XRP $3.12 ▲ 4.8% BTC $114,820 ▲ 1.2% ETH $4,380 ▼ 0.6% RLUSD $1.00 ▲ 0.0% XLM $0.41 ▲ 3.1% Fear & Greed 68 · GreedXRP $3.12 ▲ 4.8% BTC $114,820 ▲ 1.2% ETH $4,380 ▼ 0.6% RLUSD $1.00 ▲ 0.0% XLM $0.41 ▲ 3.1% Fear & Greed 68 · Greed
Home / Markets
● Markets

Governance Attack Drains $8.5M From Term Finance Protocol

Decentralized lending platform Term Finance suffered a significant loss after an attacker manipulated governance controls to drain strategy vaults of Ethereum and stablecoins.

JM
by Jacob Marquez · Markets Desk
Published August 24, 2026 · 2 min read

Attack Drains Millions Through Governance Exploit

Decentralized lending platform Term Finance fell victim to a governance-based attack that resulted in the loss of approximately $8.5 million, according to blockchain security researchers PeckShield and CertiK. The attacker leveraged control of governance mechanisms to seize assets from the protocol’s strategy vaults, specifically targeting Ethereum holdings and USDC reserves.

The breach resulted in the removal of roughly 2,843 ETH—worth approximately $6.87 million at the time of the attack—along with 1.68 million USDC that was subsequently converted into roughly equivalent amounts of Dai (DAI). The combined loss represented a substantial portion of the vault product’s total value. According to data from Defillama, approximately $12.45 million was held across these vaults before the incident, including nearly $8.8 million in Ethereum deposits, meaning the attack impacted roughly 68% of total vault holdings.

Term Labs Responds With Immediate Shutdown

In response to the breach, Term Labs moved quickly to prevent further damage. The company announced the permanent closure of all Term Meta Vaults and revoked their DAO governance roles, preventing additional capital inflows while maintaining withdrawal access for affected users. Early investigation by Term Labs indicated that the core lending and borrowing protocols remained unaffected by the exploit, though the company stated it was continuing security analysis to determine the full scope of the incident.

Governance Attack Vector Exposed

According to blockchain monitoring service Defimon, the attacker achieved control by acquiring a substantial stake in Term’s governance token when it was sparsely distributed, then used this majority position to propose changes granting them access to vault assets. While the vault infrastructure relies on Yearn V3 technology, Yearn clarified that the attack specifically targeted a custom governance wrapper layered on top of their standard vaults, confirming that typical Yearn setups were not affected.

Term Labs indicated it is coordinating with external security teams on asset recovery and remediation efforts. The incident follows an April 2025 oracle error that triggered unintended liquidations affecting 918 ETH, from which Term recovered a portion of funds and reimbursed users, subsequently pledging third-party validation for critical updates and enhanced governance transparency. Governance vulnerabilities like this underscore broader DeFi security challenges that investors and protocols must address as the ecosystem matures.

Source: PeckShield and CertiK, via Cointelegraph. Not financial advice.

// DISCLAIMER: This article is for informational purposes only and is not financial, investment, or trading advice. Terminalcraft may earn a commission from affiliate links. Crypto is volatile and high-risk. Always do your own research.
JM

Jacob Marquez — Markets Desk

Jacob Marquez is the founder and editor of Terminalcraft, an independent XRP-first crypto news desk. An XRP holder and market watcher since 2016, he started Terminalcraft to deliver fast, factual crypto news without the hype.