Ethereum-based lending platform, Term Finance, lost an estimated $8.5 million after an attacker apparently acquired enough governance voting power to take control of its Meta Vaults.

The attacker withdrew about 2,843 ETH worth roughly $6.9 million at the time, and 1.68 million USDC, draining about 68% of the vaults’ assets.

 

The attack exploited a weakness in governance rather than a conventional smart-contract vulnerability.

 

The attacker reportedly bought a majority of the protocol’s sparsely held governance token and used that voting power to approve proposals granting control over the vaults.

 

CASE STUDY | This Major Blockchain Ecosystem is Facing Unintended Consequences of Decentralized Governance

 

Term said its broader lending and borrowing markets were not affected. It has

  • permanently shut the vault product,

  • blocked new deposits, and

  • removed the governance permissions that enabled changes to the vaults.

The company is also working with external security teams on asset recovery and potential compensation for losses.

The vaults used Yearn V3 infrastructure although Yearn said the exploit involved Term’s custom governance layer and did not affect standard Yearn vaults.

 

The incident highlights a growing DeFi risk:

When the cost of buying governance control is lower than the value of the assets controlled by that governance, voting mechanisms themselves can become an attack vector.

 

 

CASE STUDY | This Leading DAO Exploit Shows the Biggest Risk to On-Chain Governance is Governance Itself

 

 

 

Stay tuned to BitKE on DeFi updates. 

Join our WhatsApp channel here.

Follow us on X for the latest posts and updates

Join and interact with our Telegram community

______________