Ethereum lending platform Term Finance has lost an estimated $8.5 million after an attacker seemingly acquired enough voting power to take control of some of its lending vaults.

The attacker removed roughly 2,843 ether $ETH$2,456.26, worth about $6.9 million at the time, and 1.68 million USDC, blockchain data shows, draining about 68% of the assets held in Term’s vaults.

Term's Meta Vaults held about $12.45 million before the attack, data from DefiLlama show. Nearly all of the roughly $8.8 million in ether deposited in the product was taken.

The unusual part is how the attacker may have gained access.

Onchain monitoring service Defimon said the attacker cheaply acquired a majority of the project’s sparsely held governance token, which gave holders voting rights over how the protocol is operated. The attacker then allegedly used that voting power to pass proposals that gave it control of the vaults.

Term Finance lost 68% of its vault assets in a single attack. (Shaurya Malwa/CoinDesk)

Term has not confirmed how the attacker obtained majority control or exactly which governance functions were used. It has now permanently shut the product, blocked new deposits and removed the governance permissions that allowed changes to the vaults.

The wider Term Finance protocol and its direct borrowing and lending markets were not affected based on the company's investigation so far, the team said in a Monday post.

Term said it is working with outside security teams on recovering assets and will explore ways to cover any remaining losses.

The vaults were built using Yearn V3 infrastructure, widely used software that automatically moves deposits between lending markets to chase the best available return. Yearn said the exploit involved a custom governance layer added around its technology and did not apply to standard Yearn vaults.

The attack also comes with some history.

An oracle error in April 2025 triggered about 918 $ETH of unintended liquidations at Term. The protocol later recovered most of the funds, reimbursed affected users and pledged greater governance transparency and outside validation for critical changes.

A little over a year later, governance itself appears to have become the weak point — where assets controlled by a vote can be worth far more than the tokens needed to win that vote.