Term Finance Governance Exploit Results in $8.5M Drain
An attacker exploited Term Finance's governance architecture to drain approximately $8.5 million from Ethereum-based lending protocol Term Finance on August 23. The attack targeted the protocol's vault layer, which is built on Yearn V3 infrastructure.
The attacker acquired a majority of the protocol's DAO governance token and then passed malicious proposals to seize control of Term's vaults. The LP veto mechanism, designed to prevent this kind of attack, failed to intercept it.
Term Labs confirmed the exploit publicly on Sunday, saying it was aware of a governance exploit impacting its vaults and would share more information as the investigation progressed. In a follow-up post on Monday, Term Labs announced permanent Meta Vault shutdown, revoking all DAO governance roles and permanently preventing further deposits while keeping withdrawals open.