Term Finance Governance Exploit Drains $8.5 Million From Ethereum Vaults
0
0

Summary
- Term Finance lost approximately $8.5 million as attackers exploited custom governance controls and withdrew Ether, USDC, and DAI from vaults.
- Yearn confirmed standard vaults remained secure, while Term has not explained how its timelock and depositor veto protections ultimately failed.
- The exploit erased nearly 68 percent of vault liquidity, creating added pressure following Term Finance’s separate $1.6 million oracle loss.
Ethereum-based lending protocol Term Finance lost approximately $8.5 million through an exploit targeting its custom vault governance system. According to Term Labs on X, the governance exploit affected Term vaults and prompted an internal investigation. However, the team neither confirmed the losses nor identified which Strategy Vaults experienced unauthorized withdrawals.
PeckShield estimated that the attacker withdrew 2,843 ETH, worth roughly $6.9 million, alongside 1.68 million USDC. According to PeckShield on X, the attacker exchanged the withdrawn USDC for approximately 1.68 million DAI.
Meanwhile, CertiK estimated the overall loss at nearly $8.5 million following its separate assessment of blockchain transactions. PeckShield traced the assets to e vlojiz address that initially received two ETH olv Tornado Cash.
Also Read: Cysic (CYS) Price Prediction 2026–2030: Can CYS Hit $3?
Custom Governance System Becomes the Main Attack Route
Term’s Strategy Vaults follow the ERC-4626 standard and operate through infrastructure developed using Yearn V3 architecture. However, the attacker targeted a customized governance wrapper surrounding Term’s vaults rather than exploiting Yearn’s standard infrastructure. According to Yearn on X, this attack method cannot affect vaults operating under its standard arrangements.
Term separates operational authority from depositor oversight through several roles carrying responsibilities. A manager handles auctions, while a governor controls risk parameters, emergency functions, and broader protocol settings.
Additionally, liquidity providers participate as DAO members and may veto governance transactions during a seven-day timelock. Nevertheless, Term has not explained which role the attacker compromised or why those protections failed.
Before the exploit, Term’s vault product held approximately $12.45 million across supported networks, based on DefiLlama data. Around $8.8 million of that total operated through vaults deployed on the Ethereum blockchain. Consequently, the reported loss represented nearly 68 percent of the vault product’s total value locked across all networks.
Previous Loss Adds Pressure on Term Finance
Term experienced a separate $1.6 million loss during April 2025 when an incorrectly configured oracle triggered faulty liquidations. The protocol recovered more than $1 million and pledged treasury resources to cover the remaining amount.
Governance attacks remain a persistent decentralized finance risk because attackers can manipulate voting mechanisms or obtain privileged administrative controls. Term’s investigation must establish how the attacker obtained governance access and bypassed protections designed for depositors.
Also Read: Michael Saylor Reveals Bitcoin’s True Purpose as Strategy Builds Credit Engine
The post Term Finance Governance Exploit Drains $8.5 Million From Ethereum Vaults appeared first on 36Crypto.
0
0
Securely connect the portfolio you’re using to start.







