Term Finance hit by governance exploit, $8.5M siphoned from Ethereum vaults
AI Market Summary
Term Finance's reported ~$8.5M governance exploit drained ETH, USDC, and DAI from Ethereum-based vaults, wiping ~68% of vault liquidity and compounding reputational damage after a prior oracle-loss incident. While Yearn stated standard V3 vault infrastructure was not affected, the event underscores persistent governance-layer risk in DeFi wrappers and may tighten near-term risk appetite for Ethereum lending/vault strategies and associated liquidity.
Impact level
● Medium
Affected assets
ETH/USDT+2.06%
AI Insight · ETH/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Term Finance suffered an estimated $8.5 million loss after attackers exploited the protocol's bespoke governance controls to pull funds from its vaults, draining Ether, USDC and DAI.
Term Labs said on X that the incident involved a governance exploit affecting Term vaults and that an internal investigation is underway. The team has not confirmed the final loss figure or specified which Strategy Vaults saw unauthorized withdrawals.
Security firm PeckShield estimated the attacker withdrew 2,843 ETH (about $6.9 million) along with roughly 1.68 million USDC, later swapping the USDC for about 1.68 million DAI. CertiK, reviewing on-chain activity separately, put the total impact at close to $8.5 million. PeckShield said the funds were traced to an address labeled "e vlojiz" that had received 2 ETH, with activity tied to Tornado Cash.
Term's Strategy Vaults use the ERC-4626 standard and are built on infrastructure based on Yearn V3 architecture, but the exploit targeted a customized governance wrapper around Term's vaults rather than Yearn's standard components. Yearn said on X that vaults operating under its standard setup are not affected by this attack path.
Term splits responsibilities across multiple roles: a manager runs auctions, while a governor controls risk parameters, emergency functions and broader protocol settings. Liquidity providers participate as DAO members and can veto governance transactions during a seven-day timelock. Term has not explained which role was compromised or why the timelock and depositor-veto safeguards failed.
Before the incident, Term's vault product held about $12.45 million across supported networks, according to DefiLlama data, including roughly $8.8 million in Ethereum-based vaults. The reported exploit would amount to nearly 68% of the vault product's total value locked across all networks.
The governance breach adds to pressure on the lending protocol after a separate $1.6 million loss in April 2025, when a misconfigured oracle triggered faulty liquidations. Term said it recovered more than $1 million and committed treasury funds to cover the remainder.
Governance-layer attacks remain a recurring DeFi risk, often involving manipulation of voting mechanisms or the capture of privileged administrative access. Term's probe is expected to focus on how the attacker obtained governance access and bypassed protections designed to safeguard depositors.