Ethereum lending protocol Term Finance lost approximately $8.5 million on August 23 after an attacker acquired enough governance voting power to take control of its strategy vaults and approve transfers to their own wallet.
The attacker removed roughly 2,843 ETH, worth about $6.9 million at the time, and 1.68 million USDC, subsequently swapped for a similar amount of DAI, according to blockchain security firms PeckShield and CertiK. Both traced the proceeds to a single address beginning 0xD5183.
The losses represent about 68% of the $12.45 million held in Term’s vault product before the incident, according to DefiLlama data, and wiped out nearly all of the roughly $8.8 million in ether deposited there.
No smart contract was broken. PeckShield and CertiK independently classified the incident as a governance exploit rather than a code exploit.
Two ether bought the votes
The economics are what distinguish this attack from most DeFi losses.
On-chain data cited by PeckShield indicates the attacker bootstrapped the operation with 2 ETH withdrawn from Tornado Cash, the sanctioned Ethereum mixer used to sever the link between an exchange withdrawal and subsequent on-chain activity. From that seed, the attacker began accumulating Term’s governance token on the open market.
Onchain monitoring service Defimon, which first flagged the incident, said the attacker cheaply acquired a majority of the sparsely held governance token, which conferred voting rights over how the protocol operates. Because the token had a low float and thin holder participation, assembling a controlling stake required little capital.
PeckShield reported the attacker built enough voting power to control four USDC strategy vaults and roughly 91% of the Ethereum Meta Vault. Once the proposals passed, the vaults executed them as designed and moved the funds.
Term has not confirmed how voting control was obtained or which specific governance functions were used, and no technical postmortem has been published.
The safeguards that existed
Term’s vaults were not undefended, which makes the outcome more instructive.
The vaults are ERC-4626 tokenised contracts built on Yearn V3 infrastructure, splitting capital between Term’s fixed-rate lending markets and variable-rate lending protocols elsewhere. Governance separated operational control from depositor oversight: a “manager” role handled auction operations while a “governor” role oversaw risk parameters, protocol configuration and emergency functions.
Vault liquidity providers participated as DAO members and could vote to veto queued governance transactions during a seven-day timelock. According to Term’s documentation, a successful LP veto invalidates a transaction before execution.
Reports indicate the attack routed around both the timelock and the veto through Term’s custom governance logic. Yearn addressed the incident directly, stating the exploit involved a custom governance wrapper Term built around the vaults rather than anything inherent to standard Yearn architecture, and that funds in standard Yearn vaults were unaffected.
Term Labs has permanently closed the vault product, blocked new deposits and removed the governance permissions that allowed changes to the vaults, while keeping withdrawals open. It said its broader lending and borrowing markets were not affected based on investigation so far, and that it is working with outside security teams on recovery and will explore ways to cover remaining losses.
This is Term’s second incident. In May 2025 the protocol lost approximately $1.5 million to an oracle decimal mismatch during a routine upgrade, a non-malicious internal error, and those funds were eventually returned.
A pattern with worsening economics
Governance attacks are not new, but the cost-to-payout ratio here is unusual.
Beanstalk Farms lost $182 million in 2022 when an attacker used a flash loan to acquire majority voting power almost instantly and passed a proposal moving funds to their own account. In July 2026, an attacker spent roughly $4.4 million acquiring BONK tokens to pass a malicious proposal that drained about $20 million from the BONK DAO treasury, a roughly fourfold return. Only seven addresses voted.
Term’s attacker turned 2 ETH into $8.5 million.
The underlying condition is the same across all three: when the cost of acquiring governance control falls below the value of the assets that governance controls, the voting mechanism becomes the cheapest available attack surface. Low float and low participation are what collapse that ratio.
Term’s loss pushed August DeFi losses past $27 million across 18 incidents, against cumulative 2026 losses above $1.1 billion across 182 incidents. Blockaid’s half-year report attributed roughly $332 million of that to Ethereum, the largest share of any chain.
What depositors can check
The practical lesson is that an audit certifies code, not turnout.
Every contract involved here functioned exactly as written. The proposals were valid, the votes were legitimate, and the transfers executed correctly. What failed was the assumption that anyone would be watching the governance queue, or that acquiring a majority would be prohibitively expensive.
Two questions are answerable in a few minutes from any protocol’s governance documentation: who is permitted to vote and how voting weight is distributed, and how long a passed proposal takes to execute. A timelock only protects if it is installed and set long enough for someone to notice.
Term Labs has not released a full postmortem detailing how the safeguards were bypassed, and the final loss figure remains an estimate from security firms rather than a confirmed total. Both are likely to arrive in the coming days.
Disclaimer: This article is for informational purposes only and does not constitute financial advice. Cryptocurrency investments carry significant risk. Always conduct your own research before making any investment decisions.



















