Key Takeaways
- Approximately $8.5 million was stolen from Term Finance Meta Vaults on August 24, 2026
- The exploit resulted in the loss of 2,843 ETH (valued at roughly $6.87M) and 1.68 million USDC, which was converted to DAI
- The hacker allegedly acquired inexpensive governance tokens to obtain majority voting power over the vaults
- All Meta Vaults have been permanently disabled by Term Labs, with DAO governance privileges revoked
- The core Term lending platform remained secure, with withdrawal functionality still operational
An Ethereum-based fixed-rate lending platform, Term Finance, has acknowledged losing approximately $8.5 million following a governance exploit targeting its strategy vaults. The incident, flagged by blockchain security companies PeckShield and CertiK, represents one of the most significant DeFi security breaches in 2026.
The malicious actor successfully extracted roughly 2,843 Ether, valued at approximately $6.87 million during the breach. Additionally, 1.68 million USDC was withdrawn and subsequently converted into an equal value of DAI tokens.
Data from DefiLlama shows the vaults contained around $12.45 million in total value locked before the incident occurred. The attack effectively eliminated approximately 68% of all vault assets, including virtually the entire $8.8 million Ethereum reserve.
Attack Vector Explained
Blockchain monitoring platform Defimon reported that the perpetrator acquired a substantial portion of a governance token with minimal holder distribution. Due to the token’s concentrated ownership structure, the attacker could cheaply accumulate sufficient tokens to establish majority governance authority.
Using this newly acquired control, the attacker successfully enacted governance measures that granted access to vault funds. Term Finance has yet to disclose the specific governance mechanisms exploited during the attack.
The vault infrastructure was constructed using Yearn V3 framework. Yearn issued a statement clarifying that the vulnerability existed in a custom governance layer implemented by Term Finance, emphasizing that standard Yearn vault deployments remained unaffected by this exploit.
Term Finance Response and Remediation
Following discovery of the breach, Term Labs implemented immediate countermeasures. The development team completely disabled all Term Meta Vaults and stripped all DAO governance permissions, preventing any additional deposits. User withdrawals remained enabled to allow recovery of any remaining assets.
According to Term’s statement, the primary lending and borrowing platform infrastructure was uncompromised by the attack. The team continues to assess the complete extent of the security incident.
The platform announced collaboration with external security specialists on fund recovery efforts. Term also indicated plans to explore compensation mechanisms for users who suffered losses from the exploit.
This incident marks the second major security challenge for Term Finance. In April 2025, an oracle malfunction triggered approximately 918 Ethereum worth of erroneous liquidations. The team successfully recovered 556 ETH and compensated affected users, subsequently committing to independent verification protocols for critical system changes and enhanced governance accountability.
Term Labs has not issued additional statements in response to media inquiries. The security investigation remains active, with more information anticipated as the analysis progresses.



