The attack highlights a broader DeFi governance risk: when a protocol’s voting token has limited liquidity, an attacker can potentially purchase enough influence to control assets worth far more than the cost of acquiring that voting power.
Ethereum-based lending platform Term Finance reportedly suffered an $8.5 million loss after an attacker apparently obtained sufficient voting power to take control of some of its lending vaults.
Onchain data indicates that the attacker withdrew around 2,843 ETH, worth approximately $6.9 million at the time, along with 1.68 million USDC. Together, the withdrawals represented about 68% of the assets held across Term’s vaults.
DefiLlama data shows that Term’s Meta Vaults held approximately $12.45 million before the incident. Almost all of the roughly $8.8 million worth of ETH deposited in the product was reportedly drained.
The unusual element of the incident is the suspected way the attacker obtained control.
According to blockchain monitoring firm Defimon, the attacker appears to have purchased a majority of Term’s thinly traded governance token at a relatively low cost. That stake provided voting authority over protocol decisions, which was allegedly used to approve proposals transferring control of the vaults.
The case also highlights the uncertain boundary between legitimate governance and an exploit. While the attacker may have obtained the voting tokens through normal market transactions, using that influence to gain access to depositor funds is unlikely to be considered ordinary governance activity. Even if the transactions complied with the protocol’s code, authorities could potentially characterize the conduct as an exploit or misappropriation.
Term has yet to disclose exactly how majority control was obtained or which governance mechanisms were used. The company has permanently closed the affected product, stopped new deposits and removed the governance permissions that enabled changes to the vaults.
Term said its investigation so far has found no impact on the wider protocol or its direct lending and borrowing markets.
The team is working with external security specialists to recover the assets and said it would consider measures to address any losses that cannot be recovered.
The affected vaults used Yearn V3 infrastructure, which automatically reallocates deposits among lending markets to pursue higher yields. Yearn said the incident resulted from a custom governance layer built around its infrastructure and did not affect standard Yearn vaults.
The latest incident is not Term’s first security-related setback.
In April 2025, an oracle issue caused roughly 918 ETH in unintended liquidations on the platform. Term later recovered most of the funds, compensated affected users and committed to improving governance transparency and adding external validation for critical changes.
More than a year later, the protocol’s governance structure appears to have become its key vulnerability, illustrating the danger when the value controlled by a vote vastly exceeds the cost of acquiring enough tokens to win that vote.