DeFi lending protocol Term Labs lost roughly $8.5 million after an attacker exploited governance controls on its vault product, according to Wu Blockchain, which cited alerts from PeckShieldAlert and CertiK confirming the loss and noting the exploiter held enough voting power to direct the vaults to release funds. The attack drained approximately 2,843 ETH — worth about $6.87 million at the time — along with 1.68 million USDC, which was later swapped into roughly 1.6 million DAI.

Unlike most headline DeFi hacks, this exploit didn't involve a smart contract bug, an oracle flaw, or a flash-loan trick. The attacker simply accumulated enough governance voting power to pass a proposal instructing the vaults to hand over their funds — and the contracts, functioning exactly as designed, complied. The exploited vaults were built on Yearn v3 infrastructure rather than Term Finance's core repo-lending architecture, meaning the underlying lending protocol itself was not directly compromised.

Term Labs Loses $8.5M as Attacker Buys Governance Vote to Drain Vaults
Image via @WuBlockchain on X

A governance attack, not a code exploit

The mechanics matter because they sidestep the entire category of protection that audits are built to catch. Governance attacks pass through fully audited contracts without breaking anything technically; the vulnerability lives in how voting power is distributed and how quickly a malicious proposal can be executed once passed, not in the contract logic itself. Reports indicate the attacker's initial funding traced back to just 2 ETH sourced through Tornado Cash — a small seed that nonetheless proved sufficient to acquire the governance weight needed to move roughly $8.5 million.

The scale of the loss is significant relative to the affected product: the stolen funds represent about 68% of the vault product's total value locked across all chains, and nearly the entirety of the vaults' Ethereum-based TVL specifically. This is not Term Finance's first security incident — the protocol lost around $1.5 million in May 2025 to an oracle decimal mismatch introduced during a routine upgrade, though that earlier episode involved a different failure mode entirely.

Related: Crypto Card Spending Triples to $1B as Stablecoins Go Everyday

What it means for governance-secured DeFi

The exploit adds to a growing body of evidence that governance-based attack vectors deserve the same scrutiny as smart contract vulnerabilities, particularly for protocols where voting power can be accumulated quickly and cheaply relative to the value it controls. For depositors evaluating vault products across DeFi, the Term Labs incident is a reminder to weigh not just audit history but also how concentrated and how fast-moving a protocol's governance process is — since in this case, the code worked exactly as written, and that was the problem.