×

$8.5M Drained From Term Finance in Ethereum Governance Takeover

$8.5M Drained From Term Finance in Ethereum Governance Takeover

  • The $8.5 million loss at Term Finance highlights a serious DeFi governance risk: when voting tokens are thinly traded, an attacker can potentially purchase enough influence to control assets worth much more than the cost of obtaining that voting power.
  • Ethereum lending platform Term Finance has reportedly lost around $8.5 million after an attacker appears to have accumulated enough governance tokens to seize control of some lending vaults.
  • Blockchain data indicates that roughly 2,843 ETH, valued at about $6.9 million at the time, and 1.68 million USDC were withdrawn. The incident drained approximately 68% of the assets held across Term’s vaults.
  • According to DefiLlama, Term’s Meta Vaults contained around $12.45 million before the attack. Nearly the entire ETH balance, worth approximately $8.8 million, was taken.

Governance Power Allegedly Enabled the Attack

  • The most unusual element of the incident is the apparent way the attacker gained control.
  • Onchain monitoring firm Defimon said the attacker appears to have bought a majority of Term’s lightly traded governance token at relatively little cost. The acquired voting power was then allegedly used to approve proposals that gave the attacker control of the vaults.
  • The incident illustrates the blurred line between decentralized governance and protocol exploitation. While acquiring governance tokens through the open market can be legitimate, using that voting power to gain control over user deposits could potentially be viewed as an exploit or misappropriation.
  • Even if the attacker’s actions complied technically with the protocol’s smart contracts, that would not necessarily prevent authorities from examining the transactions or treating the conduct as unlawful.
  • Term has not disclosed how the attacker obtained majority voting control or which specific governance mechanisms were involved. The platform has permanently shut down the affected product, halted new deposits and revoked the governance permissions that allowed vault changes.

Core Term Markets Remain Unaffected

  • Term said its investigation has so far found no impact on the wider protocol or its direct borrowing and lending markets.
  • The team is working with external security firms to trace and recover the missing funds. It also plans to explore options for covering any losses that cannot be recovered.
  • The affected vaults used Yearn V3 infrastructure, which automatically reallocates deposits between lending markets to seek better returns. Yearn said the incident involved a custom governance layer built around its technology and did not affect standard Yearn vaults.

A Second Major Incident for Term

  • The attack comes after a separate incident in April 2025, when an oracle error caused roughly 918 ETH in unintended liquidations at Term.
  • The protocol later recovered most of the funds, reimbursed affected users and promised greater transparency around governance as well as independent validation for critical changes.
  • The latest incident shows that governance can itself become a major attack surface, particularly when a protocol controls assets worth dramatically more than the market value of the tokens needed to obtain voting control.

Share this content:

Copyright © 2025 CoinsNewz