Term Finance, an Ethereum-based lending protocol, has fallen victim to a governance attack that drained approximately 2,843 ETH (worth around $6.9 million) and 1.68 million USDC stablecoins from its treasury. The combined value of the stolen assets is estimated at $8.5 million, representing roughly 68% of the platform's total treasury holdings. The attacker reportedly acquired majority voting power over the protocol's governance token at a low cost, subsequently submitting and passing a malicious governance proposal to seize control of the lending vaults.
On-chain monitoring service Defimon noted that the attacker purchased the platform's thinly-circulated governance tokens at a minimal price to gain operational decision-making authority. They then leveraged this voting power to approve the harmful proposal and assume control of the lending treasury. As of now, Term Finance has not confirmed the specific method by which the attacker obtained majority control, nor the exact governance functions exploited in the process.
On-chain data reveals that Term Finance's Meta Vaults product held roughly $12.45 million in assets prior to the attack, with nearly $8.8 million in Ethereum deposits almost entirely drained. According to a statement released by the Term Finance team on Monday, the protocol's other direct lending and borrowing markets remain unaffected by the incident.
In response to the breach, Term Finance has permanently shut down the affected vault product, halted new deposits, and revoked the governance permissions that allowed modifications to vault settings. The team stated that they are collaborating with external security firms to recover the stolen assets and will explore options to cover the remaining losses for affected users.
The compromised vault was built on Yearn V3 infrastructure, a technology widely used to automatically allocate deposits across various lending markets to maximize yields. Yearn responded to the incident by clarifying that the vulnerability stemmed from the custom governance layer added by Term Finance on top of their technology, and that standard Yearn vault products remain unaffected.
It is worth noting that this is not the first security incident for Term Finance. In April 2025, an oracle error triggered the unexpected liquidation of approximately 918 ETH. The protocol subsequently recovered most of the funds and compensated affected users, while pledging to enhance governance transparency and external verification for critical changes. Now, over a year later, the governance mechanism itself has once again proven to be the weak link—where the value of assets controlled through voting rights far exceeds the cost of acquiring those voting rights in the first place.

