Term Finance governance vulnerability causes Ethereum Treasury to lose US$8.5 million
Term Finance, a decentralized lending protocol, was attacked due to a custom treasury governance system, losing approximately US$8.5 million. The attacker took advantage of a custom governance control vulnerability to extract ether, USDC and DAI from the vault.
Term Labs said on social platform X that the governance vulnerability attack affected Term's treasury and has launched an internal investigation. However, the team did not confirm the specific amount of the loss, nor did it explain which strategic vaults suffered unauthorized withdrawals.
PeckShield estimated that the attacker extracted 2843 ether (approximately US$6.9 million) and 1.68 million USDC. The agency pointed out on the X platform that the attacker had exchanged the extracted USDC for approximately 1.68 million DAIs. After independently evaluating blockchain transactions, CertiK estimated the total loss to be close to US$8.5 million. PeckShield traced the asset flow to an address that initially received two ether coins through Tornado Cash.
Custom governance system becomes the main attack path
Term's policy vault follows the ERC-4626 standard and runs through an infrastructure developed based on the Yearn V3 architecture. However, the attackers targeted the custom governance encapsulation around the Term vault rather than Year's standard infrastructure.
Yearn said on the X platform that this attack method cannot affect vaults operating under its standard arrangements. Term separates operational authority from depositor supervision and shares responsibility through multiple roles: the administrator is responsible for the auction, and the governor controls risk parameters, emergency functions and broader protocol settings.
In addition, liquidity providers participate as members of the DAO and can veto governance transactions within a seven-day lock-in period. However, Term has not said which role the attacker breached and why these protections failed.
According to DefiLlama data, Term's treasury products held approximately US$12.45 million in assets in the supported network before the attack. About $8.8 million of that runs in vaults on the Ethereum blockchain. As a result, reported losses account for approximately 68% of the total locked value of treasury products across all networks.
Previous losses have put additional pressure on Term Finance.
Term was wrongly liquidated due to a misconfiguration of the oracle in April 2025, resulting in a loss of US$1.6 million. The agreement recovered more than $1 million and committed financial resources to make up for the rest.
Governance attacks remain an ongoing risk in the decentralized finance space, as attackers can manipulate voting mechanisms or gain privileged management rights. Term's investigation must determine how the attacker gained governance access and circumvented protections designed for depositors.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
ETH