Decentralized lending protocol Term Finance lost an estimated $8.5 million on August 23, 2026, following a governance exploit that targeted its strategy vaults. The incident led to the permanent closure of all Term Meta Vaults by Term Labs, the company behind the protocol.

Blockchain security firm PeckShield reported the attacker drained approximately 2,843 Ether, valued at $6.87 million at the time of the incident. An additional 1.68 million USDC was also removed and subsequently converted into an equivalent amount of Dai. CertiK provided a similar estimate, placing the total loss at $8.5 million.

The $8.5 million loss constituted about 68 percent of the $12.45 million total value held in Term's vault product prior to the exploit. The attack removed nearly all of the approximately $8.8 million in Ethereum deposits from these vaults, according to Defillama data.

On-chain monitoring service Defimon indicated the attacker acquired a majority of a sparsely held governance token, allowing them to pass malicious proposals and seize control of Term's vaults. Term has not confirmed the specific method used to obtain voting control or the governance functions exploited.

The compromised vault contracts utilized Yearn V3 infrastructure. However, Yearn clarified that the exploit involved a custom governance wrapper developed by Term. Yearn stated the attack vector does not apply to standard Yearn vault setups, isolating the vulnerability to Term's specific implementation.

Following the exploit, Term Labs announced it had irreversibly shut down all Term Meta Vaults and revoked their associated DAO governance roles. This action permanently prevents any further deposits into these vaults while keeping withdrawal functions open for users.

Term Labs' initial investigation suggests the underlying Term protocol and its direct borrowing and lending markets were unaffected by the exploit. The company is continuing to verify the full scope of the incident.

Term is coordinating with external security teams to pursue asset recovery and remediation efforts. The protocol stated it would explore various paths to address any remaining financial shortfall experienced by affected users.

This governance exploit follows a previous security incident in April 2025, when an oracle error on Term triggered unintended liquidations totaling approximately 918 ETH. Term managed to recover about 556 ETH from that event, reducing the final loss to 362 ETH, and reimbursed affected users. After the 2025 incident, Term pledged third-party validation for critical updates and committed to greater governance transparency.