TLDR
- An estimated $8.5 million was stolen from Term Finance through a governance control exploit targeting strategy vaults.
- The exploit resulted in the theft of 2,843 ETH along with approximately $1.68 million in stablecoins.
- Around 68% of the $12.45 million stored in Term Finance’s vault product was compromised during the incident.
- Majority governance control was obtained by the perpetrator, enabling malicious proposals to authorize fund withdrawals.
- Following confirmation of the breach, Term Labs disabled new Meta Vault deposits permanently and removed DAO governance privileges.
The decentralized lending platform Term Finance experienced an $8.5 million breach when an exploiter obtained governance authority over its strategy vaults. The incident impacted the Meta Vault infrastructure, though Term Finance’s core borrowing and lending operations continued functioning.
Blockchain security companies PeckShield and CertiK monitored the stolen assets. PeckShield documented holdings of 2,843 Ether valued at $6.87 million alongside 1.68 million USDC. The perpetrator subsequently converted the USDC holdings into 1.68 million DAI.

PeckShieldAlert: X
Governance Mechanism Exploited in Strategy Vault Attack
On August 23, 2026, Term Labs disclosed that a governance-based exploit had compromised Term Vaults. The organization explained that the breach targeted the vault infrastructure layer constructed above its fixed-rate lending protocol. Initial assessments indicated the core lending markets remained secure.
Blockchain tracking service Defimon identified that the perpetrator purchased a controlling stake in a thinly traded governance token. According to reports, the exploiter utilized 2 ETH originating from Tornado Cash to obtain TERM tokens. This voting authority purportedly enabled the passage of harmful proposals.
These proposals allegedly granted the perpetrator withdrawal authority over strategy vaults. Analysis suggests the approach circumvented both a seven-day timelock mechanism and an LP veto system through specialized governance architecture. Term Labs has yet to verify these technical details.
The compromised vaults operate on Yearn V3 infrastructure. Yearn clarified that the breach exploited a customized governance wrapper implemented by Term Finance. The organization emphasized that this vulnerability does not affect standard Yearn vault implementations.
Meta Vault Deposits Halted Following Security Breach
After verifying the incident, Term Labs implemented a permanent freeze on new deposits across all Meta Vaults. The company eliminated DAO governance permissions associated with the vaults. User withdrawals remain available as the investigation proceeds.
According to DefiLlama analytics, the vault infrastructure contained approximately $12.45 million before the breach occurred. The stolen amount constituted 68% of total vault assets. Prior to the drainage, the vaults also held close to $8.8 million in Ether.
Investigation Underway Following Earlier Oracle Incident
Term Labs announced collaboration with external security specialists for asset recovery and system remediation efforts. The platform recommended users temporarily revoke contract approvals and monitor only verified communication channels during the ongoing investigation.
This breach follows an April 2025 oracle malfunction that triggered approximately 918 ETH in unplanned liquidations. Term subsequently retrieved around 556 ETH, documented a final deficit of 362 ETH, and compensated impacted users.





