A $951 purchase secured 90.66% of Term Finance's governance voting power, enabling an $8.5 million vault drain on Aug. 23.
A $951 purchase secured 90.66% of Term Finance's governance voting power, enabling an $8.5 million vault drain on Aug. 23.

Term Finance lost approximately $8.5 million on Aug. 23 after a $951 token purchase seized 90.66 percent of governance voting power. The exploit hit the Ethereum-based fixed-rate lending protocol's Strategy Vaults, which are ERC-4626 tokenized vaults built on Yearn V3 infrastructure.
"We are aware of a governance exploit impacting Term vaults," Term Labs said in a statement on X. "We will share more details once it has been further investigated." Blockchain security firm PeckShield confirmed the breach, reporting the attacker withdrew approximately 2,843 ETH, valued at about $6.87 million, along with 1.68 million USDC, which was subsequently swapped into roughly 1.68 million DAI. CertiK separately corroborated the approximately $8.5 million loss figure.
The attacker bought 0.4852 tmvETH for roughly 0.5 ETH — about $951 at the time — and staked it on Aug. 17. That single purchase secured 90.66 percent of all existing voting power because the pre-drain staked supply across the pool sat at just 0.5352 gtmvETH, an almost negligible amount for a vault holding millions in depositor funds. PeckShield traced the attacker's wallet to an initial 2 ETH transfer from Tornado Cash, the privacy mixing protocol frequently used to obscure the origin of attacker wallets before an exploit.
The loss represents nearly all of the vault product's $8.8 million in Ethereum-based holdings and roughly two-thirds of its $12.45 million total value locked across chains, according to DefiLlama data. Term Finance's broader protocol held about $25.8 million in total value locked and $3.79 million in active loans before the incident.
Term's governance structure separates operational control between a "manager" role handling auction activity and a "governor" role overseeing risk parameters and emergency functions. Vault liquidity providers can vote to veto queued governance transactions during a seven-day timelock. Term has not disclosed which role the attacker exploited or why the veto window failed to stop the transaction.
The attack pattern is not new. DeFi builder Psykeeper drew a direct line to the BonkDAO exploit from July, where a malicious governance proposal drained roughly $20 million, and to a March incident at Moonwell where an attacker spent about $1,800 on tokens to push a proposal threatening $1.08 million. The structural difference with Term is stark: where the BonkDAO attacker needed millions to accumulate voting power, this attacker needed only $951, a direct function of how little of Term's vault supply was actually staked and participating in governance.
Yearn moved quickly to clarify that the exploit ran through a custom governance wrapper specific to Term's setup rather than through standard Yearn vault architecture, stating that funds deposited into standard Yearn vaults remained safe and unaffected.
Not every part of Term's ecosystem was exposed. Tori, a project connected to Term's infrastructure, confirmed directly that it had zero exposure to the exploit. According to Tori, trUSD and strUSD holders had zero exposure, Ecosystem Vault participants remain fully covered, and all operations continue running normally. The statement was direct about what affected users need to do next: nothing.
Psykeeper pointed to onchain monitoring systems like Hypernative Labs as the kind of infrastructure that could have flagged this attack before execution, since a wallet suddenly accumulating 90 percent of a governance pool's voting power off a $951 purchase is exactly the type of anomaly automated monitoring is designed to catch in real time.
Term Finance had already experienced a separate incident in April 2025, when a misconfigured oracle caused faulty liquidations in its tETH market, a loss the protocol said was not a hack and later recovered more than $1 million of the $1.6 million affected. This latest governance breach is a different kind of failure, one rooted in incentive design rather than code. Until vault architectures solve the underlying problem of near-zero governance participation creating near-zero cost takeovers, the same pattern — a small stake, a sudden supermajority, a drained treasury — is likely to keep surfacing in security reports.
This article is for informational purposes only and does not constitute investment advice.