Term Finance loses estimated $8.5M in vault governance exploit

Term Finance loses estimated $8.5M in vault governance exploit img1
Spread the love

Written by Ezra Reguerrastaff writerReviewed by Yohan Yunstaff editor

Written by Ezra Reguerrastaff writer

Reviewed by Yohan Yunstaff editor

Term Finance loses estimated $8.5M in vault governance exploit

Latest NewsPublishedAug 24, 2026

Term permanently closed its Meta Vaults after an attack reportedly removed nearly all of their Ethereum deposits.

Decentralized lending protocol Term Finance lost an estimated $8.5 million after an attacker exploited governance control of its strategy vaults, as reported by blockchain security firms. 

On Sunday, PeckShield stated the attacker drained about 2,843 Ether (ETH), valued at $6.87 million at the time, and 1.68 million USDC, which was exchanged for approximately 1.68 million Dai (DAI). CertiK made a similar estimate, placing the total loss at around $8.5 million. 

The reported loss represented about 68% of the $12.45 million held in Term’s vault product before the attack, including nearly all of its approximately $8.8 million in Ethereum deposits, as reported by Defillama data. 

Term Labs stated it had irreversibly shut down all Term Meta Vaults and revoked their DAO governance roles, permanently preventing further deposits while keeping withdrawals open. Based on its investigation so far, the company stated the underlying Term protocol and its direct borrowing and lending markets were unaffected, though it was still verifying the scope. 

Cointelegraph was unable to reach Term Labs for comment. The company does not list a public press contact, and its direct messages on X were closed. 

Attacker allegedly took control through governance

Onchain monitoring service Defimon stated the attacker cheaply acquired a majority of a sparsely held governance token and passed proposals that allowed it to seize control of Term’s vaults. Term has not verified how the attacker obtained voting control or which governance functions were used. 

The vault contracts utilize Yearn V3 infrastructure. nevertheless, Yearn stated the attack involved a custom governance wrapper and the attack vector does not apply to standard Yearn vault setups. 

Related: Zilliqa asks exchanges to pause ZIL transfers after suspected cold wallet theft

Term stated it was coordinating with external security teams on asset recovery and remediation. It stated it would “explore paths to address” any remaining shortfall.

The incident follows an April 2025 oracle error that triggered about 918 ETH in unintended liquidations. At the time, Term recovered about 556 ETH, reduced its final loss to 362 ETH and reimbursed affected users, as reported by its postmortem. Following the incident, Term pledged third-party validation for critical updates and greater governance transparency. 

Magazine: MiCA cracks down on USDT in Europe… but no one else cares

1 minute letter

1 minute letter

Subscribe to daily byte-sized crypto news from Cointelegraph

Subscribe

Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently.

  • Hacks
  • Hackers
  • Security
  • Cybersecurity
  • DAO
  • DeFi
  • Blockchain

More on the subject

Solana cuts blockchain slot time to 350 milliseconds



Aug 21, 2026

Zoltan Vardai

Optimism moves 546.9M OP from future airdrops to ecosystem growth fund



Aug 20, 2026

Nate Kostar

Centrifuge adds Symbiotic liquidity network across $1.6B in Janus Henderson, NYLIM funds



Aug 19, 2026

Yohan Yun

Solana cuts blockchain slot time to 350 milliseconds



Aug 21, 2026

Zoltan Vardai

Optimism moves 546.9M OP from future airdrops to ecosystem growth fund



Aug 20, 2026

Nate Kostar

Centrifuge adds Symbiotic liquidity network across $1.6B in Janus Henderson, NYLIM funds



Aug 19, 2026

Yohan Yun


💡 A Greener Way to Earn: Looking for a smarter, more sustainable way to earn and mining crypto? EcoPool Network is a cloud-based mining pool that does the heavy lifting on remote servers — so you earn rewards around the clock without worrying about overheating hardware or sky-high electricity bills. It’s lightweight, battery-friendly, and built for everyday users. Download EcoPool now and start mining & earning smarter today.

Spread the love

About the Author

Leave a Reply

Your email address will not be published. Required fields are marked *

You may also like these