Fintech & Crypto Alerts · Quinn Barrett · 24 August 2026

Term Finance loses estimated $8.5M in vault exploit

Term Finance loses estimated $8.5M in vault exploit

Term Finance loses estimated $8.5 million after an attacker exploited governance control of its Meta Vaults, draining nearly all Ethereum deposits, blockchain security firms said. Term Labs permanently closed the vaults, revoked DAO governance roles, and said the core lending protocol appears unaffected while recovery work continues.

Key Takeaways

The hit, reported Aug. 24, 2026, is a sharp reminder that vault governance—not only smart-contract bugs—can empty DeFi deposits. For more crypto incident coverage, see our Fintech & Crypto Alerts hub.

What happened in the Term Finance vault exploit?

Decentralized lending protocol Term Finance lost an estimated $8.5 million after an attacker seized governance control of its strategy vaults, according to blockchain security firms cited by Cointelegraph.

On Sunday, PeckShield said the attacker drained about 2,843 Ether valued at $6.87 million at the time, and 1.68 million USDC, which was exchanged for about 1.68 million Dai. CertiK placed the total near $8.5 million.

Defillama data showed the reported loss was about 68% of the $12.45 million held in Term’s vault product beforehand, including nearly all of its roughly $8.8 million in Ethereum deposits.

How did the attacker gain control?

Onchain monitoring service Defimon said the attacker cheaply acquired a majority of a sparsely held governance token and passed proposals that let it seize control of Term’s vaults. Term has not confirmed how voting control was obtained or which governance functions were used.

The vault contracts use Yearn V3 infrastructure. Yearn said the attack involved a custom governance wrapper and that the vector does not apply to standard Yearn vault setups.

What has Term Labs done since the attack?

Term Labs said it irreversibly shut down all Term Meta Vaults and revoked their DAO governance roles, permanently blocking further deposits while keeping withdrawals open. It said its investigation so far shows the underlying Term protocol and direct borrowing and lending markets were unaffected, though it was still verifying the full scope.

Term said it is coordinating with external security teams on asset recovery and remediation and would “explore paths to address” any remaining shortfall. Cointelegraph said it could not reach Term Labs for comment.

The episode follows an April 2025 oracle error that triggered about 918 ETH in unintended liquidations. Term then recovered about 556 ETH, cut the final loss to 362 ETH, reimbursed users, and pledged third-party validation plus greater governance transparency.

Why does this matter for DeFi users?

Governance tokens that are thinly held can become an attack surface as dangerous as buggy code. Depositors in strategy vaults should weigh who controls upgrades and proposals—not only advertised yields—before parking funds.

When vault admin power is compromised, users can face eight-figure shortfalls even if core lending markets stay intact. Recovery depends on whether Term and outside security teams can claw back funds or cover remaining losses.

← Open in blast feed