Login
Sign Up
Woofun AI reports that Term Finance suffered an $8.5 million loss after an attacker exploited governance control of its strategy vaults, a finding corroborated by security firms including PeckShield, CertiK, and Defimon. The incident highlights vulnerabilities in custom governance wrappers built on Yearn infrastructure.
Woofun AI data shows the financial impact was severe, with PeckShield estimating the drain at 2,843 Ether (ETH), valued at $6.87 million, alongside 1.68 million USDC swapped for approximately 1.68 million Dai (DAI). CertiK confirmed the total loss at roughly $8.5 million, representing 68% of the $12.45 million held in Term's vaults prior to the attack. This figure includes nearly all of the protocol's approximately $8.8 million in Ethereum deposits.
On Sunday, Term Labs announced the irreversible shutdown of all Term Meta Vaults, revoking their DAO governance roles to prevent further deposits while keeping withdrawals open. The company stated that the underlying Term protocol and its direct borrowing and lending markets remained unaffected, though verification continued. Term Labs could not be reached for comment, as the firm lists no public press contact and has closed direct messages on X.
Defimon noted that the attacker cheaply acquired a majority of a sparsely held governance token, passing proposals to seize vault control. While the vault contracts utilize Yearn V3 infrastructure, Yearn clarified that the exploit involved a custom governance wrapper, meaning the attack vector does not apply to standard Yearn vault setups. Term is currently coordinating with external security teams on asset recovery.
This event follows an April 2025 oracle error that triggered about 918 ETH in unintended liquidations. Term recovered about 556 ETH, reducing the final loss to 362 ETH and reimbursing users. Following that incident, the protocol pledged third-party validation for critical updates and greater governance transparency.