A governance vote, not a code bug, emptied Term Finance's vaults
An attacker bought majority control of a thinly held governance token, passed proposals against Term Finance's strategy vaults and moved roughly $8.5 million out. The contracts executed exactly as written.
By Staff, Lend Ledger
The standard list of ways a lending deposit reaches zero has three entries: the counterparty fails, the collateral is liquidated, or the contract is broken. What happened at Term Finance on 23 August fits none of them cleanly. Nothing was broken. The vaults released the money because they were instructed to, through a vote the attacker had bought.
The sequence
Term Finance is a fixed-rate lending protocol on Ethereum. Per an account published by The Crypto Times on 23 August, an attacker bought majority voting power in the protocol’s thinly held governance token on the open market — the low float made a supermajority cheap — then submitted proposals redirecting vault assets and voted them through. At execution the attacker is described as holding the entire vote in four of five USDC strategy vaults and roughly 91 per cent of the Ethereum Meta Vault.
The drained assets are put at roughly 2,843 ETH and 1.68 million USDC, the stablecoin subsequently swapped into DAI — around $8.5 million. PeckShield and CertiK each confirmed the incident, and The Cryptonomist reports that both firms traced the proceeds to a single address. Against pre-incident vault total value locked of about $12.2 million on DefiLlama data, that is the greater part of what those vaults held. The Cryptonomist places the drain in Term’s Yearn v3-based vaults, not its core fixed-rate lending architecture. The starting capital, per PeckShield’s on-chain data cited in both accounts, was 2 ETH withdrawn from Tornado Cash.
The surface nobody prices
An audit answers whether code does what its authors intended. It does not answer who is allowed to change their minds.
Where a vault’s assets sit behind a token vote, security becomes arithmetic: what does a controlling share of that token cost, against the value it can direct? A thinly held token attached to a multi-million-dollar vault inverts the ratio that keeps the arrangement honest.
A strategy vault is a permissioned allocation, and permissions have holders; where one shared allocation layer sits under several front ends, the permission holder is what a depositor is actually trusting.
What Term Labs has said
The team acknowledged the incident on X within hours of the drain settling, saying it was aware of a governance exploit affecting Term vaults and would share more once it had been investigated further. Neither account cited here records a technical postmortem, a recovery or a compensation plan at the time of publication. What has changed since is not set out in either report.
Two things are worth establishing from any such protocol’s own documentation before depositing: what controlling a vault decision costs, and whether a timelock sits between a passed proposal and its execution. The Crypto Times account names timelocks, delegate-based voting and treasury-scaled quorums as the known protections, and says adoption across smaller protocols stays inconsistent. Neither report establishes which Term had.
Deposits in this sector can be lost in full, and this is a report, not advice.