Finst

Term Finance Loses $8.5 Million After Governance Attack

The attack mainly hit the Meta Vaults on Ethereum; Term Finance has stopped new deposits and is working with security teams to see whether assets can be recovered.

Term Finance Loses $8.5 Million After Governance Attack

Key Takeaways

  • Term Finance lost an estimated $8.5 million after an attacker gained control over parts of the lending vaults through governance.
  • The attack mainly hit the Meta Vaults; Term permanently shut down the product and blocked new deposits.
  • Term is working with security teams to recover assets and says broader lending and borrowing markets were not affected.

Ethereum lending platform Term Finance has lost an estimated $8.5 million (€7.3 million) after an attacker managed to gather enough voting power to take control of part of the lending vaults. The attack mainly hit the Meta Vaults, after which Term permanently closed the product and blocked new deposits.

How the Attack Worked

According to blockchain data, the attacker withdrew about 2,843 ether and 1.68 million USDC. Together, that was worth about 68% of the assets in the vaults. At the time of the attack, ether was worth about $2,454.69 (€2,100), which put the ether haul alone at around $6.9 million (€5.9 million).

Notably, according to on-chain monitoring service Defimon, the attacker cheaply bought a majority of the project’s scarce governance token. That token gave voting rights over the protocol’s management. That voting power was then reportedly used to push through proposals that granted access to the vaults. Term has not yet confirmed exactly how the majority was obtained or which governance functions were used.

Impact on Term

Term said in a Monday post that the broader lending and borrowing markets were not affected, based on what its own investigation shows so far. The company is working with outside security teams to recover assets and wants to see whether any remaining losses can be covered.

The vaults were built on Yearn V3 infrastructure, software that automatically moves deposits between lending markets to look for the best yield. Yearn said the attack centered on a modified governance layer around that technology and not on standard Yearn vaults. That makes this case mainly an example of how, in DeFi, voting power itself can become an attack vector when governance tokens are thinly spread and rarely used.

For incidents like this, governance is often just as important as code. In a broader analysis of crypto hacks in 2026, it was already becoming clear that attacks are increasingly about governance and key management rather than just smart contracts.

Earlier Problems at Term

The attack did not come out of nowhere. In April 2025, an oracle bug already caused about 918 ETH in unintended liquidations at Term. The protocol was able to recover most of the funds at the time, reimbursed affected users, and promised more transparency around governance and extra checks on major changes.

For European crypto followers, this matters because governance tokens in DeFi do not just give decision-making power, they can also be a weak spot if the distribution is uneven. In the Ethereum world, several governance-related losses have been reported over the past few years, showing that not only code, but also human and economic choices play a role in this kind of incident.


Disclaimer: This content is for informational purposes only and does not constitute financial, investment, legal, or tax advice. The information provided may be incomplete, inaccurate, or outdated and should not be relied upon as such. Nothing on this website should be considered a recommendation to buy, sell, or hold any cryptocurrency. Investing in crypto-assets involves risk of loss.