---
title: "DeFi Lending Protocol Term Finance Loses $8.5 Million After Attacker Gains Governance Control"
type: "News"
locale: "en"
url: "https://longbridge.com/en/news/296735211.md"
description: "Term Finance, an Ethereum-based DeFi lending protocol, lost approximately $8.5 million in digital assets after an attacker exploited its governance system. The attacker accumulated sufficient voting power to approve proposals granting control over affected vaults, draining 2,843 ETH and 1.68 million USDC. Term Labs confirmed the incident and is investigating. Yearn V3 stated that standard vaults are unaffected as the exploit targeted a custom governance wrapper. This incident highlights security risks associated with concentrated voting power in DeFi governance."
datetime: "2026-08-24T04:14:51.000Z"
locales:
  - [zh-CN](https://longbridge.com/zh-CN/news/296735211.md)
  - [en](https://longbridge.com/en/news/296735211.md)
  - [zh-HK](https://longbridge.com/zh-HK/news/296735211.md)
generator: "portal-rs"
---

# DeFi Lending Protocol Term Finance Loses $8.5 Million After Attacker Gains Governance Control

## Term Finance Vaults Drained After Governance Exploit

Term Finance has lost about $8.5 million in digital assets after an attacker gained enough control through its governance system to move funds from affected vaults, turning protocol voting mechanisms into the route for the theft.

The Ethereum-based fixed-rate lending protocol said it was investigating the incident after security firms tracked large transfers from its vaults on 23 August 2026.

## Term Finance Loses 2,843 ETH And 1.68 Million USDC

PeckShield estimated that the attacker withdrew 2,843 ETH worth about $6.87 million, along with 1.68 million USDC.

The stolen USDC was then exchanged for about 1.68 million DAI, according to on-chain data.

CertiK separately estimated the overall loss at roughly $8.5 million.

Term Labs acknowledged the incident in a statement, saying, 

“We are aware of a governance exploit impacting Term vaults,” and said it would provide further information after completing its investigation.

> We are aware of a governance exploit impacting Term vaults. 
> 
> We will share more details once it has been further investigated.
> 
> — Term Labs (@term\_labs) August 23, 2026

The team has not yet confirmed the total loss, identified the affected vaults or explained exactly how the attacker bypassed the protocol's governance protections.

## How Did The Governance Attack Work?

Initial reporting indicates that the attacker accumulated enough voting power to approve proposals that granted control over affected vault assets.

That makes the incident different from a conventional attack that exploits a coding flaw to bypass a contract's intended rules.

Instead, the attacker appears to have used the protocol's own governance process to obtain authorised control.

> ‼️Around $8,5M lost due to an exploit on Term Finance
> 
> Its DAO governance token was cheap and barely held by anyone, so the attacker bought up enough of it to control the votes
> 
> After that he passed his own proposals and took control of the vaults
> 
> Attacker funded both of his… pic.twitter.com/OGzEkO0kLd
> 
> — VAL (@osint\_based) August 23, 2026

Term's Strategy Vaults are ERC-4626 tokenised vaults built on Yearn V3 infrastructure.

They can allocate capital between Term's fixed-rate lending markets and variable-rate lending protocols.

The vaults separate operational and governance responsibilities.

A manager handles auction operations, while a governor oversees areas including risk settings, protocol configuration and emergency functions.

Liquidity providers also have a role in governance, with LPs able to vote against queued transactions during a seven-day timelock.

According to Term's governance documentation, a successful LP veto can invalidate a transaction before it is executed.

Term has not disclosed which governance role was compromised or why those safeguards failed to stop the transactions.

## Yearn Says Standard Vaults Are Not Affected

The incident has also raised questions about whether other vaults using Yearn's infrastructure face the same exposure.

Yearn said Term's affected vaults use a custom governance wrapper around the underlying Yearn V3 architecture.

Yearn wrote on X,

> “While their contracts are built on Yearn's V3 architecture, the exploit occurred via a custom governance wrapper around the vaults and this attack vector is not applicable to standard Yearn vault setups.”

It added that funds deposited into standard Yearn vaults remain safe and that those vaults were not affected.

> We are aware of an exploit of Term Finance's vault contracts. While their contracts are built on Yearn's V3 architecture, the exploit occurred via a custom governance wrapper around the vaults and this attack vector is not applicable to standard Yearn vault setups.
> 
> Funds…
> 
> — yearn (@yearnfi) August 23, 2026

The distinction is important because the attack appears to have centred on Term's additional governance layer rather than the core Yearn V3 vault framework.

## Tornado Cash Funding Adds Another Layer To The Investigation

PeckShield traced the attack funds to a wallet that had received 2 ETH through Tornado Cash, a crypto mixing protocol.

The transaction provided the attacker with the ETH needed to initiate the operation, but the funding trail does not establish who controlled the wallet or identify the person behind the exploit.

The stolen assets were subsequently moved and converted on-chain, leaving investigators to track the funds while Term continues its internal investigation.

## Why Governance Security Matters For DeFi

The attack highlights a security risk that can sit outside traditional smart-contract audits.

A protocol can have audited contracts while still being exposed if an attacker can gain excessive voting power or manipulate the governance process that controls those contracts.

Concentrated voting power, limited participation, weak proposal checks and insufficient delays can therefore become critical attack points.

Blockaid recorded 212 on-chain security incidents and $1.1 billion in losses during the first half of 2026, with Ethereum accounting for about $332 million of those losses.

> H1 2026 saw 212 security incidents and over $1 billion in losses.
> 
> Blockaid Co-Founder and CEO @idobn joined @FINTECHTVglobal's Market Movers at the @NYSE to explain why attackers are shifting beyond smart contracts to target private keys through social engineering. pic.twitter.com/p423wsPxvB
> 
> — Blockaid (@blockaid\_) August 14, 2026

Its findings identified application and protocol logic vulnerabilities as major sources of losses across Ethereum.

For governance-driven protocols, the safeguards extend beyond code reviews.

Voting power distribution, proposal verification, timelocks and effective veto mechanisms can all determine whether a malicious proposal reaches execution.

## Term Finance Has Faced A Previous Loss

The latest incident is not Term Finance's first major security-related setback.

On 26 April 2025, an oracle decimal inconsistency triggered about 918 ETH in unintended liquidations.

The protocol recovered about 556 ETH, leaving a final loss of 362 ETH, worth roughly $650,000 at the time.

Term Finance said affected users would be fully reimbursed following that incident.

> The root cause of the @term\_labs incident is the inconsistent price decimals of tETH in the newly updated tETH price oracle.
> 
> A code review should have discovered this mistake.https://t.co/0vfUoi9uzEpic.twitter.com/C9ckYQzfBf
> 
> — TenArmorAlert (@TenArmorAlert) April 30, 2025

The latest exploit is considerably larger and involves governance control rather than an oracle calculation error, leaving the protocol to determine how the attacker obtained sufficient authority and whether additional funds remain at risk.

Term Labs has said it will publish more information once its investigation is complete.

### Related Stocks

- [ETHE.US](https://longbridge.com/en/quote/ETHE.US.md)
- [CETH.US](https://longbridge.com/en/quote/CETH.US.md)
- [ETHW.US](https://longbridge.com/en/quote/ETHW.US.md)
- [ETHA.US](https://longbridge.com/en/quote/ETHA.US.md)
- [FETH.US](https://longbridge.com/en/quote/FETH.US.md)

## Related News & Research

- [Term Finance loses estimated $8.5M in vault governance exploit](https://longbridge.com/en/news/296733976.md)
- [Mapping the Market: Cryptocurrency ether's technical picture brightens after sharp rebound](https://longbridge.com/en/news/296767860.md)
- [Ledger Ethereum App Version 1.22.2 Fixes Bug That Could Replace Transactions During Clear Signing](https://longbridge.com/en/news/296882199.md)
- [Aligned Launches $ALIGN, the Native Token of Its Full Ethereum Stack](https://longbridge.com/en/news/296619468.md)
- [Bitcoin, Ethereum, XRP, Dogecoin Hold Ground on Low-Volatility Monday](https://longbridge.com/en/news/296821534.md)

---
> **Disclaimer: This article is for reference only and does not constitute any investment advice.**