Term Finance said an attacker exploited governance control over its strategy vaults, resulting in an estimated loss of about $8.5 million. The drained assets included roughly 2,843 ETH, valued at around $6.87 million at the time, and 1.68 million USDC that was later swapped for about 1.68 million DAI.

The incident affected Term’s vault product rather than the protocol’s core borrowing and lending markets. In response, Term Labs permanently closed the Term Meta Vaults, blocked any new deposits, and left withdrawals available while the company and outside security teams reviewed the damage and possible recovery options.

How the exploit unfolded

According to Term, the attacker allegedly obtained majority control of a thinly held governance token at low cost and then used that position to push through proposals that transferred control of the strategy vaults. With governance captured, the vaults were seized and their assets drained.

Term estimated the loss at around $8.5 million in total. Before the attack, the vault product held about $12.45 million, meaning the exploit erased roughly 68% of those assets and removed nearly all of the Ethereum deposited in the affected product.

Assets taken and immediate response

The funds taken included approximately 2,843 ETH and 1.68 million USDC. The USDC was swapped into about 1.68 million DAI, bringing the combined value of the stolen assets to roughly $8.5 million based on prices at the time cited by the project.

After detecting the incident, Term Labs shut down all Term Meta Vaults and removed their DAO governance roles. The company also permanently disabled further deposits into those vaults, while keeping withdrawals open for users with remaining funds in the product.

What was and was not affected

Term said the exploit was confined to the vault structure and did not impact the underlying Term protocol or its direct borrowing and lending markets. Even so, the company noted that investigators were still working to verify the full scope of the incident.

That distinction matters because the attack targeted governance around the strategy vaults rather than the broader lending infrastructure. The project has so far framed the event as a vault governance failure, not a compromise of its main market operations.

Yearn’s note and the next steps

Yearn said the exploit relied on a custom governance wrapper and did not affect standard Yearn vault configurations. That statement suggested the attack path was specific to the design used in this case rather than a broader issue across ordinary Yearn vault setups.

Term said it was coordinating with external security teams on recovery and remediation efforts. The company also said it would explore ways to address any remaining shortfall, while continuing to assess the incident and determine what assets, if any, can be recovered.

Source: cointelegraph.com