# Term Finance loses $8.5M in vault governance attack

> Term Finance lost about $8.5M after an attacker bought voting power over its Meta Vaults, drained ether and stablecoins, and forced a permanent vault shutdown.

- **Source:** https://ptycoin.com/en/posts/2026-08-25-term-finance-85m-governance-exploit/
- **Published:** 2026-08-25
- **Category:** News
- **Author:** Mateo
- **Tags:** security, defi, ethereum, stablecoins, self-custody
- **Also published in:** [Español](https://ptycoin.com/es/posts/2026-08-25-term-finance-85m-governance-exploit/)

---


**Term Finance**, the Ethereum fixed-rate lending protocol built by **Term Labs**, lost an estimated **$8.5 million** on **23 August 2026** after an attacker gained governance control of its strategy vaults and withdrew ether and stablecoins, according to blockchain security firms [PeckShield](https://x.com/PeckShieldAlert/status/2091452165932175659) and CertiK.

## What happened

In a [Sunday post on X](https://x.com/term_labs/status/2091428394130886740), Term Labs said it was "aware of a governance exploit impacting Term vaults" and would share more after investigating. Later the same day the team [posted an update](https://x.com/term_labs/status/2091667425129304215): all **Term Meta Vaults** were shut down, DAO governance roles tied to those vaults were revoked, the shutdown is irreversible and blocks new deposits, and withdrawals stay open. Based on its investigation so far, Term said the underlying protocol and its direct borrowing and lending markets were not affected. It is coordinating with outside security teams on remediation and recovery, and said it would explore paths to address any remaining shortfall.

Independent monitors put numbers on the drain:

- [PeckShield](https://x.com/PeckShieldAlert/status/2091452165932175659) reported about **2,843 ETH** (roughly **$6.87 million** at the time) and **1.68 million USDC**, with the USDC already swapped for about **1.68 million DAI**.
- CertiK separately estimated total losses near **$8.5 million**, matching PeckShield’s combined figure.
- [DefiLlama](https://defillama.com/) data cited across same-day coverage showed the vault product holding about **$12.45 million** beforehand, so the reported loss is roughly **two-thirds** of that pool (and nearly all of the ether deposited in it).

PeckShield also said the exploiter’s wallet was originally funded with **2 ETH** from **Tornado Cash**. On 25 August the same firm [flagged](https://x.com/PeckShieldAlert/status/2092047363162673357) that the address labeled as the Term Labs exploiter had deposited **300 ETH** (about **$741,000**) back into Tornado Cash. Treat mixers as obfuscation signals, not proof of identity.

## How the attack worked

This was a **governance takeover**, not a classic smart-contract bug that drains funds through a reentrancy path or broken math. Onchain monitor **Defimon**, cited by [CoinCentral](https://coincentral.com/8-5m-term-finance-hack-exposes-a-weak-point-in-defi-governance/) and [Crypto Briefing](https://cryptobriefing.com/term-labs-governance-exploit-vaults/), said the attacker cheaply acquired a majority of a **sparsely held** vault-governance token, then passed proposals that seized control of Term’s strategy vaults.

Crypto Briefing reported the attacker reached **100%** voting control on four of five USDC strategy vaults and about **91%** on the Ethereum Meta Vault, then directed funds to a single address beginning `0xD5183`. Term Labs has not yet published a full technical post-mortem confirming that path, so keep those vote-share figures attributed to reporters and monitors until the team’s own write-up lands.

Coverage also says the vaults sat on **Yearn V3** infrastructure with a **custom governance wrapper** built by Term. Yearn said publicly that the exploit involved Term’s custom layer rather than standard Yearn vault deployments (as summarized by CoinCentral). That distinction matters for anyone who deposits into Yearn-branded products elsewhere: same underlying vault technology does not automatically inherit Term’s wrapper permissions.

Term’s own design docs, per same-day analysis, described safeguards including a multi-day delay and liquidity-provider veto on governance changes. Those controls only work if someone with veto power is watching the queue and uses it in time. Term has not confirmed which permission the attacker actually exercised or why the delay and veto failed in practice. Until a post-mortem says otherwise, treat “we had a timelock” as incomplete protection, not a cleared alibi.

## What depositors should check next

Readers who chase fixed-rate or vault yield on Ethereum (including through Bitso on-ramps, self-custody wallets, or regional aggregators across LatAm) meet the same product pattern Term sold: deposit into a strategy vault, trust governance to manage the strategy, and treat the UI balance as yours. A governance token that is thinly distributed turns that trust into a buyable control surface. You can hold the keys to your own wallet and still lose the portion you parked behind someone else’s voting rules.

That is different from the [Sandbox SAND bridge incident](/en/posts/2026-08-23-sandbox-sand-bridge-exploit-base-bnb/) two days earlier, which was a cross-chain mint on isolated networks. Term’s failure mode is political: enough votes, enough silence from veto holders, and the vault follows the attacker’s proposal. Audits catch many code bugs; they do not tell you who holds enough tokens to pass a malicious vote, or whether anyone is watching the queue on a Sunday morning.

Practical filters while recovery details are still open:

1. If you deposited in **Term Meta Vaults**, follow [Term Labs’ official channel](https://x.com/term_labs) only; the team warned about impersonators and said withdrawals remain open.
2. Revoke stale token approvals for contracts you no longer use (wallet settings or a reputable revoke tool), especially after any protocol you interact with discloses a governance incident.
3. Separate **core lending markets** from **strategy vaults** in your mental model. Term says the former were unaffected; the latter are permanently closed to new deposits.
4. Prefer protocols where vault admin powers are narrowly scoped, time-delayed, and held by parties with a real incentive to veto hostile proposals. Verify those claims against the live governance contracts rather than the marketing site.

This is incident reporting, not a recommendation to buy, sell, or hold any token.

## Takeaway

On 23 August 2026, Term Finance’s Meta Vaults lost about **$8.5 million** after an attacker bought voting power over a thinly held governance surface, drained roughly **2,843 ETH** and **1.68 million** in stablecoins, and forced Term Labs to shut the vault product for good while keeping withdrawals open. The core borrowing markets, the team says, stayed intact.

The lesson travels farther than one protocol: when yield sits behind a governance token few people hold and fewer people watch, the attack does not need to break the code. It only needs to win the vote. Wait for Term’s post-mortem and any recovery plan before treating the episode as closed.

---

## Keep reading

- [How do you buy and cash out USDT with Pix in Brazil? Deposit BRL at a local exchange, buy Tether, withdraw on-chain, then reverse the path to send reais back to your bank](https://ptycoin.com/en/posts/2026-08-25-buy-cash-out-usdt-pix-brazil/index.md): Buy USDT with Pix in minutes at a Brazilian exchange, withdraw to self-custody, then sell and Pix the reais home. Network choice and the R$35k DeCripto line matter.
- [How to practice a seed phrase restore before you need it](https://ptycoin.com/en/posts/2026-08-18-practice-seed-phrase-restore/index.md): A written seed phrase is only a backup after you prove it restores the same wallet. Practice the restore on a spare or wiped device before real funds depend on it.
- [How to spot phishing and fake wallet apps before you sign](https://ptycoin.com/en/posts/2026-08-11-spot-phishing-fake-wallet-apps/index.md): Fake wallet apps, lookalike sites, and urgent “support” chats steal seeds and signatures. Use this checklist to verify downloads, URLs, and WalletConnect sessions before you sign.

---

Source: PTYcoin — https://ptycoin.com/en/posts/2026-08-25-term-finance-85m-governance-exploit/. Free to read and cite with attribution to ptycoin.com. AI-usage terms: https://ptycoin.com/en/ai-usage/
