Ethereum lending app Term Finance loses $8.5 million after attacker buys voting power

The exploit shows how lightly held voting tokens can become a means of attack when control of a protocol is cheaper than the assets it governs.

Ethereum lending app Term Finance loses $8.5 million after attacker buys voting power. (Shutterstock)
Özet
  • Term Finance lost an estimated $8.5 million after an attacker apparently gained enough governance voting power to take control of its Meta Vaults.
  • The attacker removed about 2,843 ether and 1.68 million USDC, draining roughly 68 percent of the vaults’ assets, though Term said its broader lending markets were unaffected.
  • Term permanently closed the vault product and removed the relevant governance permissions, while Yearn said the exploit involved Term’s custom governance layer rather than standard Yearn vaults.

Ethereum lending platform Term Finance has lost an estimated $8.5 million after an attacker seemingly acquired enough voting power to take control of some of its lending vaults.

The attacker removed roughly 2,843 ether , worth about $6.9 million at the time, and 1.68 million USDC, blockchain data shows, draining about 68% of the assets held in Term’s vaults.

Term's Meta Vaults held about $12.45 million before the attack, data from DefiLlama show. Nearly all of the roughly $8.8 million in ether deposited in the product was taken.

The unusual part is how the attacker may have gained access.

Onchain monitoring service Defimon said the attacker cheaply acquired a majority of the project’s sparsely held governance token, which gave holders voting rights over how the protocol is operated. The attacker then allegedly used that voting power to pass proposals that gave it control of the vaults.

The incident sits in a grey area of DefI governance. The attacker may have used voting rights acquired on the open market, but the alleged use of those rights to assume control of depositor assets is unlikely to be viewed as ordinary governance. So while the transactions were valid under the protocol’s code, authorities could still treat the conduct as an exploit or misappropriation.

Term Finance lost 68% of its vault assets in a single attack. (Shaurya Malwa/CoinDesk)

Term has not confirmed how the attacker obtained majority control or exactly which governance functions were used. It has now permanently shut the product, blocked new deposits and removed the governance permissions that allowed changes to the vaults.

The wider Term Finance protocol and its direct borrowing and lending markets were not affected based on the company's investigation so far, the team said in a Monday post.

Term said it is working with outside security teams on recovering assets and will explore ways to cover any remaining losses.

The vaults were built using Yearn V3 infrastructure, widely used software that automatically moves deposits between lending markets to chase the best available return. Yearn said the exploit involved a custom governance layer added around its technology and did not apply to standard Yearn vaults.

The attack also comes with some history.

An oracle error in April 2025 triggered about 918 ETH of unintended liquidations at Term. The protocol later recovered most of the funds, reimbursed affected users and pledged greater governance transparency and outside validation for critical changes.

A little over a year later, governance itself appears to have become the weak point — where assets controlled by a vote can be worth far more than the tokens needed to win that vote.

RLUSD OG Image

As stablecoins move into regulated finance, APAC is becoming a key proving ground. This report maps the region’s rules, use cases, and RLUSD’s role.

Why it matters:

As stablecoins move into regulated finance, APAC is becoming a key proving ground. This report maps the region’s rules, use cases, and RLUSD’s role.