Written by Ezra Reguerrastaff writerReviewed by Yohan Yunstaff editor
Written by Ezra Reguerrastaff writer
Reviewed by Yohan Yunstaff editor
Term Finance loses estimated $8.5M in vault governance exploit
Latest NewsPublishedAug 24, 2026
Term permanently closed its Meta Vaults after an attack reportedly removed nearly all of their Ethereum deposits.

Decentralized lending protocol Term Finance lost an estimated $8.5 million after an attacker exploited governance control of its strategy vaults, as reported by blockchain security firms.
On Sunday, PeckShield stated the attacker drained about 2,843 Ether (ETH), valued at $6.87 million at the time, and 1.68 million USDC, which was exchanged for approximately 1.68 million Dai (DAI). CertiK made a similar estimate, placing the total loss at around $8.5 million.
The reported loss represented about 68% of the $12.45 million held in Term’s vault product before the attack, including nearly all of its approximately $8.8 million in Ethereum deposits, as reported by Defillama data.
Term Labs stated it had irreversibly shut down all Term Meta Vaults and revoked their DAO governance roles, permanently preventing further deposits while keeping withdrawals open. Based on its investigation so far, the company stated the underlying Term protocol and its direct borrowing and lending markets were unaffected, though it was still verifying the scope.
Cointelegraph was unable to reach Term Labs for comment. The company does not list a public press contact, and its direct messages on X were closed.
Attacker allegedly took control through governance
Onchain monitoring service Defimon stated the attacker cheaply acquired a majority of a sparsely held governance token and passed proposals that allowed it to seize control of Term’s vaults. Term has not verified how the attacker obtained voting control or which governance functions were used.
The vault contracts utilize Yearn V3 infrastructure. nevertheless, Yearn stated the attack involved a custom governance wrapper and the attack vector does not apply to standard Yearn vault setups.
Related: Zilliqa asks exchanges to pause ZIL transfers after suspected cold wallet theft
Term stated it was coordinating with external security teams on asset recovery and remediation. It stated it would “explore paths to address” any remaining shortfall.
The incident follows an April 2025 oracle error that triggered about 918 ETH in unintended liquidations. At the time, Term recovered about 556 ETH, reduced its final loss to 362 ETH and reimbursed affected users, as reported by its postmortem. Following the incident, Term pledged third-party validation for critical updates and greater governance transparency.
Magazine: MiCA cracks down on USDT in Europe… but no one else cares


Subscribe to daily byte-sized crypto news from Cointelegraph
Subscribe
Cointelegraph is committed to independent, transparent journalism. This news article is produced in accordance with Cointelegraph’s Editorial Policy and aims to provide accurate and timely information. Readers are encouraged to verify information independently.
- Hacks
- Hackers
- Security
- Cybersecurity
- DAO
- DeFi
- Blockchain
More on the subject
Solana cuts blockchain slot time to 350 milliseconds
Aug 21, 2026
Zoltan Vardai
Optimism moves 546.9M OP from future airdrops to ecosystem growth fund
Aug 20, 2026
Nate Kostar
Centrifuge adds Symbiotic liquidity network across $1.6B in Janus Henderson, NYLIM funds
Aug 19, 2026
Yohan Yun
Solana cuts blockchain slot time to 350 milliseconds
Aug 21, 2026
Zoltan Vardai
Optimism moves 546.9M OP from future airdrops to ecosystem growth fund
Aug 20, 2026
Nate Kostar
Centrifuge adds Symbiotic liquidity network across $1.6B in Janus Henderson, NYLIM funds
Aug 19, 2026
Yohan Yun