DeFi lending protocol Term Finance loses an estimated $8.5 million to governance exploit

DeFiAugust 23, 2026, 4:50PM EDT
UPDATED: August 23, 2026, 4:56PM EDT
DeFi lending protocol Term Finance loses an estimated $8.5 million to governance exploit
Partner offers

Quick Take

  • DeFi lending protocol developer Term Labs confirmed that a governance exploit affected its Term Finance vaults.
  • Blockchain security firms PeckShield and CertiK estimated the loss at about $8.5 million.
  • Term vault proposals face a seven-day delay and can be vetoed by liquidity providers, yet those controls apparently did not stop the exploit.

We'd love your feedback.

Advertisement

Ethereum-based fixed-rate lending market Term Finance's vaults were drained of about $8.5 million on Sunday after an unknown attacker exploited the protocol's governance system to move ether and stablecoins, according to blockchain security firms PeckShield and CertiK.

"We are aware of a governance exploit impacting Term vaults," Term Labs said on X. The team said it would provide more detail after investigating. Term did not confirm the scale of the losses or identify the affected vaults.

PeckShield estimated that the attacker withdrew about 2,843 ETH worth roughly $6.9 million and 1.68 million USDC. The USDC was swapped for about 1.68 million DAI, the firm said on X. PeckShield traced the funds to a single address which had initially received 2 ETH from mixing protocol Tornado Cash. CertiK separately put the loss at roughly $8.5 million.

Governance protections did not prevent exploit

Term's Strategy Vaults are ERC-4626 tokenized vaults built on Yearn V3 infrastructure. The vaults allocate capital between Term's fixed-rate lending markets and variable-rate lending protocols, according to Term's developer documentation.

"While their contracts are built on Yearn's V3 architecture, the exploit occurred via a custom governance wrapper around the vaults and this attack vector is not applicable to standard Yearn vault setups," Yearn wrote on X following the exploit. "Funds deposited to standard Yearn vaults are safe and those vaults are unaffected."

The vaults use a governance structure that separates operational control from depositor oversight. A "manager" role handles auction operations, while a "governor" role oversees risk parameters, protocol configuration and emergency functions. Separately, vault liquidity providers (LPs) participate as DAO members and can vote to veto queued governance transactions during a seven-day timelock. According to Term's governance documentation, a successful LP veto invalidates the transaction before it can be executed.

Governors can change the protocol controller, price oracle and risk limits, as well as pause deposits or strategy activity, the document says. Term has not disclosed which role the attacker used or why the timelock and LP veto did not prevent the exploit transactions.

Exploit drains two-thirds of TVL

Prior to the hack, the total value locked (TVL) in Term's vaults was about $12.45 million, per DefiLlama data, including about $8.8 million on Ethereum. The reported $8.55 million loss equals about 68% of the vault product's TVL across all chains — more than two-thirds of the total — and nearly all of the vaults' Ethereum TVL. 

The vaults make up one part of Term Finance's offerings. Term overall had about $25.8 million in total value locked prior to the hack, per DefiLlama's combined protocol page, and $3.79 million in active loans.

Term Finance previously suffered a separate loss in April 2025, after a misconfigured oracle led to faulty liquidations in its tETH market. The protocol recovered more than $1 million of the $1.6 million loss and said its treasury would cover the remainder, The Block previously reported.

"This was not a hack. No smart contracts were exploited, and user funds were not directly targeted," Term said of the prior incident at the time. 

DeFi protocols have long faced governance attacks powered by flash loans or cheap tokens. In March, an attacker spent about $1,800 on tokens to push a proposal that threatened $1.08 million at Moonwell. Beanstalk lost about $182 million in a flash-loan governance exploit in 2022, as The Block reported at the time.

The Block could not immediately reach Term Labs for comment. 


Disclaimer: The Block is an independent media outlet that delivers news, research, and data. As of November 2023, Foresight Ventures is a majority investor of The Block. Foresight Ventures invests in other companies in the crypto space. Crypto exchange Bitget is an anchor LP for Foresight Ventures. The Block continues to operate independently to deliver objective, impactful, and timely information about the crypto industry. Here are our current financial disclosures.

© 2026 The Block. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.