Term Finance loses estimated $8.5M in vault governance exploit
Term permanently closed its Meta Vaults after an attack reportedly removed nearly all of their Ethereum deposits.
Term Finance suffered an estimated $8.5 million loss following an attack that targeted its Meta Vaults governance control. The attacker drained approximately 2,843 Ether (ETH) worth $6.87 million and 1.68 million USDC, which was exchanged for about 1.68 million Dai (DAI). This incident equaled roughly 68% of the $12.45 million initially held in Term's vault product, including nearly all of its $8.8 million in Ethereum deposits.
After the attack, Term Labs permanently closed its Meta Vaults and revoked their DAO governance roles, preventing further deposits while keeping withdrawals open. The underlying Term protocol and its direct borrowing and lending markets remained unaffected, but the company was still assessing the full extent of the breach. The attacker exploited a sparsely held governance token, passing proposals that enabled them to seize control of Term's vaults.
Yearn confirmed that the attack involved a custom governance wrapper and did not apply to standard Yearn vault setups. Term is currently working with security teams to recover assets and address the shortfall. The attack follows a previous oracle error in April 2025, which led to the recovery of approximately 556 ETH and a reduced final loss of 362 ETH, with affected users being reimbursed.
In response, Term committed to third-party validation for critical updates and increased governance transparency.
Written by urgent.news from Cointelegraph's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.