TLDR
- Term Finance lost an estimated $8.5 million from its Meta Vaults on August 24, 2026
- An attacker drained 2,843 ETH (~$6.87M) and 1.68 million USDC, swapping the USDC for DAI
- The attacker reportedly bought cheap governance tokens to gain voting control of the vaults
- Term Labs has permanently shut down all Meta Vaults and revoked DAO governance roles
- The underlying Term lending protocol was not affected, and withdrawals remain open
Term Finance, an Ethereum-based fixed-rate lending protocol, confirmed it lost around $8.5 million after an attacker exploited governance control of its strategy vaults. Blockchain security firms PeckShield and CertiK both reported the loss, making it one of the more costly DeFi incidents of 2026.
JUST IN: DeFi lender Term Finance reports a governance attack, losses around $8.5M as ~2,843 ETH and $1.68M USDC moved; Yearn V3-based vaults targeted, outer-layer governance flaw implicated. $TERM$ETH? pic.twitter.com/8YUYoeTOVt
— Bpay News (@bpaynews) August 23, 2026
The attacker drained approximately 2,843 Ether, worth about $6.87 million at the time. They also took 1.68 million USDC, which was then swapped for an equivalent amount of DAI.
According to DefiLlama data, the vaults held about $12.45 million before the attack. That means the exploit wiped out roughly 68% of total vault holdings, including nearly all of the $8.8 million in Ethereum deposits.
How the Attacker Gained Control
Onchain monitoring service Defimon said the attacker purchased a large share of a governance token that had very few holders. Because the token was sparsely distributed, the attacker was able to buy enough to gain majority voting power cheaply.
With that control, the attacker passed governance proposals that allowed them to seize the vaults. Term Finance has not confirmed the exact governance functions that were used.
The vault contracts were built on Yearn V3 infrastructure. Yearn clarified that the attack involved a custom governance wrapper added by Term Finance, and that standard Yearn vault setups were not vulnerable.
What Term Finance Did Next
Term Labs moved quickly after the attack. The team permanently shut down all Term Meta Vaults and revoked their DAO governance roles, blocking any new deposits. Withdrawals were left open so users could access remaining funds.
Term said the core lending and borrowing markets were not affected by the exploit. The team is still verifying the full scope of the incident.
The protocol said it is working with outside security teams on asset recovery. It also said it would look into ways to cover any remaining shortfall for affected users.
This is not the first time Term Finance has faced a security issue. In April 2025, an oracle error caused about 918 Ethereum in unintended liquidations. The team recovered 556 ETH at the time and reimbursed users, later promising third-party validation for critical updates and stronger governance transparency.
Term Labs did not respond to requests for comment. The investigation is ongoing, and further details are expected as the review continues.







