Term Finance loses an estimated $8.5 million in governance exploit
Term Labs confirmed an exploit affecting its vaults, while PeckShield and CertiK estimated the drain at about $8.5 million. The protocol has not yet published a technical account or confirmed the final loss.
By The Third AnglePublished 4 min read
Illustrative infrastructure imagery; it does not depict Term Finance, the affected vaults or the attacker. Photo: Unsplash · Unsplash License
Term Labs said a governance exploit affected Term Finance vaults on Aug. 23, after an attacker moved ether and stablecoins from the Ethereum-based fixed-rate lending protocol. The Block reported that PeckShield and CertiK estimated the loss at about $8.5 million. Term Labs did not confirm that figure or identify the affected vaults in its initial public response.
Term shuts down the affected vault layer
A follow-up reported by PANews says Term Labs shut down all Meta Vaults and revoked DAO governance permissions. New deposits are blocked, withdrawals remain open and the team is working with external security firms. Term said its initial review found the direct Term lending markets were not affected, but that conclusion remains preliminary while the investigation continues.
What the chain shows
PeckShield identified roughly 2,843 ETH and 1.68 million USDC leaving the vault system; the USDC was swapped into DAI. A DeFiPrime reconstruction of the Ethereum transactions placed the first execution at 06:25:47 UTC on Aug. 23 and the second at 06:47:47 UTC. It said the first transaction pulled 2,841.74 WETH from the ETH Meta Vault, while the second drained 1,679,639.29 USDC across five vaults.
The same reconstruction says the ETH-side proposal had been visible for six days, drew no vetoes and included an action that set the vault's seven-day transaction cooldown to zero before the rest of the payload executed. That is a description of the onchain sequence, not a final explanation of how the attacker obtained the ability to submit the proposal.
The controls did not settle the risk
Term's governance documentation describes a seven-day delay and a veto path for liquidity providers. Those controls are meant to give depositors time to review queued changes, but they only protect funds if proposal permissions, monitoring and the veto mechanism work as intended. The available evidence does not establish whether a private key was compromised, whether a role was misconfigured or whether another governance path was abused.
The $8.5 million figure remains an estimate. The protocol has not published a final accounting, a list of affected users, recovery terms or a technical postmortem. Dashboard TVL is also not a substitute for an incident balance: vault accounting can continue to show assets as outstanding after funds have left the underlying strategy. The next useful evidence is Term's own postmortem, transaction-level disclosure and any confirmed pause, recovery or reimbursement plan.