EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Term Finance governance breach steals $8.5 million from Ethereum vault

2026-08-25 00:15:32
Bookmark

Term Finance governance vulnerability causes Ethereum Treasury to lose US$8.5 million

Term Finance, a decentralized lending protocol, was attacked due to a custom treasury governance system, losing approximately US$8.5 million. The attacker took advantage of a custom governance control vulnerability to extract ether, USDC and DAI from the vault.

Term Labs said on social platform X that the governance vulnerability attack affected Term's treasury and has launched an internal investigation. However, the team did not confirm the specific amount of the loss, nor did it explain which strategic vaults suffered unauthorized withdrawals.

PeckShield estimated that the attacker extracted 2843 ether (approximately US$6.9 million) and 1.68 million USDC. The agency pointed out on the X platform that the attacker had exchanged the extracted USDC for approximately 1.68 million DAIs. After independently evaluating blockchain transactions, CertiK estimated the total loss to be close to US$8.5 million. PeckShield traced the asset flow to an address that initially received two ether coins through Tornado Cash.

Custom governance system becomes the main attack path

Term's policy vault follows the ERC-4626 standard and runs through an infrastructure developed based on the Yearn V3 architecture. However, the attackers targeted the custom governance encapsulation around the Term vault rather than Year's standard infrastructure.

Yearn said on the X platform that this attack method cannot affect vaults operating under its standard arrangements. Term separates operational authority from depositor supervision and shares responsibility through multiple roles: the administrator is responsible for the auction, and the governor controls risk parameters, emergency functions and broader protocol settings.

In addition, liquidity providers participate as members of the DAO and can veto governance transactions within a seven-day lock-in period. However, Term has not said which role the attacker breached and why these protections failed.

According to DefiLlama data, Term's treasury products held approximately US$12.45 million in assets in the supported network before the attack. About $8.8 million of that runs in vaults on the Ethereum blockchain. As a result, reported losses account for approximately 68% of the total locked value of treasury products across all networks.

Previous losses have put additional pressure on Term Finance.

Term was wrongly liquidated due to a misconfiguration of the oracle in April 2025, resulting in a loss of US$1.6 million. The agreement recovered more than $1 million and committed financial resources to make up for the rest.

Governance attacks remain an ongoing risk in the decentralized finance space, as attackers can manipulate voting mechanisms or gain privileged management rights. Term's investigation must determine how the attacker gained governance access and circumvented protections designed for depositors.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP