Key Points
- Term Finance experienced an $8.5 million loss from its Meta Vaults on August 24, 2026
- The exploit resulted in the theft of 2,843 ETH (approximately $6.87M) and 1.68 million USDC, which was converted to DAI
- The hacker allegedly acquired inexpensive governance tokens to obtain voting majority over the vaults
- Term Labs has closed all Meta Vaults permanently and removed DAO governance permissions
- The core Term lending platform remained secure, with withdrawal functionality still operational
An Ethereum-based fixed-rate lending platform, Term Finance, has verified the loss of approximately $8.5 million following a governance-based exploit targeting its strategy vaults. Both PeckShield and CertiK, prominent blockchain security analysts, documented the incident, marking it as one of 2026’s most significant DeFi security breaches.
The malicious actor successfully extracted roughly 2,843 Ether, valued at approximately $6.87 million during the attack. Additionally, 1.68 million USDC was siphoned and immediately converted into an equal value of DAI.
Data from DefiLlama indicates the vaults contained approximately $12.45 million prior to the breach. The exploit consequently eliminated around 68% of the total vault assets, including virtually all of the $8.8 million in Ethereum holdings.
Attack Vector Explained
Blockchain monitoring platform Defimon reported that the perpetrator accumulated a significant position in a governance token with minimal holder distribution. Due to the token’s concentrated ownership structure, the attacker could economically acquire sufficient tokens to achieve majority governance authority.
Using this controlling position, the attacker executed governance votes that enabled them to compromise the vaults. Term Finance has not publicly disclosed the specific governance mechanisms that were manipulated during the attack.
The vault infrastructure was developed using Yearn V3 technology. Yearn representatives clarified that the vulnerability existed within a customized governance layer implemented by Term Finance, emphasizing that standard Yearn vault configurations do not contain this security flaw.
Term Finance Response Measures
Following the security breach, Term Labs implemented immediate defensive measures. The organization permanently disabled all Term Meta Vaults and eliminated their DAO governance capabilities, preventing any additional deposits. Users retained the ability to withdraw their remaining holdings.
Term confirmed that the primary lending and borrowing infrastructure remained uncompromised throughout the incident. The platform continues to assess the complete extent of the damage.
The development team stated they are collaborating with external security specialists regarding potential asset recovery efforts. They also indicated plans to explore compensation mechanisms for users who sustained losses.
This marks the second security incident for Term Finance. Previously, in April 2025, an oracle malfunction resulted in roughly 918 Ethereum worth of erroneous liquidations. The platform recovered 556 ETH during that episode and compensated affected users, subsequently committing to independent verification processes for critical system updates and enhanced governance accountability.
Term Labs has not issued additional statements in response to media inquiries. The security investigation remains active, with more information anticipated as the analysis progresses.


