HomeZ - Banner home engTerm Finance Exploit: $951 Bought 90% Control, Drained $8.5M

Term Finance Exploit: $951 Bought 90% Control, Drained $8.5M

A crypto attacker needed less than a thousand dollars to walk away with millions in digital assets this past weekend, and the Term Finance exploit is now being held up as a case study in how thin governance participation can turn a lending protocol into an easy target. No smart contract bug was involved. No months of reconnaissance. Just a small token purchase, a stake, and a vote nobody was watching closely enough to stop in time.

Key takeaways

  • Term Finance’s vaults were drained of approximately $8.5 million in a governance exploit confirmed by blockchain security firms PeckShield and CertiK.
  • The attacker spent roughly $951 to buy and stake 0.4852 tmvETH, which alone secured 90.66% of all existing voting power in the pool.
  • The exploiter withdrew about 2,843 ETH and 1.68 million USDC, converting the stablecoin haul into DAI.
  • The wallet’s initial funding traced back to just 2 ETH sourced through Tornado Cash.
  • Users holding trUSD, strUSD, or Ecosystem Vault positions were confirmed unaffected, according to the Tori project.

Details of the Term Finance Governance Exploit

The core fact of this story is simple: an attacker turned a $951 purchase into control over $8.5 million in user funds. Blockchain security firm PeckShield confirmed the breach directly, reporting that Term Labs was hit for approximately $8.5 million after a governance exploit impacted Term’s vault products. CertiK separately corroborated the same figure, putting the total loss at roughly $8.5 million as well.

According to PeckShield’s tracking, the attacker withdrew around 2,843 ETH, worth about $6.87 million at the time, along with 1.68 million USDC valued at roughly $1.68 million. The stablecoin portion was quickly swapped into 1.68 million DAI. PeckShield traced the drained funds to a single wallet that had originally been funded with just 2 ETH routed through Tornado Cash, the privacy mixing protocol frequently used to obscure the origin of attacker wallets before an exploit.

Term’s Strategy Vaults are ERC-4626 tokenized vaults built on Yearn V3 infrastructure, allocating capital between Term’s fixed-rate lending markets and variable-rate lending protocols. Yearn moved quickly to clarify that the exploit ran through a custom governance wrapper specific to Term’s setup rather than through standard Yearn vault architecture, stating that funds deposited into standard Yearn vaults remained safe and unaffected. Term Labs acknowledged the incident publicly, saying it was aware of a governance exploit affecting Term vaults and that further details would follow its investigation, though the team did not immediately confirm the exact scale of losses or name the specific vaults hit.

Mechanics Behind the Exploit and Its Enabling Factors

What made this attack work wasn’t a coding flaw, it was a governance system almost nobody was using. Voting power inside Term’s vaults required staking vault shares, and the pre-drain staked supply across the pool sat at just 0.5352 gtmvETH, an almost negligible amount for a vault holding millions of dollars in depositor funds.

On August 17, the attacker bought 0.4852 tmvETH for roughly 0.5 ETH, about $951 at the time, staked it, and that single purchase alone was enough to secure approximately 90.66% of all existing votes in the pool. With that supermajority locked in, the attacker simply voted to redirect vault funds to their own address. Term’s governance structure separates operational control between a “manager” role handling auction activity and a “governor” role overseeing risk parameters and emergency functions, while vault liquidity providers can vote to veto queued governance transactions during a seven-day timelock. Term has not disclosed which role the attacker exploited or why that veto window failed to stop the transaction before execution.

This is why low staking participation matters so much for vault-based protocols: when almost nobody votes, the price of buying a controlling stake collapses. The barrier separating “secure protocol” from “drained treasury” ends up resting entirely on whoever notices the vulnerability first. It’s not a new attack pattern either. DeFi builder Psykeeper drew a direct line to the BonkDAO exploit from July, where a malicious governance proposal drained roughly $20 million, and to a March incident at Moonwell where an attacker spent about $1,800 on tokens to push a proposal threatening $1.08 million. The structural difference with Term is stark: where the BonkDAO attacker needed millions to accumulate voting power, this attacker only needed $951, a direct function of how little of Term’s vault supply was actually staked and participating in governance.

Responses and Impact on Related Tokens and Users

Not every part of Term’s ecosystem was exposed, and that distinction matters for anyone holding related tokens. Tori, a project connected to Term’s infrastructure, confirmed directly that it had zero exposure to the exploit. According to Tori, trUSD and strUSD holders had zero exposure, Ecosystem Vault participants remain fully covered, and all operations continue running normally.

The statement was direct about what affected users need to do next: nothing. Whether someone holds trUSD, strUSD, or an Ecosystem Vault position, their balance remains exactly where it was before the attack, with no action required on their end. Prior to the breach, total value locked across Term’s vaults stood at roughly $12.45 million, according to DefiLlama data, including about $8.8 million on Ethereum. The reported $8.5 million loss represents close to two-thirds of the vault product’s total value locked across all chains and nearly the entirety of its Ethereum-based holdings, though it’s worth noting this is separate from Term Finance’s broader protocol, which held about $25.8 million in total value locked and $3.79 million in active loans before the incident.

Preventative Measures and Future Outlook

The clearest lesson from this exploit is that governance systems left unattended aren’t secure by default, they’re simply undefended until someone tests them. That framing shapes both what could have stopped this attack and what protocols need to rethink going forward.

Role of Onchain Monitoring Systems

Active monitoring tools were arguably the missing safeguard here. Psykeeper pointed specifically to onchain monitoring systems like Hypernative Labs as the kind of infrastructure that could have flagged this attack before execution, since a wallet suddenly accumulating 90% of a governance pool’s voting power off a $951 purchase is exactly the type of anomaly automated monitoring is designed to catch in real time. Without that active oversight, a governance takeover can execute cleanly, since nothing in the underlying code was technically broken.

Challenges of Governance Participation and Security

Veto power over malicious proposals is often treated as a built-in safeguard, but it carries its own tension: that same mechanism is itself an onchain attack surface requiring constant, time-sensitive attention to actually function. Low participation, thin audits, and misaligned incentives don’t just make an attack possible, they make it cheap, and cheap attacks tend to get repeated. Term Finance had already experienced a separate incident in April 2025, when a misconfigured oracle caused faulty liquidations in its tETH market, a loss the protocol said was not a hack and later recovered more than $1 million of the $1.6 million affected. This latest governance breach is a different kind of failure, one rooted in incentive design rather than code, and until vault architectures solve the underlying problem of near-zero governance participation creating near-zero cost takeovers, the same pattern, a small stake, a sudden supermajority, a drained treasury, is likely to keep surfacing in security reports.

FAQ

How did the attacker gain control over Term Finance’s vaults?

The attacker bought and staked a small amount of governance tokens for about $951, gaining 90.66% of voting power due to low staking participation across the vault pool.

What was the financial impact of the exploit on Term Finance?

Approximately $8.5 million was drained, including about 2,843 ETH and 1.68 million USDC, with the stablecoins converted into DAI.

Were all Term Finance users affected by the exploit?

No. Users holding trUSD, strUSD, and Ecosystem Vault tokens were confirmed unaffected by the Tori project, and no action is required from those holders.

What could have prevented the attack?

Active onchain monitoring systems like Hypernative Labs could plausibly have detected the sudden accumulation of voting power before it was used to redirect vault funds.

Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

Alessia Pannone
Graduated in communication sciences, currently student of the master's degree course in publishing and writing. Writer of articles from an SEO perspective, with care for indexing in search engines.
RELATED ARTICLES

Stay updated on all the news about cryptocurrencies and the entire world of blockchain.

Featured video

LATEST