Skip to content

Term Finance Exploit: $951 Governance Stake Drains $8.5M

Term Finance Exploit: $951 Governance Stake Drains $8.5M

Short answer: On August 23, 2026, DeFi lender Term Finance confirmed a governance exploit that drained about $8.5 million, roughly 2,843 ETH and 1.68 million USDC, from its Meta Vaults. The attacker did not break any smart contract: a stake bought for about $951 gave them over 90% of the vote, and they voted to send the vault funds to themselves.

What happened

Term Finance is an Ethereum-based fixed-rate lending protocol developed by Term Labs. Alongside its core lending markets it ran Meta Vaults and strategy vaults, built on Yearn V3 vault infrastructure but controlled by a custom governance layer written by Term Labs. According to blockchain security firms PeckShield and CertiK, an attacker used that governance layer to withdraw roughly 2,843 ETH (about $6.9 million) and 1.68 million USDC, which was then swapped into DAI.

The affected vaults held about $12.45 million before the attack, so the loss was close to 68% of their total value locked (TVL). The attacker's wallet was seeded with 2 ETH that had passed through Tornado Cash, a mixing service used to hide the origin of funds. Term Labs confirmed the incident on Sunday and said a fuller account would follow its investigation.

How the Term Finance governance exploit worked

A governance attack is an exploit in which someone gains enough voting power in a protocol's decision system to approve actions that benefit themselves, such as moving treasury or vault funds. No code bug is required; the rules work exactly as written.

  1. Cheap voting power. On August 17, the attacker reportedly bought 0.4852 tmvETH, a vault share token, for about 0.5 ETH, or roughly $951, and staked it.
  2. A near-empty electorate. Because almost no one else had staked, that single purchase gave the attacker about 90.66% of all votes in the pool, according to reports citing on-chain data.
  3. A proposal to pay themselves. With a supermajority, the attacker submitted and passed a proposal that redirected vault assets to their own address.
  4. Safeguards that nobody used. The vaults had a seven-day timelock and a veto right for liquidity providers. Both existed on paper, but no one vetoed the proposal before it executed.

Yearn Finance stressed that standard Yearn vault code was not at fault; the weakness sat in the additional governance wrapper that Term Labs had added on top.

ItemFigure
Attacker's cost of voting powerabout $951 (0.4852 tmvETH)
Voting share obtainedabout 90.66%
ETH drainedabout 2,843 ETH (~$6.9 million)
Stablecoins drained1.68 million USDC, swapped to DAI
Total lossabout $8.5 million, ~68% of $12.45 million TVL

How Term Labs responded

  • All Term Meta Vaults were irreversibly shut down, and the DAO governance roles tied to them were revoked so that no new deposits can be made.
  • Withdrawals were left open so remaining depositors can exit.
  • Users were advised to revoke token approvals granted to Term's contracts.
  • The team said its core lending and borrowing markets were not affected, and that it is working with external security teams on possible recovery.

Why governance attacks keep happening in DeFi

Governance attacks are rarer than code exploits, but they tend to be cheap for the attacker. The best-known case remains Beanstalk in April 2022, when a flash-loaned voting majority passed a proposal that drained about $182 million. Term Finance shows the same logic at a smaller scale: when voter turnout is low, the price of control is set by the few tokens actually staked, not by the value those votes govern.

A timelock only protects users if someone is watching. Monitoring tools can flag a sudden jump in voting power, yet in this case the stake was bought about a week before the funds moved, and nobody acted on it. According to BeInCrypto, Term was the 18th DeFi incident of August 2026, after 17 earlier cases worth about $18.8 million.

What it means for you

  • Audits are not the whole story. A vault can run audited code and still be controlled by a thin, capturable governance layer. Check who can move funds, and how many votes that takes.
  • Revoke old approvals. If you ever deposited into Term vaults, or any protocol you no longer use, remove the token allowances from your wallet.
  • Treat yield as risk compensation. Smaller vaults with low participation carry governance risk that is rarely priced in.
  • Keep only what you use in DeFi. Balances you are not actively deploying are safer in a wallet you control; our wallet security guide covers the basics.

Key takeaways

  • Term Finance lost about $8.5 million from its Meta Vaults in a governance exploit confirmed on August 23, 2026.
  • A stake worth about $951 gave the attacker roughly 90.66% of the vote.
  • A seven-day timelock and a veto right existed, but no one used them in time.
  • The Yearn V3 vault code was not at fault; Term's custom governance wrapper was.
  • Meta Vaults are permanently closed, withdrawals remain open, and core lending markets were unaffected.

For a broader look at where these risks sit, see our comparison of DeFi and CeFi.

Sources: BeInCrypto via Yahoo Finance, The Cryptonomist, Crowdfund Insider, CoinGabbar

Frequently asked questions

How much was stolen in the Term Finance hack?

About $8.5 million: roughly 2,843 ETH and 1.68 million USDC were taken from Term's Meta Vaults. The theft was confirmed on August 23, 2026.

What is a DeFi governance attack?

It is an exploit in which an attacker acquires enough voting power in a protocol's governance to pass a proposal that benefits them, for example one that transfers pooled funds. It needs no code bug, only cheap or concentrated voting power.

Can Term Finance users still withdraw their funds?

Yes. Term Labs closed the Meta Vaults to new deposits but kept withdrawals open, and said its core lending markets were not affected. Users were also told to revoke token approvals to Term contracts.

← Blog

Read next