Key Points
- Term Finance suffered approximately $8.5 million in losses from its Meta Vaults on August 24, 2026
- The exploit involved the theft of 2,843 ETH (approximately $6.87M) and 1.68 million USDC, with the stablecoin converted to DAI
- The malicious actor acquired inexpensive governance tokens to obtain majority voting power over the vaults
- Term Labs responded by permanently closing all Meta Vaults and removing DAO governance privileges
- The core Term lending protocol remained uncompromised, with user withdrawals still accessible
Term Finance, a fixed-rate lending platform built on Ethereum, has verified the loss of approximately $8.5 million following a sophisticated governance attack on its strategy vaults. The incident was flagged by blockchain security companies PeckShield and CertiK, representing one of 2026’s most significant decentralized finance breaches.
JUST IN: DeFi lender Term Finance reports a governance attack, losses around $8.5M as ~2,843 ETH and $1.68M USDC moved; Yearn V3-based vaults targeted, outer-layer governance flaw implicated. $TERM$ETH? pic.twitter.com/8YUYoeTOVt
ā Bpay News (@bpaynews) August 23, 2026
The perpetrator successfully extracted roughly 2,843 Ether tokens, valued at approximately $6.87 million during the exploit. Additionally, 1.68 million USDC was withdrawn and immediately converted into an equal value of DAI stablecoin.
Data from DefiLlama indicates the vaults contained approximately $12.45 million in total value locked before the breach occurred. The attack eliminated roughly 68% of all vault assets, including virtually the entire $8.8 million in Ethereum holdings.
The Attack Vector Explained
Blockchain monitoring platform Defimon reported that the attacker accumulated a substantial portion of a governance token with minimal holder distribution. Due to the token’s concentrated ownership structure, acquiring majority voting control required relatively little capital investment.
After obtaining controlling interest, the attacker successfully pushed through governance votes that granted access to vault assets. Term Finance has not publicly disclosed which specific governance mechanisms were exploited during the attack.
The vault smart contracts utilized Yearn V3 framework. Yearn issued a statement clarifying that the vulnerability existed in a custom governance layer implemented by Term Finance, not in the standard Yearn vault architecture.
Term Finance’s Response Strategy
Following discovery of the breach, Term Labs implemented immediate defensive measures. All Term Meta Vaults were permanently deactivated and DAO governance permissions were completely revoked, preventing any additional deposits. User withdrawal functionality remained operational to allow recovery of any remaining assets.
According to Term Finance’s statements, the underlying lending and borrowing protocol infrastructure was unaffected by the security breach. The organization continues assessing the complete impact of the incident.
The development team announced collaboration with external security specialists focused on asset recovery efforts. They also indicated plans to explore compensation mechanisms for users who sustained losses.
This marks the second significant security event for Term Finance. In April 2025, an oracle malfunction resulted in approximately 918 Ethereum worth of improper liquidations. The protocol recovered 556 ETH from that incident and compensated affected parties, subsequently committing to independent audits for critical system changes and enhanced governance oversight.
Term Labs has not issued responses to media inquiries. The security investigation remains active, with additional information anticipated as the review progresses.





