Term Finance, the Ethereum fixed-rate lending protocol built by Term Labs, lost an estimated $8.5 million on 23 August 2026 after an attacker gained governance control of its strategy vaults and withdrew ether and stablecoins, according to blockchain security firms PeckShield and CertiK.
What happened
In a Sunday post on X, Term Labs said it was “aware of a governance exploit impacting Term vaults” and would share more after investigating. Later the same day the team posted an update: all Term Meta Vaults were shut down, DAO governance roles tied to those vaults were revoked, the shutdown is irreversible and blocks new deposits, and withdrawals stay open. Based on its investigation so far, Term said the underlying protocol and its direct borrowing and lending markets were not affected. It is coordinating with outside security teams on remediation and recovery, and said it would explore paths to address any remaining shortfall.
Independent monitors put numbers on the drain:
- PeckShield reported about 2,843 ETH (roughly $6.87 million at the time) and 1.68 million USDC, with the USDC already swapped for about 1.68 million DAI.
- CertiK separately estimated total losses near $8.5 million, matching PeckShield’s combined figure.
- DefiLlama data cited across same-day coverage showed the vault product holding about $12.45 million beforehand, so the reported loss is roughly two-thirds of that pool (and nearly all of the ether deposited in it).
PeckShield also said the exploiter’s wallet was originally funded with 2 ETH from Tornado Cash. On 25 August the same firm flagged that the address labeled as the Term Labs exploiter had deposited 300 ETH (about $741,000) back into Tornado Cash. Treat mixers as obfuscation signals, not proof of identity.
How the attack worked
This was a governance takeover, not a classic smart-contract bug that drains funds through a reentrancy path or broken math. Onchain monitor Defimon, cited by CoinCentral and Crypto Briefing, said the attacker cheaply acquired a majority of a sparsely held vault-governance token, then passed proposals that seized control of Term’s strategy vaults.
Crypto Briefing reported the attacker reached 100% voting control on four of five USDC strategy vaults and about 91% on the Ethereum Meta Vault, then directed funds to a single address beginning 0xD5183. Term Labs has not yet published a full technical post-mortem confirming that path, so keep those vote-share figures attributed to reporters and monitors until the team’s own write-up lands.
Coverage also says the vaults sat on Yearn V3 infrastructure with a custom governance wrapper built by Term. Yearn said publicly that the exploit involved Term’s custom layer rather than standard Yearn vault deployments (as summarized by CoinCentral). That distinction matters for anyone who deposits into Yearn-branded products elsewhere: same underlying vault technology does not automatically inherit Term’s wrapper permissions.
Term’s own design docs, per same-day analysis, described safeguards including a multi-day delay and liquidity-provider veto on governance changes. Those controls only work if someone with veto power is watching the queue and uses it in time. Term has not confirmed which permission the attacker actually exercised or why the delay and veto failed in practice. Until a post-mortem says otherwise, treat “we had a timelock” as incomplete protection, not a cleared alibi.
What depositors should check next
Readers who chase fixed-rate or vault yield on Ethereum (including through Bitso on-ramps, self-custody wallets, or regional aggregators across LatAm) meet the same product pattern Term sold: deposit into a strategy vault, trust governance to manage the strategy, and treat the UI balance as yours. A governance token that is thinly distributed turns that trust into a buyable control surface. You can hold the keys to your own wallet and still lose the portion you parked behind someone else’s voting rules.
That is different from the Sandbox SAND bridge incident two days earlier, which was a cross-chain mint on isolated networks. Term’s failure mode is political: enough votes, enough silence from veto holders, and the vault follows the attacker’s proposal. Audits catch many code bugs; they do not tell you who holds enough tokens to pass a malicious vote, or whether anyone is watching the queue on a Sunday morning.
Practical filters while recovery details are still open:
- If you deposited in Term Meta Vaults, follow Term Labs’ official channel only; the team warned about impersonators and said withdrawals remain open.
- Revoke stale token approvals for contracts you no longer use (wallet settings or a reputable revoke tool), especially after any protocol you interact with discloses a governance incident.
- Separate core lending markets from strategy vaults in your mental model. Term says the former were unaffected; the latter are permanently closed to new deposits.
- Prefer protocols where vault admin powers are narrowly scoped, time-delayed, and held by parties with a real incentive to veto hostile proposals. Verify those claims against the live governance contracts rather than the marketing site.
This is incident reporting, not a recommendation to buy, sell, or hold any token.
Takeaway
On 23 August 2026, Term Finance’s Meta Vaults lost about $8.5 million after an attacker bought voting power over a thinly held governance surface, drained roughly 2,843 ETH and 1.68 million in stablecoins, and forced Term Labs to shut the vault product for good while keeping withdrawals open. The core borrowing markets, the team says, stayed intact.
The lesson travels farther than one protocol: when yield sits behind a governance token few people hold and fewer people watch, the attack does not need to break the code. It only needs to win the vote. Wait for Term’s post-mortem and any recovery plan before treating the episode as closed.



