Term Finance Loses $8.5 Million in Governance Attack on Ethereum Vaults
Ethereum lending platform Term Finance has lost an estimated $8.5 million after an attacker seemingly acquired enough governance voting power to take control of some of its lending vaults, Co
A
AnonymousCryptoCompass newsroom
August 24, 2026
2 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for defi coverage.
Ethereum lending platform Term Finance has lost an estimated $8.5 million after an attacker seemingly acquired enough governance voting power to take control of some of its lending vaults, CoinDesk reported.
How the exploit unfolded
The attacker removed roughly 2,843 ether, worth about $6.9 million at the time, and 1.68 million USDC, draining around 68% of the assets held in Term’s Meta Vaults. The vaults held about $12.45 million before the attack, according to DefiLlama data, and nearly all of the ether deposited in the product was taken. The Meta Vaults sat on top of Term’s broader lending platform, which the company said was not affected by the incident.
A governance weak point
The unusual element is how access was gained. Onchain monitoring service Defimon said the attacker cheaply acquired a majority of the project’s sparsely held governance token, then allegedly used that voting power to pass proposals giving it control of the vaults. Term has not confirmed how majority control was obtained or exactly which governance functions were used. The incident sits in a grey area: while the transactions were valid under the protocol’s code, authorities could still treat the conduct as an exploit or misappropriation rather than ordinary governance.
Term’s response and outlook
Term has permanently shut the product, blocked new deposits and removed the governance permissions that allowed changes to the vaults. The team said its broader borrowing and lending markets were unaffected and that it is working with outside security firms on recovering assets, and will explore ways to cover any remaining losses.
Yearn, whose V3 infrastructure underpinned the vaults, said the exploit involved a custom governance layer added around its technology and did not apply to standard Yearn vaults. The episode also follows an April 2025 oracle error that triggered roughly 918 ETH of unintended liquidations, which Term later largely recovered after reimbursing affected users. A little over a year on, governance itself has become the weak point, where assets controlled by a vote can be worth far more than the tokens needed to win that vote.
Two applications for digital trading now allow users to purchase memecoins with credit card, a minimal level of knowledge about cryptocurrency, and no additional forms for identification veri
BitcoinWorld AUD/NZD Climbs to July 8 High as Australian GDP Beats, RBNZ Holds Steady The Australian Dollar (AUD) surged to its highest level against the New Zealand Dollar (NZD) since July 8
BitcoinWorld RBNZ Cuts Official Cash Rate to 2.75% as Expected, Signals Cautious Path Ahead The Reserve Bank of New Zealand (RBNZ) lowered its Official Cash Rate (OCR) by 25 basis points to 2