Ethereum lending platform Term Finance has lost an estimated $8.5 million after an attacker acquired enough governance voting power to take control of its Meta Vaults product, according to blockchain data and the project's post-mortem statement.
Market Context
The exploit represents a growing category of DeFi attacks that target governance mechanisms rather than smart contract code directly. Term Finance's Meta Vaults held approximately $12.45 million before the attack, data from DefiLlama shows. The breach drained roughly 68% of vault assets in a single incident, though Term emphasized its broader lending markets remained unaffected.
Analysis
The attacker apparently cheaply acquired a majority of Term's governance token, which carries sparse participation among holders. With that voting power secured, the malicious actor passed proposals giving it direct control over the vaults before draining approximately 2,843 ether and 1.68 million USDC. On-chain monitoring service Defimon flagged this pattern as emblematic of a broader vulnerability: when assets controlled by governance votes are worth far more than the tokens required to win those votes, protocols become ripe targets.
Term has not confirmed exactly how the attacker obtained majority control or which specific governance functions were exploited. The project has since permanently closed the vault product, blocked new deposits and removed the governance permissions that enabled vault modifications. Yearn, whose V3 infrastructure underpins Meta Vaults, clarified the exploit involved Term's custom governance layer rather than standard Yearn vaults.
The attack carries particular irony given Term's recent history. An oracle error in April 2025 triggered roughly 918 ETH of unintended liquidations at the protocol. Following that incident, Term pledged greater governance transparency and outside validation for critical changes—promises now complicated by governance itself becoming the exploit vector just over a year later.
Key Numbers
- $8.5 million total loss estimate from the Meta Vaults exploit
- 2,843 ether drained, worth approximately $6.9 million at the time of attack
- 1.68 million USDC removed from vaults
- 68% of vault assets drained in a single incident
- $12.45 million held in Term's Meta Vaults before attack (DefiLlama data)
What to Watch
Term Finance is working with external security teams on asset recovery and exploring ways to cover remaining losses for affected users. The incident will likely reignite debates around governance token distribution and quorum requirements across DeFi protocols using vote-based control mechanisms. Traders should monitor whether the broader Yearn ecosystem sees any spillover concern, given Term's use of V3 infrastructure. For DeFi participants, the exploit underscores risks in products with low voter participation rates—a pattern that can make protocols vulnerable to relatively inexpensive takeover attempts.