A lending protocol lost $8.5 million to a governance vote — how a vault gets taken over legitimately
Term Finance, a decentralized lending protocol, lost an estimated $8.5 million after an attacker took control of the gov…
Term Finance, a decentralized lending protocol, lost an estimated $8.5 million after an attacker took control of the governance that steered its strategy vaults and used that control to drain them. Blockchain security firms PeckShield and CertiK put the loss at around that figure, and Term has now permanently closed the affected vaults.
PeckShield said the attacker took about 2,843 ether, worth $6.87 million at the time, along with 1.68 million USDC that was exchanged for roughly 1.68 million DAI. According to DefiLlama data, that came to about 68% of the $12.45 million held in Term's vault product before the attack, including nearly all of its roughly $8.8 million in ether deposits.
The mechanism is the part worth understanding. Onchain monitoring service Defimon said the attacker cheaply acquired a majority of a sparsely held governance token, then passed proposals that handed it control of the vaults. Term has not confirmed how the attacker obtained voting control or which governance functions were used. Nothing here required breaking a lock: if a vault answers to a token vote, and the token is cheap enough to accumulate, buying the votes is the exploit.
Term Labs said it had irreversibly shut down all Term Meta Vaults and revoked their DAO governance roles, blocking new deposits while keeping withdrawals open. Its investigation so far found the underlying Term protocol and its direct borrowing and lending markets unaffected, though it was still verifying the scope. The vault contracts were built on Yearn V3 infrastructure, but Yearn said the attack involved a custom governance wrapper and the vector does not apply to standard Yearn vault setups. Term said it was coordinating with external security teams on recovery and would explore paths to address any remaining shortfall. Cointelegraph said it was unable to reach Term Labs for comment.
This is not the protocol's first incident. An oracle error in April 2025 triggered about 918 ETH in unintended liquidations; Term recovered roughly 556 ETH, reduced the final loss to 362 ETH and reimbursed affected users, and afterwards pledged third-party validation for critical updates and greater governance transparency.
For a beginner, the lesson is that depositing into a yield vault means trusting two separate things: the code, and whoever is allowed to change the code's settings. That second thing is governance, and it has a price. Before you deposit, it is fair to ask who holds the governance token, how widely it is distributed, and what a passing vote is actually permitted to do with your money. A vault that answers those questions clearly is easier to trust than one advertising a yield number. Information, not advice.