Login
Sign Up
Woofun AI reports that Term Finance, an Ethereum lending platform, suffered an $8.5 million loss after an attacker acquired majority voting power through cheap governance tokens to drain Meta Vaults.
The financial impact was severe, with the attacker removing 2,843 ether (ETH), valued at approximately $6.9 million, alongside 1.68 million USDC. This extraction represented about 68% of the assets held in Term's vaults, which contained roughly $12.45 million prior to the incident. Nearly all of the $8.8 million in ether deposited in the product was taken, leaving the vaults significantly depleted.
Woofun AI data shows, Structurally, the attack vector relied on the cheap acquisition of sparsely held governance tokens, as observed in on-chain data. This allowed the attacker to pass proposals granting control over the vaults, which were built using Yearn V3 infrastructure. Yearn clarified that the exploit involved a custom governance layer added around its technology and did not apply to standard Yearn vaults.
Notably, this incident follows a previous security breach in April 2025, when an oracle error triggered unintended liquidations of 918 ETH. At that time, the protocol recovered most funds and pledged greater governance transparency and outside validation for critical changes, aiming to prevent similar vulnerabilities.
Term Finance has permanently shut down the affected product and is working with outside security teams to recover assets. This marks a recurring theme where governance mechanisms, rather than code exploits, become the primary weak point in decentralized finance protocols.