DeFi lending protocol Term Finance lost $8.5 million when an unknown attacker exploited the governance system controlling its Strategy Vaults, according to blockchain security firms PeckShield and CertiK. The attacker withdrew approximately 2,843 ETH worth roughly $6.9 million and 1.68 million USDC, which was then swapped for DAI, per PeckShield. Term Labs confirmed a governance exploit impacting its vaults but did not verify the loss amount or identify which vaults were affected. The funds were traced to a single address that initially received 2 ETH from mixing protocol Tornado Cash.

The exploit matters because it bypassed supposedly robust controls and wiped out two-thirds of the vault product's total value locked. Term's Strategy Vaults use a governance structure that separates operational control from depositor oversight, with vault liquidity providers able to veto queued governance transactions during a seven-day timelock, according to Term's governance documentation. The $8.55 million loss equals about 68 percent of the vault product's TVL across all chains and nearly all of its Ethereum TVL, which stood at about $8.8 million before the hack out of $12.45 million total vault TVL, per DefiLlama data. Term has not disclosed which governance role the attacker exploited or why the timelock and LP veto controls failed to prevent the transactions. Yearn Finance clarified that the exploit occurred via a custom governance wrapper around Term's vaults and is not applicable to standard Yearn vault setups, stating that funds in standard Yearn vaults remain safe.

For traders, this is isolated protocol damage with no contagion path to broader DeFi infrastructure or major assets. The exploit targeted Term's custom governance layer on top of Yearn V3 architecture, not a shared bridge, oracle, or cross-chain collateral system. Term's overall TVL was about $25.8 million before the hack, meaning the vaults represented less than half of its total locked value and the protocol itself is a small player in the DeFi lending space. Funding stands at 1.0 basis points per eight hours, 67 percent above the 30-day average of 0.6 basis points, and Fear and Greed at 66 Greed versus a 30-day average of 35, indicating leverage remains elevated and sentiment frothy. This type of governance exploit does not trigger cascading liquidations or affect collateral backing for other protocols.

Watch whether Term discloses the attack vector and whether other protocols using custom governance wrappers on Yearn infrastructure respond with audits or pauses. Until then, this is noise for BTC and ETH traders and a reminder that high-yield vault strategies carry execution risk independent of the underlying lending markets they tap.

Source: The Block