An attacker drained approximately $8.5 million from Term Finance using an initial capital of just $951. The exploiter purchased enough governance tokens to gain control over four USDC strategy vaults and roughly 91% of the Ethereum Meta Vault. This incident highlights how protocol governance mechanisms can be turned against depositor funds.
How $951 in Capital Seized Control of the Protocol
Data from PeckShield reveals that the attacker withdrew around 2,843 ETH worth $6.87 million and 1.68 million USDC from the system. The USDC was immediately swapped for DAI following the withdrawal. Prior to the attack, total depositor funds in the Meta Vault stood at approximately $12.45 million, meaning the exploit wiped out nearly 68% of the total value deposited.
The perpetrator’s digital wallet initially received 2 ETH in funding from Tornado Cash. Etherscan has now labeled two related addresses as ‘Term Finance Exploiter 1 & 2’. With just $951 spent to acquire governance tokens, the attacker was able to take over the assets stored in the vaults.
No Code Flaws or System Bugs Involved
Term Finance emphasized that the incident did not exploit bugs in the codebase. Instead, the attacker executed legitimate governance processes after securing dominant voting power. While Term’s vault system is built using Yearn V3 architecture, the exploit occurred through a custom governance wrapper component designed specifically by the Term team. Standard Yearn components were reported to remain secure.
Team Response and a String of Similar Attacks
As a protective measure, Term Finance permanently closed all Term Meta Vaults and revoked DAO governance functions. The Term Labs team has yet to announce compensation plans, repayment schedules, or coordination with law enforcement. However, existing users can still withdraw their remaining funds from the platform.
This governance manipulation is not an isolated incident. In July 2026, another attacker acquired voting power to transfer $20 million worth of BONK tokens from the BonkDAO treasury. Later on August 18, Binance thwarted a similar attempt targeting an unnamed DAO project, saving $1.2 million in funds.
Three governance attacks within the past two months have prompted the DeFi community to reassess its security practices. For instance, ENS DAO established an eight-member security council following the BonkDAO incident. This council requires approval from at least five members to veto suspicious transactions before execution.
For DeFi investors, this incident demonstrates that even the most rigorous code audits cannot guarantee fund safety if a protocol’s governance rules leave room for low-cost manipulation. Before allocating capital to new platforms, reviewing voting power defense mechanisms may now be an indispensable necessity.
Reported by crypto.news.
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




