The Ethereum-based fixed-rate lending platform Term Finance has suffered substantial losses after an attacker manipulated its governance system. Security researchers estimate the damage at around $8.5 million, with the majority of assets drained from the protocol’s specialized vault products on August 23, 2026.
According to analyses from firms including PeckShield and CertiK, the attacker extracted approximately 2,843 ETH—valued at roughly $6.9 million at the time—and about 1.68 million USDC from Term’s strategy vaults.
The stablecoins were subsequently exchanged for a similar amount of DAI.
These withdrawals accounted for nearly 68 percent of the roughly $12.45 million total value locked in the vaults prior to the incident, according to DefiLlama data, and wiped out almost all of the Ethereum-side holdings.
We are aware of a governance exploit impacting Term vaults.
We will share more details once it has been further investigated.
— Term Labs (@term_labs) August 23, 2026
Unlike traditional smart-contract vulnerabilities involving code flaws or flash loans, this incident centered on governance control.
Reports indicate the attacker acquired a controlling stake in a relatively thinly distributed governance token associated with the vaults.
With that voting power in hand—reportedly reaching full control over several USDC vaults and a strong majority in the ETH Meta Vault—the individual or group submitted and passed proposals that redirected funds.
The initial capital used to bootstrap the position has been linked to a small amount of ETH previously mixed through Tornado Cash.
The affected products were Term’s Meta Vaults and related strategy vaults, which operate on Yearn V3 infrastructure but incorporate a custom governance layer developed by Term Labs.
Yearn has clarified that the issue stemmed from Term’s additional governance wrapper rather than any problem with standard Yearn vault designs.
Protective measures such as a seven-day timelock and liquidity-provider veto rights were reportedly in place yet proved insufficient to stop the proposals from executing once the voting thresholds were met.
Term Labs acknowledged the incident promptly in an official statement, noting awareness of a governance exploit impacting the Term vaults and promising additional details after further investigation.
In a subsequent update, the team confirmed it had irreversibly shut down all Term Meta Vaults, revoked the associated DAO governance roles to permanently block new deposits, and left withdrawals open.
Based on its review so far, the underlying Term protocol and its direct borrowing and lending markets remained unaffected.
The project is coordinating with external security teams on remediation and recovery options, and indicated it would explore ways to address any remaining shortfall for users.
This event underscores ongoing challenges in DeFi governance design, particularly when governance tokens have limited circulating supply or low active participation.
Concentrated voting power can enable rapid changes that override intended safeguards, even when technical delays and veto mechanisms exist.
Similar incidents in the broader ecosystem have repeatedly highlighted the need for more robust distribution of governance rights, stronger quorum requirements, and multi-layered oversight of critical functions such as fund movements.
For Term Finance, the losses represent a significant portion of the vault product’s assets and follow an earlier 2025 incident involving an oracle-related issue that also resulted in user losses.
As the DeFi sector matures in 2026, cases like this reinforce the importance of scrutinizing not only smart-contract security but also the economic and participatory assumptions underlying on-chain governance. Users and developers are reminded that decentralization does not automatically eliminate the possibility of concentrated control being leveraged for malicious objectives.