative permissions, designed to manage risk, into the apparent channel through which most of the product’s Ethereum-held value was removed.
Worried about governance exploits? Strengthen your defenses by mastering DeFi basics with our DeFi security guide today.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.
