Term Finance loses $8.5M after attacker buys governance votes for just 2 ETH

2 hours ago 11

Someone just spent roughly 2 ETH to steal $8.5 million. On August 23, an attacker purchased enough voting power to commandeer multiple strategy vaults on the fixed-rate lending platform Term Finance, draining approximately 2,843 ETH (worth about $6.87 million) and 1.68 million USDC. The seed money for the entire operation came from Tornado Cash, the sanctioned Ethereum mixer. All stolen funds were funneled to a single wallet.

How the attack worked

The attacker gained 100% voting control over four of Term Finance’s five USDC strategy vaults and roughly 91% control over the Ethereum Meta Vault. Once the attacker held a supermajority of votes, they could redirect vault funds wherever they wanted.

The impacted vaults operate on Yearn V3 infrastructure with a custom governance framework built by Term Labs, the development team behind Term Finance. Security firms PeckShield and CertiK both confirmed the exploit, noting it targeted the voting mechanics rather than any flaw in the underlying smart contract code.

The USDC portion of the stolen funds was subsequently converted to DAI, a common post-exploit laundering step that makes tracing and freezing assets more difficult since DAI, unlike USDC, cannot be blacklisted by a centralized issuer like Circle.

A second blow in just over a year

This is not Term Finance’s first significant loss. In May 2025, the protocol suffered a roughly $1.5 million hit caused by an oracle error during a system upgrade. That incident had a happier ending: the funds were eventually recovered.

Term Labs has acknowledged the breach and said an investigation is underway. The team has not yet shared any details about potential fund recovery or remediation plans.

The governance problem DeFi keeps ignoring

The Term Finance exploit is a textbook example of what happens when voting power is too cheap or too concentrated. An attacker spending 2 ETH to control vaults holding millions of dollars in assets suggests that the cost of acquiring governance influence was wildly misaligned with the value of the assets those votes could control.

Beanstalk suffered a similar fate in 2022 when an attacker used a flash loan to pass a malicious governance proposal, draining roughly $182 million. The mechanics differ slightly, but the core vulnerability is identical: if enough votes can be acquired cheaply, governance becomes an attack vector rather than a safeguard.

Term Finance’s custom governance layer apparently lacked sufficient guardrails to prevent a rapid accumulation of voting power from translating into immediate fund control. Time-locked voting, quorum requirements, vote delegation limits, and multi-sig overrides on vault operations are common mitigations that can raise the cost of such attacks significantly.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article