Term Finance Loses $8.5M in Vault Exploit
Term Finance lost an estimated $8.5 million in a governance exploit targeting its strategy vaults on August 23, according to blockchain security researchers.
Term Labs has irreversibly shut down all Term Meta Vaults and revoked their DAO governance roles. New deposits are permanently blocked while withdrawals remain open. The team said its investigation has so far found no impact to Term’s direct fixed-rate borrowing and lending markets.
Attacker Drains 2,843 ETH and 1.68M USDC
PeckShield tracked roughly 2,843 ETH, worth about $6.87 million at the time, and 1.68 million USDC leaving the affected vaults. The USDC was subsequently exchanged for roughly 1.68 million DAI.
The attacker’s wallet was initially funded with ETH routed through Tornado Cash. CertiK separately estimated the total loss at approximately $8.5 million. The reported loss was equivalent to about 68% of the $12.45 million held in Term’s vault product before the incident. Its Ethereum vaults contained roughly $8.8 million.
Seven-Day Governance Safeguards Fail to Stop Vault Drain
Term’s strategy vaults use Yearn V3 infrastructure and give liquidity providers veto rights over queued governance transactions during a seven-day delay.
On-chain monitor Defimon said the attacker acquired a majority of a thinly held governance token and used malicious proposals to take control of the vaults. Term Labs has not yet confirmed how the attacker obtained that voting power or which governance functions enabled the drain.
A separate on-chain reconstruction found that a malicious proposal remained visible during the veto period without being stopped and then disabled the cooldown during execution. Term has not yet confirmed that sequence.
Yearn said the exploit involved a custom governance wrapper around Term’s vaults and does not affect standard Yearn V3 configurations.
Meta Vault Shutdown Permanently Blocks New Deposits
Term Labs said the Meta Vault shutdown is irreversible. DAO governance permissions have been revoked, preventing new deposits while existing users retain withdrawal access.
The team is working with external security specialists on remediation and asset recovery and said it will explore ways to address any remaining shortfall.
Term previously suffered an oracle error in April 2025 that triggered about 918 ETH in unintended liquidations. By July, Term said all affected users had been reimbursed, and its final absorbed loss had fallen to 164.5 ETH after additional recovery.
Term Labs is still verifying the full scope and cause of the August 23 governance exploit and has not yet published a complete postmortem.