Term Finance lost an estimated $8.5 million after an attacker exploited its governance system and drained most of its Ethereum vault liquidity.
Catenaa, Saturday, August 29, 2026-Ethereum-based lending protocol Term Finance lost an estimated $8.5 million Sunday after an attacker exploited its governance system and withdrew ether and stablecoins from strategy vaults.
Blockchain security firms PeckShield and CertiK independently estimated the losses at about $8.5 million.
Term Labs acknowledged a governance exploit affecting its vaults and said it was investigating the incident.
The protocol had not confirmed the final loss figure or identified every affected vault when the attack was disclosed.
PeckShield estimated that the attacker withdrew about 2,843 ETH, valued near $6.9 million, and 1.68 million USDC.
The USDC was later exchanged for about 1.68 million DAI.
The security firm traced the stolen assets to a single Ethereum address.
That address had earlier received 2 ETH through Tornado Cash, a decentralized cryptocurrency mixing protocol.
The attack appears to have targeted Term Finance’s governance layer rather than the underlying Yearn V3 vault technology.
Term’s Strategy Vaults use the ERC-4626 token standard and are built on Yearn V3 infrastructure.
Yearn said its standard vault architecture was not affected.
The vulnerability instead involved a custom governance wrapper added by Term Finance around the vault system.
That distinction matters because Term’s governance design included several layers intended to prevent unauthorized or dangerous changes.
A manager role controlled routine auction operations.
A separate governor role had broader authority over risk settings, protocol configuration and emergency functions.
Liquidity providers could also participate in the protocol’s decentralized autonomous organization.
They were allowed to veto queued governance transactions during a seven-day timelock.
A successful veto was designed to cancel a proposed transaction before execution.
Term has not yet explained how those protections failed.
It has also not disclosed which governance privilege the attacker obtained or how the malicious transactions passed through the timelock.
The governor role carries substantial authority.
According to Term Finance documentation, governors can modify the protocol controller, change price oracles and alter risk limits.
They can also pause deposits and strategy activity.
Those permissions are necessary for protocol management, but they can become dangerous if an attacker gains control.
Governance security therefore depends on more than whether individual smart contracts contain coding errors.
Protocols must also secure the systems that determine who can change those contracts and under what conditions.
The Term Finance incident appears to demonstrate that risk.
The vault contracts themselves may have operated as designed while governance permissions allowed the attacker to move assets.
The size of the loss is particularly damaging relative to Term Finance’s vault business.
The strategy vaults held about $12.45 million across supported networks before the attack, according to DefiLlama data cited by The Block.
About $8.8 million of that amount was on Ethereum.
An $8.5 million loss would represent about 68% of the product’s total value locked.
It would also account for nearly all the Ethereum liquidity held in the vaults before the incident.
Term Finance operates additional lending products outside the affected vault system.
The protocol had about $25.8 million in total value locked before the attack and roughly $3.79 million in active loans.
The incident therefore did not drain the entire Term Finance protocol.
However, it removed most of the capital held in one of its major product categories.
Term Finance specializes in fixed-rate cryptocurrency lending.
Many decentralized lending protocols use variable interest rates that change according to market supply and borrowing demand.
Term instead uses auction-based mechanisms intended to let users lock in borrowing and lending rates for defined periods.
Its strategy vaults extend that model by allocating capital between Term’s fixed-rate lending markets and variable-rate protocols.
That allows depositors to place funds into managed vaults while strategies move capital across lending opportunities.
The structure can improve capital efficiency.
It also introduces additional layers of smart contracts, governance and risk management.
Each layer can create another potential attack surface.
The latest exploit is not Term Finance’s first major operational problem.
The protocol suffered a separate $1.6 million loss in April 2025 after an incorrectly configured price oracle triggered faulty liquidations in its tETH market.
Term Finance recovered more than $1 million from that incident.
The protocol said its treasury would cover the remainder.
At the time, Term stressed that the event was not a smart-contract exploit and that attackers had not directly targeted user funds.
The latest event is different.
Security firms are describing it as a governance exploit, and assets were transferred from vaults to an attacker-controlled address.
That makes the incident more comparable with earlier attacks in which governance authority itself became the entry point.
DeFi protocols have faced governance attacks for years.
Some attacks use flash loans to temporarily acquire enough voting power to approve malicious proposals.
Others rely on cheaply purchased governance tokens or compromised administrative privileges.
In 2022, Beanstalk lost about $182 million after an attacker used a flash loan to gain enough governance power to approve transactions transferring protocol assets.
More recently, Moonwell faced a governance attack in March after an attacker spent about $1,800 on tokens to support a proposal that placed more than $1 million at risk.
Term’s incident appears structurally different because the protocol already used a seven-day timelock and liquidity-provider veto system.
Those controls were specifically intended to give participants time to detect and block dangerous governance actions.
How the attacker bypassed them will be central to the investigation.
The attack adds to evidence that DeFi security cannot be measured by smart-contract audits alone.
Protocols increasingly rely on governance wrappers, upgrade mechanisms, oracle systems and administrative roles.
Any one of those layers can create a path to user assets.
Timelocks can reduce that risk, but only if malicious transactions cannot bypass them.
Community veto systems can also work only when users can detect a dangerous proposal before execution.
For Term Finance, the immediate priorities are determining how the attacker obtained governance control and whether additional funds remain exposed.
The protocol will also face questions over compensation for affected depositors.
The larger issue extends beyond one lending platform.
As DeFi systems become more sophisticated, the mechanisms designed to manage them can become as important to security as the financial contracts themselves.
Term Finance built safeguards to separate operational authority from depositor oversight.
The attacker appears to have found a way around them.
That failure turned governance from a protective layer into the mechanism through which most of the vault liquidity was lost.
