The attacker bought a majority of a thinly held DAO token, then voted the vault contents to themselves. Term Labs shut down Meta Vault deposits and revoked governance roles in response.
Term Finance confirmed on Sunday that an attacker had drained roughly $8.5 million from its strategy vaults by hijacking a governance vote it should never have been able to win. The mechanism was mundane. The economics were absurd. Two ETH withdrawn from Tornado Cash was all the attacker spent to acquire the tokens they needed to seize control.
The Ethereum-based fixed-rate lending protocol lost about 2,843 ETH (worth roughly $6.87 million) alongside 1.68 million USDC that was quickly swapped into DAI. Term Labs, the company behind the protocol, has permanently frozen deposits into its Meta Vaults, revoked DAO governance roles, and left withdrawals open while it investigates.
What makes this different from the more familiar smart-contract exploit is that nothing broke. The code did what it was told. PeckShield and CertiK both classified the incident as a governance exploit, meaning the attacker used ordinary, valid on-chain votes to steer depositor assets into their own wallet. Once they had the tokens to force the proposal through, the rest was procedural.
The proposal thresholds are the story. At the point of execution, the attacker held 100 percent of voting power in four out of five USDC strategy vaults and roughly 91 percent in the Ethereum Meta Vault. Those numbers reveal how little of Term's governance token was in active circulation; enough tokens to represent a majority of vault voting power were quietly acquired on the open market, funded by less than $5,000 in bootstrapped ETH.
Once the balance crossed proposal and quorum thresholds, the attacker submitted proposals redirecting vault assets and voted them through with their own holdings. Term's own governance system executed the transfer. Depositors had no ability to intervene.
Decurity's on-chain monitoring bot Defimon flagged the drain first, and both PeckShield and CertiK confirmed the pattern within hours. Attribution of the wallet remains open. What is not open is the pattern: this is the second high-profile buy-the-vote attack on a DeFi lending protocol in six weeks, following BonkDAO's $20 million loss on 8 July after seven wallets passed a proposal 18,000 others ignored.
Term Finance was founded in 2022 and pitched as the first onchain platform bringing scalable fixed-rate, fixed-term lending to DeFi. Its Meta Vaults automated strategy across USDC and ETH positions and paid depositors a yield sourced from Term's auction mechanism. That model always required governance to remain honest, because governance controlled which strategies the vaults ran. Once the attacker owned the vote, they owned the strategy and the vault assets that funded it.
The parallel to Compound's 2024 governance episode is uncomfortable. Compound narrowly avoided losing $24 million to Proposal 289's Golden Boys attack, when a coordinated group used exchange-purchased COMP to reach quorum on a proposal that would have handed treasury control to a small pool of wallets. The Golden Boys were eventually bought off with a settlement. Term's attacker didn't negotiate. They executed, drained, and moved the funds.
The response from Term Labs has been rapid but limited by design. Permanently disabling Meta Vault deposits stops new capital walking into the same trap. Revoking DAO governance roles neutralises the compromised voting layer. Withdrawals remain open because the money that is still in the vaults belongs to depositors, and Term has no legal or moral claim to freeze it. A code exploit could have been patched. A governance exploit against a thinly held token has no clean fix short of migrating the entire lending surface off the current DAO.
The wider problem is that token-weighted voting continues to be treated as an adequate security model for pools holding tens of millions in depositor funds. When the governance token trades sparsely, its market cap can be a fraction of the assets under its control. Two ETH is enough to sweep the vote if the float is low enough. Every DeFi protocol using unmodified token voting to control vault strategy is running the same experiment; only the price of the tokens changes.
Term hasn't committed to a specific reimbursement plan. In the immediate aftermath the priority is stopping further loss, then documenting what the attacker did with the funds, which for now trace to freshly created wallets holding the DAI proceeds. Historical precedent suggests some fraction of stolen DeFi funds will be recovered through negotiation or law enforcement, and some will not.
DefiLlama's running tally now shows 17 security incidents worth about $18.8 million in August before the Term drain, pushing the month past $27 million and cementing governance exploits alongside bridge failures as one of the two categories DeFi has yet to solve.