ADVERTISEMENT
LIVE DESK·Global markets desk·Last updated 14s ago
ADVERTISEMENT
Novara — A Smarter Way to Access Global Markets
Markets/CryptoArticle

Term Finance loses $8.5M in governance exploit targeting vaults

Attacker drains 2,843 ETH and 1.68M USDC from Term's strategy vaults, representing 68% of pre-attack holdings. Protocol shuts down Meta Vaults while investigating scope of breach.

MW
Marcus Webb · Crypto Desk · 24 Aug 2026 · 04:16 · 1 min read
Share
Term Finance loses $8.5M in governance exploit targeting vaults

Decentralized lending protocol Term Finance reported an estimated $8.5 million loss after an attacker exploited governance control of its strategy vaults on Sunday. Blockchain security firms PeckShield and CertiK independently estimated the total loss at $8.5 million, with PeckShield citing the extraction of 2,843 Ether (ETH) valued at $6.87 million and 1.68 million USDC converted to 1.68 million Dai (DAI).

The reported loss accounted for approximately 68% of the $12.45 million held in Term's vault product prior to the attack, including nearly all of its $8.8 million in Ethereum deposits, according to Defillama data. Term Labs confirmed it had irreversibly shut down all Term Meta Vaults and revoked their DAO governance roles, while maintaining open withdrawal functionality. The company stated its underlying Term protocol and direct borrowing and lending markets remained unaffected but continued verification of the breach's scope.

Bitcoin

BTCUSD
Full profile →
76873.9900▼ 1.11%
As of 24/08/2026, 00:00:00

On-chain monitoring service Defimon attributed the attack to the attacker acquiring a majority of a sparsely held governance token at low cost, enabling passage of proposals that granted control over Term's vaults. Term did not confirm the method of governance acquisition or specify which governance functions were exploited. The vault contracts utilized Yearn V3 infrastructure, though Yearn clarified the attack involved a custom governance wrapper and did not affect standard Yearn vault configurations.

Term is coordinating with external security teams to pursue asset recovery and remediation efforts, and stated it would explore measures to address any remaining shortfall. The incident follows a separate April 2025 oracle error that resulted in 918 ETH in unintended liquidations, which Term partially recovered and reimbursed to affected users. In response to that prior incident, the protocol pledged enhanced governance transparency and third-party validation for critical updates.

This article was produced with AI assistance and edited by a Finance Review Daily journalist.
ADVERTISEMENT
Share this story
MW
Written by
Marcus Webb
Crypto Desk

Marcus reports on digital assets, from spot ETF flows to protocol-level developments in DeFi. He pays particular attention to how institutional adoption is reshaping crypto market structure.

More from Marcus Webb →
ADVERTISEMENT
ADVERTISEMENT